HKMA Online Transaction Measures


On Oct. 10, HKMA issued circular on online anti-fraud measures.


  • HKMA issued circular on enhanced anti-fraud measures for online card payments.
  • Retail banks introduced anti-malware measure in Feb. 2024, restricting mobile banking app access if suspicious apps detected; no new malware cases since implementation.
  • New malware scam tactics observed, involving fraudsters tricking customers into installing malicious apps, disclosing card details and SMS one-time passwords (OTPs).
  • Follows Aug. 2024 HKMA expanded the suspicious account alert for banking, #221665.
  • Enhanced Measures
  • Card-issuing authorized institutions (AIs) to work with card scheme operators on new authentication methods; banking app to authenticate via a bound device by default.
  • Changes to default authentication method deemed high-risk; SMS OTP not to be used.
  • AIs to consider alternative arrangements for vulnerable customers, dormant app users.
  • Customers without mobile bank apps may continue using SMS OTPs for authentication.
  • AIs should incentivize mobile banking app installation, use, with education initiatives.
  • Tighter fraud monitoring required for transactions authenticated via SMS OTPs.
  • AIs to regularly review, assess effectiveness of authentication processes and controls.
  • AIs with difficulties meeting requirements/timeline can discuss alternatives with HKMA.
  • Effectiveness
  • Enhanced measures to be implemented as soon as practicable, by Dec. 31 at latest.

Regulators HKMA
Entity Types Bank; MSB
Reference Cir B1/15C, B9/29C, 10/10/2024
Functions Audit; Compliance; Cyber; Fraud; Operations; Risk; Technology
Countries Hong Kong
Category
State
Products Banking; Cards; Payments
Regions AP
Rule Type Final
Rule Date 10/10/2024
Effective Date 12/31/2024
Rule Id 229224
Linked to Rule :221665
Reg. Last Update 10/10/2024
Report Section International

Last substantive update on 10/15/2024