Guide

Five data breaches that hit Hong Kong, and what they really cost

5 min read

A Hong Kong data breach usually reaches the news as a number. Nine million records. Three million voters. What matters to a business owner is what came next. Weeks of disruption. Staff doing nothing else for a fortnight. A letter from the regulator. Customers who quietly stopped calling.

Below are five incidents that really happened here, all publicly reported. None of them involved a small business. That is the point. Each one started in a way that reaches small firms every week, just without the coverage.

Cathay Pacific, 2018: 9.4 million records and four years exposed

In October 2018 Cathay Pacific disclosed that the personal data of about 9.4 million passengers had been accessed without permission. Names, dates of birth, phone numbers, passport numbers and some Hong Kong identity card numbers were involved. The unauthorised access had been going on since 2014.

The bill arrived in pieces. The UK data protection regulator fined the airline £500,000, the maximum available under the law that applied at the time, pointing to unencrypted backups, out of date software and servers reachable from the internet. Hong Kong's Privacy Commissioner issued an enforcement notice. Then came months of coverage, most of it about how long the airline took to tell anyone.

The lesson for a smaller firm is not about scale. It is about the gap. Cathay took months to inform customers after spotting the problem. Most small businesses have a worse gap. They never find out at all. A customer tells them, usually by asking why they received a strange invoice.

Cyberport and the Consumer Council, 2023: locked out of your own files

Ransomware puts a padlock on your own filing cabinet and then sells you the key. Two well known Hong Kong organisations met it in the same year.

Cyberport reported a data breach to the Privacy Commissioner in August 2023. The investigation report, published in April 2024, found the personal data of more than 13,000 people had leaked, about 40% of them former staff and unsuccessful job applicants. Two findings matter for any business. Security checks were infrequent, and personal data was being kept long after there was any reason to keep it. The attackers got in by guessing an administrator password on a remote access connection.

A month later the Consumer Council was hit. Roughly 80% of its computer systems were damaged and the attackers demanded USD 500,000. The Council refused to pay. That was the right call and also the expensive one, because refusing means rebuilding, and rebuilding means services offline and staff pulled off their real jobs.

Verizon's 2024 breach report found that 88% of breaches at small businesses involve ransomware or extortion. Smaller firms get the extortion version because it is the model that pays when there is no huge customer database worth reselling.

Arup, 2024: HK$200 million lost on a video call

In early 2024 a finance employee at the Hong Kong office of engineering firm Arup transferred about HK$200 million, roughly USD 25 million, to criminals. It began with an email claiming to be from the chief financial officer. The employee was suspicious, so he joined a video call with the CFO and several colleagues. Everyone else on that call was a deepfake. Fifteen transfers went out. Arup confirmed the incident in May 2024.

This is fraud rather than a leak of records, and it belongs on the list because of where it started. Public information. Who works there, who reports to whom, what a payment request normally looks like. Your website, your team page and your public domain records give away more of that than most owners realise.

The stolen laptops, 2017: a breach with no hacker

In March 2017 two laptops were stolen from a locked room at AsiaWorld-Expo, the fallback venue for the Chief Executive election. One held the names, addresses and identity card numbers of all 3.78 million registered voters. No malware, no phishing, no 網絡攻擊 of any kind. Someone carried a bag out of a room.

The government said the data was encrypted, and there is no public evidence it was ever used. The Privacy Commissioner still found the Registration and Electoral Office had failed to take adequate steps to protect it. That distinction is worth holding on to. You can fall short of the standard without anybody suffering a loss.

The small business version is a laptop left in a taxi, a phone with the company email still logged in, or a departing employee whose account was never switched off.

What it really costs a smaller business

IBM put the average global cost of a data breach at USD 4.88 million in 2024. Ignore that figure. It is an average shaped by banks and hospitals with thousands of staff. Your version is smaller and still serious. It is a few days when you cannot take bookings or orders. It is you and your office manager doing nothing else for two weeks. It is money that left the account and is not coming back, an enquiry from the Privacy Commissioner that you have to fund, and the customers who never say a word and never return.

資料外洩 makes the news when the number runs to millions. The version that hurts a twenty person company never gets reported at all.

The direction of travel is clear. HKCERT handled 12,536 security incidents in Hong Kong in 2024, the highest in five years. Phishing was about 62% of them, up 108% on the year before. IBM has noted that AI can now write a convincing phishing email in around five minutes, against roughly 16 hours by hand. Volume and quality are rising together.

Most of it is not aimed at anyone in particular. Our own scan of 214 Hong Kong business websites found an average exposure score of 41 out of 100, and 72% had at least one finding we rate high or critical. 62% had no DMARC, which means anyone can send an email that appears to come from their company address. 17% publish the owner's personal name and contact details in public WHOIS records, the registration file attached to every domain name.

Where to start this week

None of the following needs an IT department.

  • Ask whoever manages your domain to set up SPF, DKIM and DMARC. They are three settings that let receiving mail servers spot a forgery of your address, a bit like a chop on your letterhead.
  • Turn on two step login for email and accounting software, starting with the owner and anyone who handles payments.
  • Write down one payment rule. Any change of bank details gets confirmed by calling a number you already had on file, never a number from the email or the call itself.
  • Switch on domain privacy so your home address and mobile number are not sitting in public records.
  • Close the accounts of people who have left. Check this week, not at year end.
  • Keep one backup that is not connected to your network, and restore a single file from it this month to prove it works.

Every incident above began with something visible from the outside, whether that was an open remote connection, a public team page or an email address anyone could imitate. It costs nothing to look at your own business the way an attacker would, and neurabase runs a free passive check of your website and domain that does exactly that, with no access to your systems required.