Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific and Middle East: 1,929 cases from 40 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Securities and Futures Commission (SFC) €235,595 100 % · 1 case
What for?
by topicWho?
by companyWhen?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 0 | – |
| Q1 2025 | 0 | – |
| Q2 2025 | 0 | – |
| Q3 2025 | 0 | – |
| Q4 2025 | 0 | – |
| Q1 2026 | 0 | – |
| Q2 2026 | 0 | – |
| Q3 2026 | 1 | €235,595 |
| Q4 2026 | 0 | – |
1 case
28 Jul 2026 Luk Fook Securities (HK) LimitedLuk Fook Securities: HKD 2.1m fine for weak cybersecurity ahead of ransomware attack €235,595
Luk Fook Securities (HK) was publicly reprimanded and fined 2,100,000 HKD because inadequate cybersecurity controls might have contributed to a ransomware attack on 19 September 2022 hitting numerous core servers and to full recovery taking until 7 October 2022; during that time clients could not trade via the app or internet platform. Findings included missing firewall protection, outdated operating systems and antivirus software, weak access and password controls with credentials stored unencrypted, insufficient controls over remote access and external devices, inadequate data backup and a last security training session in 2018.
Basic cyber hygiene – patching, access and password controls, backups and regular staff training – is a regulatory obligation for financial firms.
Ransomware defence, password security and security awareness training
Missing or inadequate training played a role in the decision.
- Authority / court
- Securities and Futures Commission (SFC)
- Area of law
- Information security and cyber · Security measures and risk management
- Legal basis
- s. 194 SFO (Cap. 571); Code of Conduct GP 2, GP 3, GP 7, paras. 12.1, 18.5 und Schedule 7; Guidelines for Reducing and Mitigating Hacking Risks Associated with Internet Trading
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Repeat case
- no
- Mitigating circumstances
- Root-cause review with an independent reviewer, strengthened controls, no evidence of client loss, cooperation, clean disciplinary record.
- Published
- 28 Jul 2026
Original amount 2,100,000 HKD, converted at the ECB reference rate of 28 Jul 2026.
- SFC press release 26PR118: SFC reprimands and fines Luk Fook Securities (HK) Limited $2.1 million for inadequate cybersecurity control (28.07.2026) Press release of an authority
- SFC Statement of Disciplinary Action zu 26PR118 Decision of an authority
Checked against the official source on 3 Oct 2026 · Direct link