HK Causeway Bay Hang Seng branch interior Yee Woo Street December 2016 Lnv3 恆生銀行 service counters

24 September 20262 min read

HKMA alerts public to phishing and fake login screens at five banks

RegulationLending operations

“HK Causeway Bay Hang Seng branch interior Yee Woo Street December 2016 Lnv3 恆生銀行 service counters” by Bulk Greenman Richards, source · CC BY-SA 4.0 · via Wikimedia Commons

The HKMA's 23 September alert names five banks hit by fraudulent websites, fake internet banking login screens and phishing. Here is what it means for a lender's onboarding and payment checks.

On Wednesday 23 September 2026 the Hong Kong Monetary Authority issued an alert on behalf of five banks. The Bank of East Asia, Shanghai Commercial Bank, Chong Hing Bank and Chiyu Banking Corporation were each reported for fraudulent websites and internet banking login screens. Dah Sing Bank was reported for a fraudulent website. The HKMA published the list and linked to each bank's own press release.

The alert repeats two statements the HKMA makes whenever it issues this kind of notice. Banks will not send SMS or emails containing embedded hyperlinks that take customers to the bank's website to carry out transactions. Banks will not ask for login passwords or one-time passwords by phone, email or SMS, including through embedded links. Anyone who has handed over personal information or carried out a transaction in response should contact the bank and report the matter to the Police Crime Wing Information Centre on 2860 5012.

For a licensed money lender, the operational point is narrower than the headline. The scam targets bank credentials, not loan applications. But the same credentials are what a borrower uses to show income, service an existing facility or receive a disbursement. When a customer says their bank login was compromised, the practical question is whether any account your firm holds or draws on has been touched, and whether a repayment mandate or autopay instruction needs to be re-verified before the next due date.

The part operators tend to underestimate is the outbound side. A lender that sends borrowers an SMS with a link to a payment page, or that asks for an OTP to confirm a direct debit, is doing something the HKMA has just told the public banks never do. Borrowers who have read this alert are more likely to treat that message as a scam, and some will report it. Firms that rely on link-based collection messages should expect more failed contact and more inbound verification calls, not less.

This is an HKMA alert about authorized institutions. It does not change the Money Lenders Ordinance, the licensing conditions, or the Personal Data (Privacy) Ordinance, and it imposes no new duty on money lenders. It is a reminder that the fraud typologies reaching your borrowers are the same ones reaching bank customers.

Covenant Desk publishes regulatory context for Hong Kong lending operations, not legal advice. Confirm how anything here applies to your licence with your own advisers.

All lending news