Cybersecurity firms have warned of a new wave of AI-powered phishing attacks targeting financial institutions in Hong Kong, Singapore, and Tokyo.

The attack uses large language models to generate highly convincing email messages that mimic the writing style of senior executives. Unlike traditional phishing attempts, these messages are grammatically flawless and contextually relevant, making them extremely difficult to detect.

“This represents a significant evolution in social engineering attacks,” said a researcher at a leading security firm. “The AI can adapt its tone and content based on the victim’s role and recent activities.”

Security experts recommend implementing multi-factor authentication, conducting regular phishing simulations, and using AI-assisted email filtering solutions to combat this threat.

HKISG advises organisations to review their email security policies and ensure staff are trained to identify suspicious communications, even when they appear legitimate.

Hong Kong operator checklist

  1. Confirm whether the systems, vendors, or practices described apply to your estate.
  2. Assign an owner and a review date — do not leave findings as unread newsletter content.
  3. Capture evidence (configs, tickets, screenshots) if you later enter a Trust Review.
  4. Brief leadership with a dated one-page note when residual risk remains high.

What “good” looks like

  • Controls are operated, not only documented
  • Privileged access uses phishing-resistant MFA where feasible
  • Detection and response paths are exercised at least annually
  • Third-party dependencies have an owner and an exit plan

Sources and further reading

Editorial note

This page is published by the Hong Kong Information Security Group (HKISG) for educational and early-warning purposes. It is not a substitute for legal advice, formal audit opinions, or national CERT coordination.

Frequently asked questions

Who should read this?

Security, IT, and risk owners in Hong Kong organisations who need practical context rather than marketing claims.

Does this change any public HKISG rating?

No. TrustScores are produced only through the published Trust Review / Awards process. Reading this page does not alter scores.

How often is this content reviewed?

HKISG dates publications and retains corrections under our editorial standards. Check the updated field in the page header when present.