Search

Hongke's latest articles

HongKe

Add your title text here

I. Introduction: Strategic Changes at the Data Layer under the Critical Infrastructure Legislation

[Hongke Insights] The Hong Kong Monetary Authority’s Fraud Prevention Checklist Reveals Corporate Blind Spots: Why the Financial Industry Needs KnowBe4-Style Cybersecurity Awareness Training

Have you ever received a text message or email like this? ”There has been an unusual transaction in your account. Please click the link to confirm; otherwise, your online transfer service will be suspended.” The sender appears to be a well-known bank, and the link looks legitimate. The Hong Kong Monetary Authority (HKMA) repeatedly emphasizes a key regulatory principle on its “Beware of Scammers!” webpage:Banks will never use links in text messages or emails to direct customers to websites or apps to conduct transactions, nor will they ever use such links to request sensitive information such as login passwords or one-time passwords.
 
In other words, any banking message that asks you to ”click a link or enter your password” can almost always be identified as a phishing scam. But why does this tired old scam continue to run rampant? The answer lies in the fraud list that the Hong Kong Monetary Authority continually updates.

I. Scammers" "Banks” Are Becoming Increasingly Realistic: A Continuously Updated List of Scams

The “Beware of Scammers!” page is the Hong Kong Monetary Authority’s public anti-fraud education section, with its core component being a public list titled “Fraudulent Banking Websites, Phishing Emails, and Similar Scams”: The HKMA compiles press releases issued by various banks (and the HKMA itself) regarding fraud incidents into a large table organized by date, listing them row by row.Date of Release, Impersonated Organization, Type of Fraud (with link to press release), Website Involved. It is not a real-time alert system, but rather aAn alert archive that is continuously collected and regularly updated— Whenever a bank discovers a new fraudulent website, phishing email, or fake app, it issues a press release and adds the information to this list, which the public can access and verify at any time. A closer look at this list reveals several trends:
 
First, the update frequency is high, and the time span is long. The latest entries go as far as August 2026, with new ones added almost every week, and the archive extends back several years—scammers never ”stop.”
 
Second, almost all of Hong Kong's major banks have been targeted by counterfeiters. HSBC, Bank of China (Hong Kong), Standard Chartered, Bank of East Asia, DBS, Overseas-Chinese Banking Corporation, Shanghai Commercial Bank, Chong Hing Bank, Chiyu Bank, CITIC Bank International, Bank of Communications (Hong Kong), CCB Asia, ICBC Asia, ZhongAn Bank, Ant Bank, Furuong Bank, Dah Sing Bank, Fubon Bank, LiHui Bank… along with international private banks such as Julius Baer and Yingfeng, as well as the Bank of Singapore, have all appeared on the list of thoseImpersonationon the list.
 
Third, the range of fraud schemes is becoming increasingly ”comprehensive.” In addition to fraudulent websites and online banking login pages, there are also spoofed emails, phishing text messages and instant messages, fake mobile apps, and fake social media accounts and posts. For example, a fake WeChat account named ”CITIC Bank (International) Cross-Border Services” appeared under the name of CITIC Bank (International); there was a fake TikTok account for Bank of Singapore; DBS Bank’s fraudulent posts were disguised as Facebook ads; ZhongAn Bank had its name used to develop a fake app called ”ZA Repay”; and DBS Bank’s phishing emails used sender addresses disguised as seemingly official domains such as ”@dbsportal.com.”
 
Fourth, fraud has become ”assembly-line style.” On August 10, 2026, alerts regarding ”fraudulent websites and online banking login pages” for Shanghai Commercial Bank, Chong Hing Bank, Overseas-Chinese Banking Corporation, and Chi Yu Bank all pointed to the same set of domain names—carousellref[.]money-receive[.]fun cap (a poem) carousell[.]money-receive[.]fun ...all following the same path. The same set of fake login pages can be deployed in bulk simply by swapping in different banks” logos—this is a classic characteristic of ”industrialized phishing”: build the site once, then ”reuse” it across the entire industry.
 
Fifth, the list specifically displays URLs in a format designed to prevent accidental clicks. All URLs related to the case should be written as carousell[.]xxx This practice of replacing the dot with [.] The purpose of this approach is to prevent readers from falling into a trap after copying the text—they’ve even been extremely careful about the very act of ”exposing the villain.”

