SFC reprimands and fines Luk Fook Securities (HK) Limited $2.1 million for inadequate cybersecurity control to fend off cyberattack

Jul 28, 2026
Latest News SFC SFC reprimands and fines Luk Fook Securities (HK) Limited $2.1 million for inadequate cybersecurity control to fend off cyberattack

On July 28, 2026, the SFC reprimanded and fined Luk Fook Securities ("HK") Limited $2.1 million for inadequate cybersecurity controls following a 2022 ransomware attack that delayed system recovery by approximately three weeks.

This article was generated using SAMS, an AI technology by Timothy Loh LLP.

On July 28, 2026, the Securities and Futures Commission ("SFC") has reprimanded and fined Luk Fook Securities ("HK") Limited ("LFSHK") $2.1 million for failing to implement adequate and effective cybersecurity control measures, which might have contributed to its failure to withstand a ransomware attack and led to a delay of approximately three weeks in fully recovering its systems from the cyberattack.

Operational Disruption and Recovery Timeline

The disruption from the 19 September 2022 ransomware attack on LFSHK’s critical IT infrastructure was sweeping, affecting file servers, domain controllers, email servers, trading application servers, and accounting servers. LFSHK restored its system in phases, and the process was not complete until 7 October 2022. During the recovery period, LFSHK’s clients were unable to trade via the firm’s mobile trading app or internet platform, and they could only place orders through their account executives.

Identified Cybersecurity Deficiencies

The SFC conducted an investigation which revealed multiple deficiencies in LFSHK’s cybersecurity policies and systems, following LFSHK’s self-report about the incident in which a hacker exploited the firm’s remote access system to gain entry to its server. These deficiencies, which increased LFSHK’s vulnerability to cyberattacks and contributed to a delay in its recovery from the incident, included a lack of firewall protection and adequate network monitoring, outdated operation systems and antivirus software, weak controls over user access and privileged accounts, poor password management practices, such as storing credentials in unencrypted files, insufficient controls over remote access and external devices, a lack of regular cybersecurity awareness training for staff, and inadequate data backup and business continuity arrangements.

SFC Findings on Misconduct and Compliance

In the light of these findings, the SFC is of the opinion that LFSHK is guilty of misconduct after determining that the firm failed to fully comply with the cybersecurity requirements applicable to its regulated activities. LFSHK’s systemic failures, reflecting the firm’s failure to meet fundamental cybersecurity requirements mandated under multiple frameworks, have significantly contributed to both its inability to withstand the incident and the severity of its impact, thereby compromising its clients’ interests and the integrity of its operations.

Mitigating Circumstances and Disciplinary Considerations

In deciding the disciplinary sanction, the SFC has taken into account all relevant circumstances, including LFSHK’s reviews to identify the root causes and extent of its failings, such as appointing an independent reviewer at the SFC’s request to conduct an independent assessment of the incident and its cybersecurity related internal controls. LFSHK has taken steps to enhance its systems and controls to prevent future breaches, there is no evidence that LFSHK’s clients suffered any loss as a result of its deficiencies, LFSHK’s co-operation in resolving the SFC’s concerns, and LFSHK’s clean disciplinary record.

Regulatory Licensing and Documentation

LFSHK is licensed to carry on Type 1 (dealing in securities), Type 4 (advising on securities) and Type 9 (asset management) regulated activities under the Securities and Futures Ordinance. Details of the relevant regulatory requirements are set out in the Statement of Disciplinary Action, a copy of which is available on the SFC website. Page last updated 28 Jul 2026.

View the full article:Source

We use cookies to enhance your experience of our websites and to enable you to register when necessary. By continuing to use this website, you agree to the use of these cookies. For more information and to learn how you can change your cookie settings, please see our Cookie Policy and our Privacy Notice.