Security Tips for UK Mobile Banking


A. Security Practices for Mobile Passcode

1.

Do not use your passport number, national insurance number, telephone number, date of birth, driving licence number, or any simple number sequence (such as 123456) as your Passcode. Avoid using the same numeric character more than once (such as 111111).

2.

Do not disclose your mobile Passcode to anyone. The Bank will never ask you for your Passcode.

3.

Do not send your Passcode via email / SMS or use it as password for accessing other services.

4.

Memorise your Passcode. Do not write it down or store your Passcode and other sensitive information on your phone in a way that can be understood by someone else.

5.

For security reasons, change your Passcode regularly.

6.

Change options on your browser to avoid storing your Passcode on your mobile device.

7.

Change your Passcode immediately if you suspect someone knows it or if you suspect that you have been deceived by a fraudulent website, email, or SMS message to disclose your Passcode.


B. Mobile Device and Email Protection

1.

Maintain adequate security on all devices accessing UK Cyberbanking.

2.

Get our app only from the Apple Store or Google Play Store and ensure that you download the latest version.

3.

Install/update mobile security software if available.

4.

Do not "root" or "jailbreak" your mobile device.

5.

Do not update your mobile operating system via or download mobile apps from untrustworthy sources. You are recommended to set your device to block installation of apps from unknown sources and keep it properly configured.

6.

Carefully read installation and/or permission requests from websites, apps and other software and programs. Be wary of any unusual or unnecessary request.

7.

Do not follow links sent in suspicious emails and SMS messages. Take precautions against hackers, viruses, spyware, and any other malicious software when reading emails, opening attachments, visiting unfamiliar websites, and downloading mobile apps and programs from websites.

8.

Do not browse suspicious websites or click on the hyperlinks and attachments in suspicious emails or messages received through WhatsApp, Line, WeChat, and other e-Communities. Contact the Bank for confirmation immediately whenever a website, SMS, email or other correspondence claiming to originate from the Bank looks suspicious to you.

9.

Disable your mobile device's "AutoFill" or similar option and avoid storing your Username and Passcode on your mobile device.

10.

Disable any wireless network functions that are not in use, such as Wi-Fi, Bluetooth, near-field communication (NFC) or payment apps.

11.

Do not share your mobile device with others or use other people's devices to log in to Cyberbanking. Always lock your mobile device with password protection when not in use, and activate the auto-lock function.

12.

If your device is capable of biometric authentication (e.g. fingerprint or facial recognition), do not let any other person register his/her biometrics on it.

13.

Do not disable any feature that can strengthen the security of biometric authentication, such as "attention awareness" for facial recognition (e.g. ensure that the "Require Attention for Face ID" setting is enabled).


C. Accessing UK Cyberbanking

1.

You should access Cyberbanking from your own mobile device only. Do not use shared mobile devices to access Cyberbanking.

2.

Never Share the One-Time-Password ("OTP") with anyone. The OTP we send you should not be given to anyone (even to the police or us), either verbally or in writing. It should only be entered when using our Cyberbanking.

3.

Make sure that all other browsers are closed before logging in to Cyberbanking.

4.

Only access Cyberbanking through our website www.hkbea.co.uk or our mobile app.

5.

Be alert to your surroundings when performing any online banking transactions and make sure that no one sees you enter your Passcode.

6.

Every time you log in to Cyberbanking, please check to ensure that your Personal Greeting and your last login details are correct.

7.

Do not click on URLs or hyperlinks embedded in any email, SMS, instant message, QR code, search engine, or any untrusted source to log in to Cyberbanking. The Bank will not send emails to the customers with embedded hyperlinks / QR codes to access Cyberbanking.

8.

Always log out and then close the app after each banking session.

9.

Do not leave your mobile device unattended while using Cyberbanking.

10.

Avoid joining untrusted Wi-Fi networks and using public Wi-Fi hotspots to access Cyberbanking.

11.

Do not activate any SMS forwarding function which is supported by your mobile network provider.

12.

Regularly review and follow the security tips issued by the Bank.


D. Other Notes

1.

Check your account activity regularly and inform the Bank immediately if you discover any errors or suspicious/unusual transactions.

2.

Inform the bank immediately whenever you change your mobile phone number or if your phone is lost or stolen to prevent anyone else from accessing the OTP.

3.

Contact the bank immediately, if you ever receive an OTP which you are not expecting.

4.

Keep your bank statements, cheque books, and other important documents in a safe place. If you want to discard any documents that contain your personal information, destroy them first.

5.

Under no circumstances shall the Bank, by way of email /SMS, instant message, phone call or any other method, ask for your personal information, such as your PIN, OTP, or Username and Passcode, data of birth etc. In addition, we will not ask you to access the Bank's website by clicking hyperlinks contained in any email/SMS.

6.

Do not send account information via email, SMS or social networks.




Authorised and regulated by the Hong Kong Monetary Authority. Authorised by the Prudential Regulation Authority. Subject to regulation by the Financial Conduct Authority and limited regulation by the Prudential Regulation Authority. Covered by the Financial Services Compensation Scheme and the Financial Ombudsman Service. Financial Services Register number: 204628.
Jul 2020