Sitonce
Country: US
Show exams for United States Hong Kong
Sign in

Phishing Controls and SFC Notification Duties

Updated 6 min read
Key takeaway

The SFC expects licensed corporations to reduce phishing risk through client education, safe message design, account monitoring, and incident response.

More key points
  • Firms must not direct clients through embedded links to transact or submit credentials, and specified material system failures or suspected market misconduct require immediate SFC notification under the Code of Conduct.
On this page14 sections
  1. Design communications so clients can verify them
  2. Monitor accounts and act on a reported attempt
  3. Know what requires immediate SFC notification
  4. The SFC’s baseline message-design controls
  5. More recent authentication expectations
  6. Respond when a client reports a fake message
  7. Immediate SFC notifications are specific
  8. Unauthorized trading can raise additional reporting
  9. Account monitoring and red flags
  10. Client education that is actionable
  11. Exam sequence
  12. What to do in the first hour
  13. Avoid false reassurance
  14. Exam takeaway

Phishing can lead to stolen credentials, unauthorized access, and client losses. In its 2025 circular, the SFC reminded licensed corporations of controls for detecting and preventing phishing that impersonates a firm. The circular links cyber hygiene to conduct, supervision, and prompt regulatory notification.

Design communications so clients can verify them

  • Do not send electronic messages with embedded links that direct clients to the firm’s website or app to conduct transactions.
  • Do not ask clients to submit passwords, account credentials, or one-time passcodes through a link.
  • Send regular warnings explaining that the firm will not request sensitive information through hyperlinks.
  • Encourage clients to avoid unverified websites even when they appear genuine.

Monitor accounts and act on a reported attempt

A licensed corporation should maintain effective monitoring and surveillance to detect unauthorized access to internet trading accounts. If a client asks about a suspicious message or reports that they were defrauded, the firm should help the affected client understand appropriate reporting steps, including contacting police where applicable, and alert other clients as soon as practicable. The firm should investigate the incident, contain access, and preserve relevant records.

Know what requires immediate SFC notification

The circular highlights Code of Conduct paragraph 12.5(e), which requires immediate reporting of a material failure, error, or defect in trading, accounting, clearing, or settlement systems or equipment. Paragraph 12.5(f) addresses immediate reporting where the firm reasonably suspects client market misconduct under the relevant SFO provisions. A phishing attempt alone is not automatically every notification category; assess the resulting facts against the specified duties and report when a trigger is met.

The SFC’s baseline message-design controls

The 2025 SFC phishing circular says licensed corporations should not send electronic messages with embedded hyperlinks directing clients to websites or applications to transact, and should not ask clients to submit sensitive information such as passwords or one-time codes through links. Firms should explain that policy to clients, issue regular security reminders, monitor internet-trading accounts for unauthorized access, and alert clients when phishing targeting them is identified. A genuine-looking sender name is not enough to establish authenticity.

More recent authentication expectations

A July 2026 SFC circular added expectations for internet brokers and SFC-licensed virtual-asset platform operators, including robust authentication and device-binding measures, monitoring and surveillance for suspicious client-account activity, and prompt response and reporting procedures for hacking incidents. These are directed to the specified firms and should be read with the circular’s scope and examples. They supplement the earlier phishing prevention standards; they do not turn every firm or account into the same technical design.

Respond when a client reports a fake message

A client may report an SMS, email or website impersonating the firm before any money is lost. A sound response verifies whether credentials or transactions were affected, advises the client through a trusted channel, warns other clients as soon as practicable where appropriate, and directs the affected person to report to Police where applicable. Preserve the message, URL, timestamps and account telemetry so security staff can investigate and block related attempts.

Immediate SFC notifications are specific

Under Code of Conduct paragraph 12.5(e), a licensed corporation must report immediately a material failure, error or defect in the operation or functioning of its trading, accounting, clearing or settlement systems or equipment. Paragraph 12.5(f) also requires immediate reporting of a material breach or non-compliance with specified market-misconduct provisions that the firm reasonably suspects a client may have committed. A phishing attempt alone is not automatically identical to those triggers; assess the facts and other notification duties.

Unauthorized trading can raise additional reporting

If a compromise leads to unauthorized trades, firms should contain the activity, protect remaining client assets, review account access and determine whether suspicious-transaction, law-enforcement, privacy or other regulatory reports are required. The SFC’s 2025 unauthorized-trading circular describes controls such as sender registration, client education, monitoring for abnormal activity, and promptly reporting suspected crime to the Joint Financial Intelligence Unit where applicable. Do not treat a single alert as a substitute for incident triage.

Account monitoring and red flags

Useful indicators include an unfamiliar device or location, repeated failed logins, a sudden change in transaction pattern, new payee or contact details, or a series of trades inconsistent with the client’s history. Automated surveillance can surface outliers, but staff need an escalation path and authority to pause or confirm transactions. The firm should size controls to client volume and complexity and test whether alerts lead to timely action.

Client education that is actionable

Tell clients what the firm will never request, how to reach the official application or website independently, and what to do if credentials may be exposed. Avoid asking clients to click a link in the warning that supposedly protects them. Provide a verified phone number and clear account-locking route. Education works best when the real firm’s communication practices are consistent with the message.

Exam sequence

Classify the event as a phishing attempt, suspected credential compromise, unauthorized transaction, material system failure, or suspected market misconduct. Apply the matching control and notification trigger, preserve evidence, protect clients, and document why a report was or was not made. Separate preventative expectations from the Code’s immediate reporting duties; do not claim that every phishing email automatically requires the same SFC filing.

What to do in the first hour

Use a trusted contact path to confirm whether the client clicked, entered credentials or approved a transaction. Lock or restrict compromised access where justified, reset authentication securely, identify other affected clients, notify internal incident leads, preserve logs and coordinate with the client’s bank where funds are involved. Notify Police or the JFIU where appropriate. A quick response limits harm but should not destroy the evidence needed to understand the attack.

Avoid false reassurance

Do not tell a client that an account is safe solely because no unauthorized trade is yet visible. Credentials may have been captured and the attacker may wait. Monitor sessions and pending instructions, confirm contact details independently, and tell the client what to do next using official channels. Document what the firm knows, what remains uncertain and when it will update the client.

Exam takeaway

Separate prevention, detection, client communication, and regulatory notification. Identify the event and the specific Code trigger rather than treating every cyber alert as identical.

Common questions

Should a licensed corporation send a transaction link by SMS?

The SFC’s 2025 circular says firms should not send electronic messages with embedded links directing clients to the firm’s site or app to undertake transactions.

When can a cyber event require immediate notification to the SFC?

The circular highlights material failures in specified systems and reasonably suspected client market misconduct as immediate-notification triggers under the Code provisions it cites.