2026-07-28

Added · Updated

SFC reprimands and fines Luk Fook Securities (HK) Limited $2.1 million for inadequate cybersecurity control to fend off cyberattack

The Securities and Futures Commission reprimanded Luk Fook Securities (HK) Limited and imposed a $2.1 million fine for failing to implement adequate cybersecurity controls, which contributed to a three-week system recovery delay following a September 2022 ransomware attack. The disciplinary action addresses specific deficiencies including lack of firewall protection, outdated software, weak access controls, and inadequate data backup arrangements. The regulator determined that these systemic failures compromised client interests and operational integrity, constituting misconduct under applicable cybersecurity requirements.

Securities and Futures Commission Hong Kong logo

Hong Kong

Securities and Futures Commission Hong Kong

Click to view thumbnail

Search

Popup advanced search keywords

Advanced search

All of these words:

Any of these words:

The exact phrase:

None of these words:

Popup search form

Close

28 Jul 2026 The Securities and Futures Commission (SFC) has reprimanded and fined Luk Fook Securities (HK) Limited (LFSHK) $2.1 million for failing to implement adequate and effective cybersecurity control measures, which might have contributed to its failure to withstand a ransomware attack and led to a delay of approximately three weeks in fully recovering its systems from the cyberattack (Note 1).

The disruption from the 19 September 2022 ransomware attack on LFSHK’s critical IT infrastructure was sweeping, affecting file servers, domain controllers, email servers, trading application servers, and accounting servers. LFSHK restored its system in phases, and the process was not complete until 7 October 2022.

During the recovery period, LFSHK’s clients were unable to trade via the firm’s mobile trading app or internet platform, and they could only place orders through their account executives.

The SFC conducted an investigation which revealed multiple deficiencies in LFSHK’s cybersecurity policies and systems, following LFSHK’s self-report about the incident in which a hacker exploited the firm’s remote access system to gain entry to its server. These deficiencies, which increased LFSHK’s vulnerability to cyberattacks and contributed to a delay in its recovery from the incident, included:

a lack of firewall protection and adequate network monitoring;

outdated operation systems and antivirus software;

weak controls over user access and privileged accounts;

poor password management practices, such as storing credentials in unencrypted files;

insufficient controls over remote access and external devices;

a lack of regular cybersecurity awareness training for staff; and

inadequate data backup and business continuity arrangements.

In the light of these findings, the SFC is of the opinion that LFSHK is guilty of misconduct after determining that the firm failed to fully comply with the cybersecurity requirements applicable to its regulated activities (Note 2). LFSHK’s systemic failures, reflecting the firm’s failure to meet fundamental cybersecurity requirements mandated under multiple frameworks, have significantly contributed to both its inability to withstand the incident and the severity of its impact, thereby compromising its clients’ interests and the integrity of its operations.

In deciding the disciplinary sanction, the SFC has taken into account all relevant circumstances, including:

LFSHK has conducted reviews to identify the root causes and extent of its failings, including by appointing an independent reviewer at the SFC’s request to conduct an independent assessment of the incident and its cybersecurity related internal controls;

LFSHK has taken steps to enhance its systems and controls to prevent future breaches;

there is no evidence that LFSHK’s clients suffered any loss as a result of its deficiencies;

LFSHK’s co-operation in resolving the SFC’s concerns; and

LFSHK’s clean disciplinary record.

End

Notes:

LFSHK is licensed to carry on Type 1 (dealing in securities), Type 4 (advising on securities) and Type 9 (asset management) regulated activities under the Securities and Futures Ordinance.

Details of the relevant regulatory requirements are set out in the Statement of Disciplinary Action.

A copy of the Statement of Disciplinary Action is available on the SFC website Page last updated 28 Jul 2026