SFC reprimands and fines Luk Fook Securities (HK) Limited $2.1 million for inadequate cybersecurity control to fend off cyberattack | Securities & Futures Commission of Hong Kong

https://apps.sfc.hk/edistributionWeb/gateway/EN/news-and-announcements/news/doc?refNo=26PR118
Success
Specialism
Product
Obligation
Activity
Themes
Functions
2026-07-29 08:24:52 · pthandapani@vixio.com
Meta Id
3358803
Content ID
3367285
GUID
fea4c087feb624edb3a11709d59eaf44

e-Distribution from the Securities and Futures Commission.

Pipeline Progress

🔄 Pipeline Journey

⏱ 22s total
Queued 08:24:30
+0s
Metadata 08:24:30
+0s
S3 Content 08:24:30
+0s
Extracted 08:24:30
+5s
LLM Gen 08:24:35
+17s
Stored 08:24:52
TITLE: Hong Kong Securities and Futures Commission Fines Luk Fook Securities $2.1 Million for Inadequate Cybersecurity Controls BODY: On July 28, 2026, the Securities and Futures Commission (SFC) reprimanded and fined Luk Fook Securities (HK) Limited (LFSHK) $2.1 million for failing to implement adequate and effective cybersecurity control measures. The firm's deficient controls contributed to its inability to withstand a ransomware attack on September 19, 2022, and resulted in approximately three weeks of system recovery time until October 7, 2022. The September 2022 cyberattack compromised LFSHK's critical IT infrastructure, including file servers, domain controllers, email servers, trading application servers, and accounting servers. During the recovery period, clients could not trade via the firm's mobile trading app or internet platform and could only place orders through account executives. The SFC's investigation identified multiple systemic cybersecurity deficiencies that increased LFSHK's vulnerability to attack and delayed recovery. These included: lack of firewall protection and adequate network monitoring; outdated operating systems and antivirus software; weak user access and privileged account controls; poor password management practices, including storing credentials in unencrypted files; insufficient remote access and external device controls; lack of regular cybersecurity awareness training for staff; and inadequate data backup and business continuity arrangements. The hacker exploited LFSHK's remote access system to gain entry to its servers. The SFC determined that LFSHK failed to fully comply with cybersecurity requirements applicable to its regulated activities under the Securities and Futures Ordinance. LFSHK holds licences for Type 1 (dealing in securities), Type 4 (advising on securities), and Type 9 (asset management) activities. In mitigation, the SFC considered that LFSHK appointed an independent reviewer to assess the incident, implemented system enhancements, cooperated with the SFC, maintained a clean disciplinary record, and no clients suffered losses from the deficiencies.
  • Scraped:2026-07-29 08:24:52
  • Created:2026-07-29 08:24:52
  • By:pthandapani@vixio.com (6)