1. Introduction In the mid-2000s, as online banking grew, so did the threat of sophisticated cyber attacks—particularly Man-in-the-Middle (MitM) and Man-in-the-Browser (MitB) attacks. Simple passwords proved insufficient. HSBC, like several other global banks, responded by deploying PINsentry : a physical device that generates one-time passcodes (OTPs) to authenticate high-risk transactions and logins.

PINsentry was a pioneering and highly secure 2FA solution that protected millions from online fraud. In 2026, it feels dated but remains a gold standard for transaction-level security—at the cost of convenience. For most users, HSBC’s mobile authenticator offers a better balance. For those requiring maximum protection against remote attacks (and willing to carry an extra gadget), PINsentry still delivers. Disclaimer: This write-up reflects general knowledge about HSBC PINsentry as of 2026. Features and availability vary by country and account type. Always refer to HSBC’s official documentation.

This site uses cookies and related technologies for site operation, analytics, and third party advertising purposes as described in our Privacy and Data Processing Policy. You may choose to consent to our use of these technologies or reject non-essential technologies. To opt-out of sharing with third parties information related to these technologies, select "Decline All".