Hong Kong — Cyber Threat Profile

Hong Kong pairs its role as a global financial centre with a fast-formalizing cyber regime. HKCERT, under the Hong Kong Productivity Council, handled a record 15,877 incidents in 2025 (up 27%; phishing 57%), and the Protection of Critical Infrastructures (Computer Systems) Ordinance (Cap. 653) took effect on 1 January 2026, imposing statutory obligations on designated critical-infrastructure operators. Threat activity is heavy: Trigona's August 2023 ransomware attack on Cyberport leaked personal data of 13,632 people; a September 2023 attack crippled almost 80% of the Consumer Council's systems; an Arup finance employee in Hong Kong was duped by a deepfake video call into HK$200 million of transfers in early 2024; and Symantec ties long-dwell Spyder Loader espionage against Hong Kong organizations to Operation CuckooBees, with attackers active on some victim networks for over a year.

Read the full analysis on IntelFusions