
Licensed virtual asset platforms and online brokers must replace OTPs for client logins and new-device binding by July 8, 2027, while strengthening fraud monitoring, alerts and incident response under tighter cybersecurity rules.
Hong Kong’s Securities and Futures Commission has ordered licensed virtual asset service providers and internet brokers to replace one-time passwords used for client logins and new-device registration or binding with phishing-resistant authentication by July 8, 2027. The July 9 circular says OTPs no longer meet the required standard for those two processes, though other OTP uses are unchanged. Large internet brokers are expected to deploy stronger methods immediately, while the broader group has a 12-month implementation period. The regulator also imposed immediate expectations for stronger client notifications, account monitoring, surveillance and incident response, and said firms can be held accountable for client losses if inadequate safeguards fail to prevent, detect and stop large-scale unauthorized transactions after a hacking incident.