II. Behind the Numbers: How Fast Are Phishing Attacks Growing?

A press release issued by the Hong Kong Monetary Authority and the Hong Kong Association of Banks in July 2021 provided a set of illustrative statistics: In the first half of 2021, Hong Kong banks detected a total of 169 cases, compared with the same period in 2020, 69 cases—a significant increase—145%; The number of affected bank customers reached 111 people, involving an amount of approximately 22 million Hong Kong dollarsThe
 
This data represents only the portion that ”was detected by the bank.” The true scale of phishing attacks is usually far greater than the disclosed figures—because a large number of emails are never reported at all before employees click on them.

III. HKMA "Dissects" Phishing Emails: Five Characteristics and One Easily Overlooked Detail

To help the public identify such emails, the Hong Kong Monetary Authority has analyzed counterfeit emails and summarized the following:Five Common Characteristics::
 
  1. No specific recipient name—Anonymous mass email, casting a wide net;
  2. Sender Spoofing—The name and email address displayed may match the bank’s actual records exactly, but the account number has been spoofed;
  3. Create a Sense of Urgency—The content refers to ”important matters,” such as notifications about large-amount transfers or requests to enable new security features, warning that services will be suspended otherwise, and pressuring you to click as soon as possible;
  4. The link doesn't live up to its name—The screen displays the bank’s website address, but the actual domain name is revealed only when the mouse hovers over it;
  5. There is a flaw—Occasional grammatical or spelling errors.
The third point is the one most likely to cause people to let their guard down: fake ”important notices” naturally create a sense of urgency, and when people feel rushed, they tend to skip verification steps. The Hong Kong Monetary Authority also specifically reminds the public:Even if the bank's phone number is printed at the bottom of the email, do not call it directly.—You should verify the customer service hotline yourself through official channels, such as the bank’s official website or physical mail; this is because hackers often include a ”security notice” at the end of phishing emails to make the entire fake email appear more professional and credible.

IV. More Than Just Email: The Battle Over Text Messages, Phone Calls, and Credit Cards

Phishing attempts are not limited to email. The Hong Kong Monetary Authority’s anti-fraud tips cover text messages, phone calls, and credit card-related scenarios:
 
  • Text Message: Text messages claiming to be from a bank and asking you to log in via a link or enter personal information are almost never sent by the bank. Banks do not use text message or email links to guide customers through transactions, nor do they contact customers via pre-recorded voice calls; scammers also often forge local calls with the ”+852” prefix to make the caller ID appear ”legitimate.”
  • Credit Card: Card numbers, expiration dates, the security code on the back of the card, and one-time passwords (OTPs) are the primary targets of scammers. The Hong Kong Monetary Authority (HKMA) advises that before providing credit card information to authorize a transaction, you should first verify the authenticity of the merchant and the website (you can check the police’s ”Anti-Fraud Alert” service); when you receive an OTP text message, verify the transaction type, merchant name, amount, and currency, and be careful that your phone’s ”auto-fill” feature isn’t being exploited; After linking your card to Apple Pay or Google Pay, you will receive a notification from your bank; if you did not initiate the action yourself, contact your issuing bank immediately—because once the card is successfully linked, subsequent small-amount electronic payments may no longer require an OTP.
  • Daily Habits: Review your transaction history and monthly statements regularly; if you notice any suspicious or unauthorized transactions, regardless of the amount, notify the card-issuing bank immediately; if you lose your credit card or suspect that your information has been compromised, notify the bank immediately and report it to the police.
Behind these seemingly trivial reminders lie real-life lessons learned from losses—there is often only a few seconds to make a decision between ”entering your password” and ”completing the transaction.”

V. Regulatory Oversight and the Industry’s Counterattack: A "National Education" Campaign That Has Lasted for Years"

In the face of ever-evolving scams, Hong Kong's regulatory authorities have adopted a ”Alerts + Guidelines + Education“A combination of measures:
 
