HKMA issues scam alert on bank-related phishing and fraud
HKMA alerted the public to fraudulent websites, phishing emails and scam SMS impersonating banks.
HKMA reiterated that banks do not send SMS or emails with embedded hyperlinks for transactions. Institutions should strengthen anti-phishing controls, brand monitoring, and customer education to mitigate rising impersonation fraud risks in Hong Kong.
Ongoing phishing threats increase conduct, operational, and reputational risk for retail banks.
Action Required
Reinforce customer fraud awareness communications and monitor for impersonation attacks on bank channels.
Recurring HKMA alerts indicate sustained fraud campaigns requiring active mitigation.
Review anti-phishing controls, takedown processes, and customer authentication safeguards; refresh fraud awareness messaging across digital channels.
“HKMA alerts the public to press releases from banks regarding fraudulent websites, phishing emails and scams; banks will not send SMS/emails with embedded hyperlinks.”
Published: 2026-07-21