Sitonce
Country: HK
Show exams for United States Hong Kong
Sign in

Responding to Suspected Unauthorised Trading in a Client Account

Updated 5 min read
Key takeaway

When a licensed corporation suspects unauthorised trading, it should promptly verify activity with the client, take immediate steps to stop further unusual transactions, safeguard assets, and assess reporting duties.

More key points
  • SFC guidance highlights login and trading alerts, anomaly monitoring, secure communication, and escalation.
  • A familiar username or password alone does not prove the client authorized a trade.
On this page12 sections
  1. Why a valid login may still be suspicious
  2. Monitor for patterns that do not fit
  3. Verify with the client using trusted channels
  4. Stop further activity and protect assets
  5. Client communications and alerts
  6. Reporting and investigation
  7. A practical example
  8. Client role and firm responsibility
  9. Paper 1 takeaway
  10. Operational details that strengthen the control
  11. How to apply it in a real case
  12. Points to carry into practice

When a licensed corporation suspects unauthorised trading, it should promptly verify activity with the client, take immediate steps to stop further unusual transactions, safeguard assets, and assess reporting duties. SFC guidance highlights login and trading alerts, anomaly monitoring, secure communication, and escalation. A familiar username or password alone does not prove the client authorized a trade.

Why a valid login may still be suspicious

Phishing and man-in-the-middle attacks can capture credentials and one-time passwords, allowing an attacker to access a genuine account. The SFC’s 2025 circular describes this pattern and expects licensed corporations to improve prevention, detection, and response. A successful authentication event is evidence of system access, not conclusive proof that the client personally instructed the trade.

Monitor for patterns that do not fit

The SFC identifies potential red flags such as sudden changes in transaction volume or type, formerly inactive accounts trading frequently, clients concentrating in small-cap or illiquid securities, login locations that change quickly, several accounts accessed from a similar IP address, or multiple accounts bound to one device. Surveillance should reflect the firm’s size and complexity; a large broker may need automated tools.

Verify with the client using trusted channels

If unusual activity appears, contact the client promptly using verified contact information already held by the firm. Do not rely on a number, email, or link included in the suspicious message. Ask whether the login and trade were authorized and document the response. If the client cannot be reached, continue protective steps under the firm’s procedure rather than assuming silence confirms the transaction.

Stop further activity and protect assets

The SFC expects immediate steps to prevent unusual activity from continuing, such as suspending the account where appropriate. The response may include blocking withdrawals, freezing online access, resetting credentials through a verified route, preserving records, and alerting operations, cyber security, compliance, and senior management. The precise restriction depends on the facts and client impact, but speed matters because further trades can compound losses.

Client communications and alerts

Firms should encourage clients to review login, password reset, trade execution, and profile-change notifications. Clients who opt out of these alerts should be reminded regularly of the risks and how to enable them. SFC guidance also expects firms to educate customers about phishing, including avoiding hyperlinks in SMS messages and checking that genuine firm texts use the registered sender prefix where applicable.

Reporting and investigation

A licensed corporation should assess whether the incident triggers immediate SFC notification, a suspicious transaction report to JFIU, law-enforcement contact, or other regulatory reporting. The 2025 circular identifies reporting duties for material system failures and suspicious transactions. Preserve logs, IP and device data, order history, authentication events, calls, client messages, and any third-party communications. Do not overwrite data during recovery.

A practical example

A normally inactive account logs in from an unfamiliar location, changes contact details, and trades a cluster of illiquid shares. The broker sees similar IP activity on multiple accounts. Staff contact the customer through the pre-existing phone number, restrict further activity according to policy, preserve system records, and alert the incident team. The response is based on the combined indicators, not merely the account’s valid password.

Client role and firm responsibility

Clients should protect credentials and report unfamiliar activity, but the firm still needs reasonable controls to protect client accounts. Do not blame the client before investigation. Explain the protective action in plain language, provide verified contact points, and document the client’s report. When staff themselves suspect unauthorized access, they should escalate even if the client has not yet complained.

Paper 1 takeaway

Treat unusual account activity as an incident to verify and contain. Use trusted contact channels, stop further loss, preserve evidence, and assess regulatory reporting promptly.

Operational details that strengthen the control

The incident timeline should include the first suspicious login or instruction, detection time, client contact attempts, account restrictions, outstanding orders and withdrawals, and the person who approved each response. Preserve evidence before resetting devices or deleting access tokens if the security team needs forensic information. Confirm that the client can regain access securely after containment and that contact details were not changed by the attacker. If the client confirms a trade was not authorized, assess whether related accounts or beneficiaries are involved. Notify the relevant internal teams promptly so AML, cyber, operations, and client-service responses do not conflict or inadvertently reveal an STR.

How to apply it in a real case

Do not send a password reset link through a channel that may already be controlled by the attacker. Use the firm’s verified recovery process and check whether the customer’s phone number, email, mailing address, or linked bank details changed shortly before the incident. If notification settings were disabled, the firm should determine when and how that change occurred. Staff should tell the client what protective steps to take, such as contacting the police or checking other accounts, without asking them to use a link from a suspicious message.

Where multiple clients show similar unusual trades or access patterns, assess whether a common phishing campaign or compromised intermediary is involved. A firm should not treat each affected account as an unrelated customer-service issue.

After containment, review whether similar login or trade anomalies occurred before the first reported case. A short lookback may identify additional affected clients and help the firm meet its reporting obligations.

Once the client confirms the activity was unauthorized, give clear instructions on secure account recovery and the firm’s complaint channel. Do not promise reimbursement before the review is complete.

Points to carry into practice

  • Check current SFC rules, guidance and firm procedures for the exact requirement.
  • Record the facts, escalate uncertainty and protect client interests.

Common questions

Does a correct password prove that a trade was authorized?

No. Credentials can be stolen; firms should assess activity patterns and verify with the client.

What should staff do first when unauthorized trading is suspected?

Escalate promptly, verify through a trusted channel, and follow controls to prevent further activity.

Should the account be suspended automatically?

The SFC expects immediate steps to stop unusual activity; restriction should follow risk-based firm procedure.

What evidence should be preserved?

Login and device data, order and trade history, client communications, authentication records, and incident actions.