Live Updates

SFC reprimands and fines Luk Fook Securities (HK) Limited $2.1 million for inadequate cybersecurity control to fend off cyberattack

AI Analysis

Executive Summary

The SFC has reprimanded and fined Luk Fook Securities (HK) Limited HK$2.1 million for systemic failures to implement fundamental cybersecurity controls, which left its core infrastructure vulnerable to a ransomware attack and caused a roughly three‑week disruption to client trading services. This action reinforces that cybersecurity requirements for Hong Kong licensed corporations are treated as core conduct and governance obligations, and that basic control failures (firewalls, patching, access management, backups, training) will be sanctioned even in the absence of direct client financial loss.

What Changed

  • - Licensed corporations must ensure that firewall protection and network monitoring are implemented and effective across critical infrastructure, including file servers, domain controllers, email servers, trading application servers, and accounting s
  • Licensed corporations must maintain up‑to‑date operating systems and antivirus software, avoiding end‑of‑life or unpatched environments that materially increase vulnerability to ransomware and other cyberattacks.
  • Firms must enforce strong user access and privileged account controls, including robust administration of system admin accounts, least‑privilege access models, periodic reviews of access rights, and monitoring of privileged activity.
  • Firms must implement secure password management practices, prohibiting the storage of credentials in unencrypted files and enforcing strong password policies and technical controls for credential protection.
  • Remote access must be subject to strict controls, including secure configuration of VPN or other remote access solutions, need‑to‑have access principles, and monitoring for unusual or unauthorized remote sessions.
  • Firms must implement controls over external devices (e.g., USB drives, external storage), including policies, technical restrictions, and monitoring to prevent malware introduction or data exfiltration.

Suggested Considerations

  • Conduct a comprehensive cybersecurity risk assessment and control gap analysis across all critical systems, including trading platforms, email servers, domain controllers, file servers, and accounting systems.
  • Implement and regularly review firewall configurations and network monitoring tools to ensure effective protection and detection capabilities for internal and external network traffic.
  • Upgrade all operating systems and antivirus software to supported, fully patched versions and establish formal patch and vulnerability management procedures with defined timelines and testing steps.
  • Establish and enforce robust user access management policies, including least‑privilege access, periodic recertification of user and privileged accounts, and logging and monitoring of admin activities.
  • Implement secure password management solutions and technical controls, eliminating unencrypted storage of credentials and enforcing strong password complexity, rotation, and multi‑factor authentication where applicable.
  • Review and harden remote access solutions (such as VPNs and remote desktop services), restricting access to a need‑to‑have basis, enforcing strong authentication, and monitoring for anomalous remote access patterns.

Key Dates

19 September 2022 – 7 October 2022
- Approximate three‑week period during which LFSHK’s systems were restored in phases and clients could not trade via mobile app or internet platform, relying only on account executives to place orders
19 September 2022
- Ransomware attack on LFSHK’s critical IT infrastructure, affecting servers and core trading‑related systems
7 October 2022
- Completion of LFSHK’s system restoration following the ransomware attack
TBD (post‑incident)
- LFSHK conducted internal reviews and appointed an independent reviewer at the SFC’s request to assess the incident and cybersecurity internal controls; exact dates are not specified but occurred after the attack and prior to enforcement
TBD (enforcement publication date)
- SFC issues public disciplinary action reprimanding and fining LFSHK HK$2.1 million for misconduct relating to inadequate cybersecurity controls; the reference number indicates 2026 publication but the precise calendar date is not specified in the excerpt

Compliance Impact

Non‑compliance with SFC cybersecurity requirements and internal control guidelines can lead to findings of misconduct, public reprimands, and significant financial penalties, even where clients do not suffer direct financial loss. Repeated or severe deficiencies may also result in more intrusive supervisory actions, reputational damage, and potential constraints on business operations, particularl

Who is Affected

Hong Kong licensed corporations under the Securities and Futures Ordinance carrying on Type 1 (dealing in securities), Type 4 (advising on securities), and Type 9 (asset management) regulated activities.Internet brokers and online trading platform operatorsVirtual asset trading platforms and service providersSenior management, responsible officers, and compliance officersIT, information security, and operations teams

AI-generated analysis. May contain errors or omissions — verify with the original SFC source before acting. Full disclaimer.

Summary

No description available.

Relevant Firm Types

Broker DealerAsset ManagerWealth ManagerAll Firms
View Original on SFC Back to Feed

Share this update