Hong Kong SFC Takes Enforcement Action Against Firm for Cybersecurity Deficiencies Client Alert | August 12, 2026 This is, in our view, intended as a pointed reminder to the market that the SFC expects licensed corporations to maintain robust cybersecurity frameworks – and is willing to take action against firms whose frameworks fail to meet their expectations, even if clients are not directly affected. On July 28, 2026, the Securities and Futures Commission (SFC) reprimanded and fined Luk Fook Securities (HK) Limited (LFSHK) HK$2.1 million for failing to implement adequate and effective cybersecurity control measures.[1] While the fine itself is not large, this matter is notable given that it is the first known example of the SFC taking disciplinary action against a licensed corporation because of a cyberattack against the firm’s trading systems. Importantly, the SFC took action notwithstanding the absence of client asset misappropriation, unauthorized trading, client complaints or client financial loss – factors which the SFC treated as mitigating rather than exculpatory. This is, in our view, intended as a pointed reminder to the market that the SFC expects licensed corporations to maintain robust cybersecurity frameworks – and is willing to take action against firms whose frameworks fail to meet their expectations, even if clients are not directly affected. I. SFC ENFORCEMENT ACTION LFSHK is licensed to carry on Type 1 (dealing in securities), Type 4 (advising on securities) and Type 9 (asset management) regulated activities. During the COVID-19 pandemic, LFSHK enabled remote working through a VMware virtual environment, which allowed employees, third-party vendors, and IT staff to access office systems remotely. On September 19, 2022, a hacker exploited the VMware environment to gain access to LFSHK’s Active Directory (AD) server. The SFC described the resulting disruption to LFSHK’s critical IT infrastructure as sweeping, extending to its file