Luk Fook Securities (HK) Limited has been reprimanded and fined $2.1 million by the Securities and Futures Commission (SFC) for failing to implement adequate cybersecurity controls that could have prevented a significant ransomware attack. The Hong Kong regulator determined that the firm’s systemic security deficiencies contributed to the breach and a three-week recovery period following the 19 September 2022 incident.

  • Attack Date: 19 September 2022
  • Full Recovery Date: 7 October 2022
  • Penalty Amount: $2.1 million
  • Impact Duration: Approximately three weeks of system unavailability

The ransomware attack compromised critical infrastructure across Luk Fook Securities, affecting file servers, domain controllers, email systems, trading application servers, and accounting infrastructure. During the recovery period, clients lost access to the firm’s mobile trading application and internet platform, forcing them to place orders exclusively through account executives. The SFC’s investigation revealed that a hacker exploited inadequate remote access controls to breach the system.

The regulator identified seven categories of cybersecurity failures, including lack of firewall protection and network monitoring, outdated operating systems and antivirus software, weak user access controls, poor password management practices, insufficient remote access controls, inadequate staff training, and deficient data backup arrangements. The SFC concluded that these systemic failures reflected the firm’s inability to meet fundamental cybersecurity requirements mandated across multiple regulatory frameworks, thereby compromising client interests and operational integrity.

In determining the penalty, the SFC considered mitigating factors including Luk Fook Securities‘ self-report of the incident, subsequent remediation efforts, appointment of an independent reviewer, cooperation with regulators, clean disciplinary record, and the absence of client losses. The firm is licensed to conduct Type 1 (dealing in securities), Type 4 (advising on securities), and Type 9 (asset management) regulated activities.

By Gavriel Gavrielides

Gavriel Gavrielides is the Founder and Chief Editor of fintech-intelligence. An ACA-qualified finance executive, he previously served as Group CFO and Global Head of Accounting & Finance for a major international Forex broker with over 800 employees, following a foundational career as an auditor at a Big Four firm. Having spent over 15 years navigating complex international regulatory frameworks, scaling financial infrastructure, and managing global corporate strategies, Gavriel launched fintech-intelligence because he recognized that the traditional boundaries between finance and technology have completely dissolved. He saw a critical need for an industry publication driven by actual operational expertise rather than outside commentary. Today, Gavriel leverages his deep institutional background to cut through the market noise, delivering high-signal, deeply analytical insights into the technologies, regulations, and innovations reshaping the future of money. Connect with Gavriel on https://www.linkedin.com/in/gavriel-gavrielides-103734124/