On 28 July 2026, the Securities and Futures Commission (SFC) reprimanded and fined Luk Fook Securities (HK) Limited HK$2.1 million over cybersecurity control failures that left the firm unable to withstand a ransomware attack in 2022.
The attack happened in 2022
According to the SFC, a hacker exploited the firm’s remote access system on 19 September 2022 to get into its servers, then deployed ransomware. The attack hit a wide spread of infrastructure; the SFC lists file servers, domain controllers, email servers, trading application servers and accounting servers. Recovery was slow. The firm restored its systems in phases, with full restoration only on 7 October 2022, roughly three weeks later. During that window, clients could not use the mobile app or the internet trading platform and could only place orders through their account executives.
Notably, the SFC found no evidence that the firm’s clients suffered any loss as a result of the deficiencies, and the release does not allege that client data was stolen. The action is about the weakness of the controls themselves, not a downstream loss.
The control failures
The SFC set out a list of basic defence deficiencies:
- inadequate firewall protection and network monitoring;
- outdated operating systems and antivirus software, in other words unpatched legacy systems;
- weak user access and privileged-account controls;
- poor password management, including storing credentials without encryption;
- insufficient controls over remote access and external devices;
- a lack of regular staff cybersecurity training;
- inadequate data backup and business-continuity arrangements.
No specific rule in numbers is mentioned in the press release, saying the detail sits in a separate Statement of Disciplinary Action, but licensed firms in Hong Kong operate under the SFC’s Code of Conduct and its cybersecurity guidelines for internet trading, which set baseline expectations for these controls. The failures here map onto those expectations point by point.
What worked in the firm’s favour
The penalty could have been heavier. The SFC took account of several mitigating factors: the firm carried out reviews to find the root causes, including by appointing an independent reviewer; it took remedial steps to strengthen its systems and controls; there was no evidence of client loss; it cooperated in resolving the SFC’s concerns, and it had a clean disciplinary record. That combination of self-diagnosis, remediation and cooperation is the well-worn path to a lighter outcome, and it is worth noting because it tells other firms what to do if they find themselves in the same position.
Why it matters for brokers
Cyber resilience is now an enforceable obligation in its own right. The specifics of this case double as a checklist.
The case also fits a wider run of security and resilience failures the regulators are now acting on, from Hong Kong’s own stablecoin sector, where a licensed issuer failed an independent security review, to wallet providers hit by customer-data breaches. The common thread is that supervisors are increasingly willing to treat operational and cyber resilience as a front-line compliance duty.
For Hong Kong’s licensed corporations, the Luk Fook fine is a concrete reminder that the SFC will look at the plumbing behind the trading screen and act on what it finds, even when customers never noticed.
