The SFC has reprimanded and fined Luk Fook Securities (HK) Limited HK$2.1 million for systemic failures to implement fundamental cybersecurity controls, which left its core infrastructure vulnerable to a ransomware attack and caused a roughly three‑week disruption to client trading services. This action reinforces that cybersecurity requirements for Hong Kong licensed corporations are treated as core conduct and governance obligations, and that basic control failures (firewalls, patching, access management, backups, training) will be sanctioned even in the absence of direct client financial loss.
What Changed
- - Licensed corporations must ensure that firewall protection and network monitoring are implemented and effective across critical infrastructure, including file servers, domain controllers, email...
- Licensed corporations must maintain up‑to‑date operating systems and antivirus software, avoiding end‑of‑life or unpatched environments that materially increase vulnerability to ransomware and other...
- Firms must enforce strong user access and privileged account controls, including robust administration of system admin accounts, least‑privilege access models, periodic reviews of access rights, and...
- Firms must implement secure password management practices, prohibiting the storage of credentials in unencrypted files and enforcing strong password policies and technical controls for credential...
- Remote access must be subject to strict controls, including secure configuration of VPN or other remote access solutions, need‑to‑have access principles, and monitoring for unusual or unauthorized...
Suggested Considerations
- Conduct a comprehensive cybersecurity risk assessment and control gap analysis across all critical systems, including trading platforms, email servers, domain controllers, file servers, and accounting systems.
- Implement and regularly review firewall configurations and network monitoring tools to ensure effective protection and detection capabilities for internal and external network traffic.
- Upgrade all operating systems and antivirus software to supported, fully patched versions and establish formal patch and vulnerability management procedures with defined timelines and testing steps.
- Establish and enforce robust user access management policies, including least‑privilege access, periodic recertification of user and privileged accounts, and logging and monitoring of admin activities.
- Implement secure password management solutions and technical controls, eliminating unencrypted storage of credentials and enforcing strong password complexity, rotation, and multi‑factor authentication where applicable.
Key Dates
- Approximate three‑week period during which LFSHK’s systems were restored in phases and clients could not trade via mobile app or internet platform, relying only on account executives to place orders
- Ransomware attack on LFSHK’s critical IT infrastructure, affecting servers and core trading‑related systems
- Completion of LFSHK’s system restoration following the ransomware attack
- LFSHK conducted internal reviews and appointed an independent reviewer at the SFC’s request to assess the incident and cybersecurity internal controls; exact dates are not specified but occurred after the attack and prior to enforcement
- SFC issues public disciplinary action reprimanding and fining LFSHK HK$2.1 million for misconduct relating to inadequate cybersecurity controls; the reference number indicates 2026 publication but the precise calendar date is not specified in the excerpt
Compliance Impact
Non‑compliance with SFC cybersecurity requirements and internal control guidelines can lead to findings of misconduct, public reprimands, and significant financial penalties, even where clients do not suffer direct financial loss. Repeated or severe deficiencies may also result in more intrusive supervisory actions, reputational damage, and potential constraints on business operations, particularly for online or technology‑dependent business models.