  • Alert: The Hong Kong Monetary Authority requires banks to promptly issue press releases to notify customers and report any incidents involving fraudulent websites, phishing emails, and the like; the “Beware of Scammers!” page serves as the public face of this alert system.
  • Charter: In June 2023, the Hong Kong Monetary Authority, in collaboration with the Hong Kong Association of Banks, launched the “Consumer Protection and Fraud Prevention Charter.” Participating institutions committed to disseminating fraud prevention alerts to the public through channels such as official websites and apps, providing verifiable contact information, and offering training to frontline staff.
  • Education: Since 2021, the Hong Kong Monetary Authority (HKMA) and the Hong Kong Association of Banks have continued to promote the anti-scam slogan ”Digital KEY: Keep a Close Eye on It, Think Twice Before Clicking a Link.” The police have launched the ”Scameter+” app to allow the public to check suspicious links, while expanding outreach through initiatives such as the ”Citywide Anti-Fraud Grand Raffle”; The HKMA’s official website has also launched a series of anti-fraud videos covering topics such as online dating investment scams, job-seeking money transfer scams, ”complete orders to earn commissions” scams, phishing attacks, and online investment scams, transforming anti-fraud knowledge into “content products”; The Hong Kong Interbank Clearing Limited has also issued a reminder, urging the public to be wary of fake websites.
Regulatory enforcement has certainly been rigorous, and public education efforts have certainly been diligent. But here’s an awkward fact:Scams haven’t decreased as a result; on the contrary, they’ve become more covert and more industrialized.. The reason is that all lines of defense ultimately come down to human judgment—and people are precisely the weakest link that attackers are best at exploiting.

VI. Scammers Don’t Target Systems—They Target People

If you look at the cases on the HKMA’s list as a whole, you’ll notice a common thread: whether it’s fake login pages, phishing emails, or fake apps,There are actually very few technical ”vulnerabilities”; what is truly exploited is human psychology.—A sense of urgency, trust, herd mentality, and an innate trust in ”official channels.” Firewalls and email gateways can block known threats, but they cannot stop a carefully disguised threat that ”just happens to slip through all technical checks.”
This is precisely the essence of social engineering: bypassing machines and targeting people directly. And the only scalable way to counter social engineering is toEquip everyone with the instinct to recognize and resist—This requires systematic, ongoing training, not just a once-a-year safety seminar.

VII. KnowBe4: Turning Employees from the "Weakest Link" into the "First Line of Defense"

This is the world’s largest security awareness training and phishing simulation platform KnowBe4 What we do. KnowBe4 was founded by Stu Sjouwerman in 2010 and currently has over 70,000 organizationsAdopted; Kevin Kevin Mitnick—once known as the “world’s number one hacker” before transitioning to a role as a white-hat security consultant—has long served as the company’s Chief Hacking Officer and personally helped design the classic “Kevin Mitnick Security Awareness Training” (KMSAT) course.
Its methodology is not mysterious, but rather a complete closed-loop system:Assessment → Training → Drill → Feedback...through continuous repetition, transforming “safety education” from a once-a-year lecture into an ongoing civil defense mechanism.
 

Step 1: Baseline Assessment — Start by conducting a “human security checkup” for the organization”

Before the training begins, KnowBe4 will conduct one (or more) simulated phishing attacks to assess the organization’sPhishing-Prone Percentage— In other words, how many employees would click on a phishing link or enter their credentials without any intervention. For KnowBe4, this figure represents an organization’s “human defense baseline”: some organizations exceed 30 percent on their first test, meaning that one out of every three employees could potentially leave the company’s doors wide open. With a baseline in place, the effectiveness of every subsequent training session has a benchmark against which to measure its results.
 

Step 2: Tiered Training — Turning Safety Awareness into “Microlearning”

KnowBe4 boasts the world’s largest library of security awareness training content, featuring over 1,000 course modules—including interactive lessons, short videos, games, posters, and employee presentations—and includes a built-in “ModStore” that allows you to select courses based on employee roles and risk profiles. Most SecurityTrainingWorks courses are broken down into 5–10-minute microlearning modules covering topics such as phishing, social engineering, ransomware, password security, and data protection—all designed to minimize disruption to work time; Training assignments can be automatically scheduled and follow-ups triggered; those who have not completed them will receive reminders—turning “organizational requirements” into “system-automated processes.”

