HONG KONG — The Mandatory Provident Fund Schemes Authority (MPFA) issued a stern warning on June 1st, alerting the public to a new wave of phishing SMS messages and fraudulent websites impersonating the MPFA and the eMPF Platform. Scammers are sending fake SMS claiming that users have “not updated their MPF account personal information,” luring recipients to click embedded links that lead to counterfeit websites designed to steal personal data.
The MPFA has identified two fraudulent websites — “mpf8[.]xyz” and “mp-f[.]org” — which falsely claim that MPF administrative work has been transferred to their platforms. An MPFA spokesperson categorically stated that neither the MPFA nor the eMPF Platform Company Limited has any association with these websites. The official MPFA website is https://www.mpfa.org.hk.
The MPFA and eMPF Company have enrolled in the SMS Sender Registration Scheme established by the Office of the Communications Authority (OFCA). All legitimate MPFA and eMPF SMS messages carry a “#” prefix identifier, including “#MPFA,” “#eMPF,” and “#eMPFsecure.” Official SMS messages are one-way notifications that do not require replies and will never contain hyperlinks asking members to provide personal information or log into their accounts. Any SMS claiming to be from the MPFA without the “#” prefix should be treated as suspicious.
Source: MPFA Press Release (June 1, 2026), MPF.hk

The Mandatory Provident Fund Schemes Authority (MPFA) has identified...
eMPF issues fraud alert reminding members to only access via official...
eMPF's special weekend service hours end July 31; the platform warns of...