Important Notice: Ensuring Phishing-Resistant
Authentication for SFC Compliance

To our Valued Partners and Clients,
The Securities and Futures Commission (SFC) has issued Circular 26EC35 on 9 July 2026, mandating that internet brokers and Virtual Asset Service Providers (VASPs) in Hong Kong transition away from SMS/Email-based One-Time Passwords (OTP) toward phishing-resistant authentication.
To protect your business and your clients from the rising threat of AI-enabled phishing attacks and account takeovers, NetMon—as the official distributor of Yubikeys in Hong Kong—is committed to guiding you through this transition before the July 8, 2027, deadline.
A. The SFC Mandate: What You Need to Know
The SFC expects all internet brokers and VASPs to implement robust, phishing-resistant solutions for both client logins and device binding. OTPs are no longer considered sufficient as they are vulnerable to interception via Man-in-the-Middle (MitM) and phishing attacks.
Key compliance takeaways:
● Deadline: Full implementation must be completed by 8 July 2027.
● Requirement: Transition to phishing-resistant methods, such as hardware-backed FIDO keys or secure passkeys, to mitigate hacking risks.
● Liability: Firms are held liable for client losses resulting from inadequate security controls.
B. Frequently Asked Questions (FAQ)
1. What is Passkey
A passkey is a phishing‑resistant, passwordless authentication credential built on the open FIDO2 / WebAuthn standard maintained by the FIDO Alliance and W3C.
2. Are all Passkeys the same?
No. While software-based passkeys offer convenience, they are often synced to the cloud, making them vulnerable to remote account hijacking if your device or cloud account is compromised. Hardware-backed keys (like YubiKey) store private keys on an isolated, physical secure element that cannot be extracted, copied, or synced to the cloud.
3. What kinds of YubiKeys should be used?
For financial institutions, we recommend the YubiKey 5 Series. It supports multiple protocols (FIDO2/WebAuthn, PIV, OpenPGP, OATH-TOTP) simultaneously, allowing you to bridge legacy and modern infrastructure without custom middleware.
4. What are the best practices when using YubiKey?
● Dual-Key Strategy: Always issue a primary and a backup key to clients to prevent lockouts.
● Phased Rollout: Prioritize high-value accounts, admins, and institutional clients first.
● Phased Rollout: Prioritize high-value accounts, admins, and institutional clients first.
● Integration: Utilize FIDO2-compliant identity platforms (e.g., Microsoft Entra ID, Okta) to simplify the implementation architecture.
5. Why should Passkey in mobile devices not be used?
Mobile devices are subject to Remote Access Trojans (RATs) and malware that can intercept authentication prompts. Hardware keys require a physical touch, ensuring that the authentication process cannot be triggered or hijacked remotely by attackers.
6. Can I use YubiKey for other purposes?
Yes. Beyond trading account security, the YubiKey 5 Series can be used for secure access to corporate VPNs, password managers, cloud services (AWS, Google Cloud), and physical office access, providing a unified security posture across your entire organization.
C. Why Choose NetMon for Your SFC Compliance Journey?
NetMon provides more than just hardware. We offer:
● Regulatory Readiness: Pre-audit support to ensure your architecture meets SFC expectations.
● Rapid Deployment: Local fulfilment in Hong Kong to avoid global supply chain delays.
● Expert Consulting: Architecture design tailored for broker trading platforms.
The benefits of purchasing through an official distributor of Yubikeys in Hong Kong:
● One-year product warranty: Unlike other channels, we provide a full one-year warranty. Troubleshooting and replacements are handled directly through our streamlined process, ensuring minimal downtime even in the rare event of an issue.
● Guaranteed Authenticity: Avoid the critical security risks associated with counterfeit hardware. Buying from an official distributor ensures you receive genuine, certified products, protecting your infrastructure from the vulnerabilities of "grey market" goods.
● Direct Access to Technical Expertise: Gain exclusive access to our certified technical support team. We provide expert guidance on configuration, deployment, and ongoing optimization tailored to SFC compliance requirements.
● Official Product Lifecycle Support: Stay current with guaranteed access to the latest firmware, security patches, and software updates, ensuring your compliance posture remains resilient against evolving threats.
● Local Inventory & Faster Lead Times: Benefit from our dedicated local inventory in Hong Kong, ensuring faster delivery and consistent product availability compared to non-authorized, cross-border shipping channels.
● Compliance Documentation: Receive full, audit-ready documentation and proof-of-origin for every unit, simplifying your internal and external reporting processes for regulatory compliance.Ready to start your compliance roadmap?
Contact our team today to request a YubiKey Evaluation Kit or to schedule a consultation with our technical architects.
Disclaimer: This announcement is for informational purposes. Please refer to the official SFC Circular 26EC35 for detailed regulatory obligations.
