← Back to Home News · HK

SFC fines Luk Fook Securities HK$2.1 million over ransomware control failures

Make RegTech.com preferred on Google
SFC fines Luk Fook Securities HK$2.1 million over ransomware control failures
The SFC reprimanded and fined Luk Fook Securities (HK) Limited HK$2.1 million on 28 July 2026 over cybersecurity control failures behind a September 2022 ransomware attack.
AI Summary
  • Hong Kong’s SFC has reprimanded and fined Luk Fook Securities (HK) Limited HK$2.1 million over cybersecurity control failures that left it unable to withstand a ransomware attack in September 2022.
  • A hacker exploited the firm’s remote access system on 19 September 2022 and deployed ransomware that hit its file, domain, email, trading and accounting servers. Systems were fully restored only on 7 October, about three weeks later, and clients could trade only through their account executives in the meantime. The SFC found no evidence that clients suffered any loss.
  • The regulator listed deficiencies spanning firewalls and network monitoring, outdated systems, access and password controls, remote-access controls, staff training and backups. The action shows the SFC will penalise weak cyber controls in their own right, even where no client lost money.

On 28 July 2026, the Securities and Futures Commission (SFC) reprimanded and fined Luk Fook Securities (HK) Limited HK$2.1 million over cybersecurity control failures that left the firm unable to withstand a ransomware attack in 2022.

The attack happened in 2022

According to the SFC, a hacker exploited the firm’s remote access system on 19 September 2022 to get into its servers, then deployed ransomware. The attack hit a wide spread of infrastructure; the SFC lists file servers, domain controllers, email servers, trading application servers and accounting servers. Recovery was slow. The firm restored its systems in phases, with full restoration only on 7 October 2022, roughly three weeks later. During that window, clients could not use the mobile app or the internet trading platform and could only place orders through their account executives.

Notably, the SFC found no evidence that the firm’s clients suffered any loss as a result of the deficiencies, and the release does not allege that client data was stolen. The action is about the weakness of the controls themselves, not a downstream loss.

The control failures

The SFC set out a list of basic defence deficiencies:

  • inadequate firewall protection and network monitoring;
  • outdated operating systems and antivirus software, in other words unpatched legacy systems;
  • weak user access and privileged-account controls;
  • poor password management, including storing credentials without encryption;
  • insufficient controls over remote access and external devices;
  • a lack of regular staff cybersecurity training;
  • inadequate data backup and business-continuity arrangements.

No specific rule in numbers is mentioned in the press release, saying the detail sits in a separate Statement of Disciplinary Action, but licensed firms in Hong Kong operate under the SFC’s Code of Conduct and its cybersecurity guidelines for internet trading, which set baseline expectations for these controls. The failures here map onto those expectations point by point.

What worked in the firm’s favour

The penalty could have been heavier. The SFC took account of several mitigating factors: the firm carried out reviews to find the root causes, including by appointing an independent reviewer; it took remedial steps to strengthen its systems and controls; there was no evidence of client loss; it cooperated in resolving the SFC’s concerns, and it had a clean disciplinary record. That combination of self-diagnosis, remediation and cooperation is the well-worn path to a lighter outcome, and it is worth noting because it tells other firms what to do if they find themselves in the same position.

Why it matters for brokers

Cyber resilience is now an enforceable obligation in its own right. The specifics of this case double as a checklist. 

The case also fits a wider run of security and resilience failures the regulators are now acting on, from Hong Kong’s own stablecoin sector, where a licensed issuer failed an independent security review, to wallet providers hit by customer-data breaches. The common thread is that supervisors are increasingly willing to treat operational and cyber resilience as a front-line compliance duty. 

For Hong Kong’s licensed corporations, the Luk Fook fine is a concrete reminder that the SFC will look at the plumbing behind the trading screen and act on what it finds, even when customers never noticed.

Link copied to clipboard
AI Bot
AI Bot
Hi! I'm the RegTech.com assistant. How can I help you today?
Ask me anything — top trending news, latest regulatory changes in the EU, or simply search for topics.