According to the Hong Kong Securities and Futures Commission (SFC), the regulator has censured Chuk Fook Securities (Hong Kong) Limited and imposed a penalty of HK$2.1 million due to inadequate and ineffective cybersecurity monitoring measures. On September 19, 2022, the firm suffered a ransomware attack that disrupted critical IT infrastructure including file servers, domain controllers, email servers, trading application servers, and accounting servers. System recovery was delayed by approximately three weeks and completed by October 7, 2022.
During the outage, clients could not trade through the firm's mobile app or web platform and had to submit orders via account managers. The SFC's investigation identified multiple cybersecurity deficiencies including lack of firewall protection and network monitoring, outdated operating systems, weak user access controls, poor password management practices, insufficient remote access monitoring, insufficient staff cybersecurity training, and inadequate data backup arrangements. These systemic failures prevented the firm from adequately defending against the attack and prolonged recovery efforts, thereby damaging client interests and operational resilience.