Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific and Middle East: 1,907 cases from 40 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

1case from 1 jurisdiction
€235,595Total of monetary amounts
€235,595Largest single case: Luk Fook Securities (HK) Limited
€235,595Median per case with an amount

Click a bar to drill down one level.

Where?

by authority
  1. Securities and Futures Commission (SFC) €235,595 100 % · 1 case

What for?

by topic
  1. Security measures and risk management €235,595 100 % · 1 case

Who?

by sector

All sectors

  1. Financial services and insurance €235,595 100 % · 1 case

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q4 20230–
Q1 20240–
Q2 20240–
Q3 20240–
Q4 20240–
Q1 20250–
Q2 20250–
Q3 20250–
Q4 20250–
Q1 20260–
Q2 20260–
Q3 20261€235,595
Q4 20260–

1 case

28 Jul 2026 Luk Fook Securities (HK) LimitedLuk Fook Securities: HKD 2.1m fine for weak cybersecurity ahead of ransomware attack Hong KongSecurity measures and risk management €235,595

Luk Fook Securities (HK) was publicly reprimanded and fined 2,100,000 HKD because inadequate cybersecurity controls might have contributed to a ransomware attack on 19 September 2022 hitting numerous core servers and to full recovery taking until 7 October 2022; during that time clients could not trade via the app or internet platform. Findings included missing firewall protection, outdated operating systems and antivirus software, weak access and password controls with credentials stored unencrypted, insufficient controls over remote access and external devices, inadequate data backup and a last security training session in 2018.

What organisations can take from it

Basic cyber hygiene – patching, access and password controls, backups and regular staff training – is a regulatory obligation for financial firms.

Relevance to training and awareness

Ransomware defence, password security and security awareness training

Missing or inadequate training played a role in the decision.

Authority / court
Securities and Futures Commission (SFC)
Area of law
Information security and cyber · Security measures and risk management
Legal basis
s. 194 SFO (Cap. 571); Code of Conduct GP 2, GP 3, GP 7, paras. 12.1, 18.5 und Schedule 7; Guidelines for Reducing and Mitigating Hacking Risks Associated with Internet Trading
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Repeat case
no
Mitigating circumstances
Root-cause review with an independent reviewer, strengthened controls, no evidence of client loss, cooperation, clean disciplinary record.
Published
28 Jul 2026

Original amount 2,100,000 HKD, converted at the ECB reference rate of 28 Jul 2026.

Checked against the official source on 3 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

Ready for training that actually lands?

Try the combination for free: automated administration for you, learning formats that fit your team, with no minimum or credit card.

Start 14-day free trial