HKMA warns public of bank-related phishing and scam websites
HKMA issued a public alert regarding fraudulent websites, phishing emails and scam SMS impersonating banks.
HKMA has reiterated warnings on bank impersonation scams involving fake websites and phishing emails. Banks are reminded not to embed hyperlinks in SMS or emails directing customers to transact. Signals continued elevated fraud typologies targeting retail banking customers in Hong Kong.
Impersonation scams drive conduct, operational and reputational risk exposure for banks operating in Hong Kong.
Action Required
Review customer fraud controls, phishing detection, and public awareness communications for impersonation risk.
Ongoing HKMA scam alerts indicate sustained fraud pressure and supervisory expectations on customer protection controls.
Assess phishing and impersonation controls, customer communications policy on embedded links, and fraud monitoring. Confirm alignment with HKMA expectations.
“The HKMA alerts the public to bank press releases on fraudulent websites, phishing emails and scams, reminding that banks will not send SMS or emails with embedded hyperlinks directing customers to transact.”