SFC Fines Luk Fook Securities Over Cybersecurity Failures Tied to Ransomware Attack | LeapRate
Hong Kong’s Securities and Futures Commission (SFC) has reprimanded and fined Luk Fook Securities (HK) Limited (LFSHK) $2.1 million after finding the firm failed to implement adequate cybersecurity controls, a lapse that may have contributed to its inability to withstand a ransomware attack in 2022.
The attack, which struck on 19 September 2022, hit LFSHK’s critical IT infrastructure across the board, disrupting file servers, domain controllers, email servers, trading application servers and accounting servers. The firm did not fully restore its systems until 7 October, nearly three weeks later. During that period, clients were locked out of the firm’s mobile trading app and internet platform, forced instead to place orders through account executives.
Following LFSHK’s self-report, the SFC launched an investigation and uncovered a string of deficiencies. These included a lack of firewall protection, outdated operating systems and antivirus software, weak controls over user access, poor password management practices such as storing credentials in unencrypted files, insufficient oversight of remote access and external devices, no regular cybersecurity training for staff, and inadequate data backup arrangements.
The regulator concluded that LFSHK had breached cybersecurity requirements tied to its regulated activities, calling the failures systemic and damaging to both client interests and the integrity of its operations.
In setting the penalty, the SFC noted mitigating factors, including LFSHK’s cooperation, its clean disciplinary record, remedial steps taken since the incident, an independent review of the breach, and the absence of evidence that clients suffered financial losses as a result.