Lukfook Securities was criticized and fined HK$2.1 million by the Hong Kong Securities Regulatory Commission for insufficient cyber security surveillance measures to withstand cyber attacks

Zhitongcaijing · 1d ago

The Zhitong Finance App learned that the Hong Kong Securities Regulatory Commission condemned Lukfook Securities (Hong Kong) Limited (Lukfook Securities) and fined HK$2.1 million because the company did not implement sufficient and effective cyber security monitoring measures, which may cause Lukfook Securities to be unable to withstand the ransomware attack and delay the full recovery of its system from this cyber attack by about three weeks.

The September 19, 2022 ransomware attack caused widespread disruption to Lukfook Securities' critical IT infrastructure, affecting file servers, domain controllers, email servers, trading application servers and accounting servers. Lukfook Securities restored its system in stages, and the relevant process was not completed until October 7, 2022.

During the recovery period, customers of Lukfook Securities will not be able to trade through the company's mobile trading app or internet platform; they can only issue trading instructions through their account director.

The Securities Regulatory Commission launched an investigation after Lukfook Securities voluntarily reported that a hacker had used the company's remote access system to hack into its server and discovered that Lukfook Securities' network security policies and systems were lacking in many cases. These omissions made Lukfook Securities more vulnerable to cyber attacks and delayed the company's recovery from the incident, including:

Lack of firewall protection and adequate network monitoring;

Outdated operating systems and anti-virus software;

Weak surveillance measures for user access and privileged accounts;

Poor password management practices, such as storing credentials in unencrypted files;

inadequate monitoring measures for remote access and external devices;

lack of regular cyber security awareness training for employees; and

Data backup and business continuity arrangements are inadequate.

In light of the above findings, the Securities Regulatory Commission determined that Lukfook Securities had not fully complied with the cybersecurity requirements applicable to its regulated activities and concluded that the company had misbehaved. Lukfook Securities' systemic deficiencies reflect the company's failure to meet the basic cyber security requirements set out in various frameworks. It is also the main reason why the company was unable to withstand the incident and its serious impact, thereby harming the company's customer interests and operational soundness.

The Securities Regulatory Commission has taken into account all relevant circumstances when deciding to take the above disciplinary action, including:

Lukfook Securities has carried out a review to identify the root cause and scope of its absence, including appointing an independent review agency at the request of the Securities Regulatory Commission to conduct an independent assessment of the incident and internal control measures relating to network security;

Lukfook Securities has taken steps to improve its systems and monitoring measures to prevent future irregularities;

There is no evidence that Lukfook Securities customers have suffered any losses due to the company's omission;

Lukfook Securities has shown cooperation in addressing concerns raised by the Securities Regulatory Commission; and

Lukfook Securities has no record of being subject to disciplinary action in the past.