
Hong Kong's Securities and Futures Commission (SFC) has reprimanded and fined Luk Fook Securities (HK) Limited (LFSHK) HK$2.1 million for failing to implement adequate cybersecurity controls, following a ransomware attack that disrupted its operations and client services.
The cyberattack, which occurred in September 2022, compromised the firm's critical IT infrastructure, including file servers, email systems, trading applications and accounting servers. During the recovery period, clients were unable to access mobile or online trading platforms and could only place orders through account executives. The firm fully restored its systems around three weeks after the incident.
The SFC's investigation found that the attack exploited weaknesses in the firm's remote access system and identified multiple deficiencies in its cybersecurity framework. These included inadequate firewall protection and network monitoring, outdated operating systems and antivirus software, weak user access controls, poor password management, insufficient controls over remote access and external devices, limited staff cybersecurity training, and inadequate data backup and business continuity arrangements.
The regulator concluded that these shortcomings significantly increased the firm's vulnerability to cyberattacks, contributed to the severity of the incident, and failed to meet the cybersecurity standards required for its regulated activities.
In determining the disciplinary action, the SFC considered that LFSHK had commissioned an independent review, strengthened its cybersecurity controls, cooperated fully with the investigation, and had no previous disciplinary record. The regulator also noted that there was no evidence of client financial losses resulting from the incident.