Step 3: Continuous Practice — Trade “One Safe Fishing Trip” for Real Immunity

This is the core component of KnowBe4. The platform includesThousands of realistic phishing email templates...supports an unlimited number of simulation exercises and can be customized based on employee informationTargeted Phishing (Spear Phishing) Scenarios, simulate malicious attachments, track whether employees reply to emails, and leak information. When an MNCCC employee “falls for the trap,” the system immediately pops up a real-time training page, pointing out the specific mistakes they just made—not as a punishment, but to turn a single error into a customized mini-lesson. More importantly, KnowBe4’s PhishER module can also“Wild Fishing” emails reported in actual attacksAutomatically convert them into simulation exercise materials, ensuring that training always keeps pace with the latest real-world threats.
 
The “fake bank websites,” ”fake login pages,“ and ”fund transfer confirmation notices” listed by the Hong Kong Monetary Authority serve as a training ground for employees here ——Only those who have been safely "hooked" once know best how to avoid the real hook.The

Step 4: Quantifying Feedback — Making “Human Risk” Reportable to the Board

Every step of the training and drills is captured as data: changes in the phishing success rate, failure rates by team, phishing email reporting rates, skills assessment scores, and security culture survey results. KnowBe4 uses these metrics to generate risk scores and trend reports, transforming the vague sense that “employees are gullible” intoMeasurable, traceable, reportableHuman-related risk indicators — safety managers can use these to demonstrate the return on investment and pinpoint exactly which departments need the most training.

Take It a Step Further: SecurityCoach Real-Time Coaching—Embedding Training into Workflows

In addition to “regular drills,” KnowBe4 also offersReal-Time Coaching Module: SecurityCoach: By integrating with the company’s existing security products via an API, the system immediately sends a brief security alert via Microsoft Teams, Slack, or email when it detects an employee engaging in risky behavior (such as visiting high-risk websites or entering credentials on suspicious pages), thereby providing education the moment the risk occurs. This is essentially the enterprise-level implementation of the HKMA’s public advisory to “think twice before clicking a link”—except that “thinking twice” has been transformed into a systematic, real-time intervention.
Industry best practices generally hold that through the continuous cycle of “assessment—training — Drills — Feedback,” employees“ ability to recognize phishing attempts improves significantly: employees who were ”easily tricked” in baseline tests often become the most vigilant group after a few rounds of drills. Being tricked once is a fluke; being tricked repeatedly despite ongoing training is the vulnerability that companies truly need to address.

Conclusion

The Hong Kong Monetary Authority uses a continuously updated list to remind the public that scammers never rest, and their tactics are becoming increasingly sophisticated. For individuals, the bottom line is: “Don’t click on links, don’t enter passwords, and verify through official channels.” For organizations, the bottom line should be:Treat security awareness training as a routine investment that is just as important as firewalls and antivirus software. Technology handles the blocking, and people handle the identification—and platforms like KnowBe4 are exactly the solution that fills in that “human” element.

Other Articles

Hongke Dry Goods

[Hongke Solutions] How Can Hong Kong Companies Prevent Phishing and Data Breaches? From Compliance Training to Employee Risk Management

The latest data from Hongke and the PCPD shows a sharp surge in phishing and data breaches in Hong Kong! Relying solely on rigid technical safeguards and annual training is no longer sufficient to prevent AI-powered social engineering. This article provides an in-depth analysis of how Hong Kong B2B enterprises can transition to “Human Risk Management,” effectively comply with the PDPO and financial regulatory requirements, and establish a zero-trust defense against human-related risks.

Read more
Hongke Sharing

[Hongke Insights] How Does TSN Build a Deterministic Foundation for Embodied Intelligence?

Discover how TSN (Time-Sensitive Networking) overcomes the bottlenecks of cable clutter, control latency, and data silos in embodied intelligent robots. Hongke’s TSN IP core offers extreme scheduling precision of ±16 ns and a unified network architecture, enabling precise multi-joint coordination and microsecond-level synchronization to build a highly reliable communication foundation for robots.

Read more
Hongke Case

[Hongke Solutions] AR Smart Healthcare Solution: A Practical Guide to Implementing Remote Consultations and Intraoperative Collaboration

Discover Hongke’s AR Smart Healthcare Solutions! Combining Vuzix AR smart glasses with a remote collaboration platform, these solutions support first-person-view remote consultations, intraoperative demonstrations, pre-hospital emergency care, and medical device after-sales support—freeing up healthcare professionals’ hands and enhancing the efficiency of cross-hospital collaboration. Learn about the key evaluation points for implementation by Hong Kong healthcare institutions today!

Read more

Contact Hongke to help you solve your problems.

Let's have a chat