Context
Hong Kong SMEs are seeing two high-impact patterns in the same quarter: ransomware that succeeds because backups were never restored under time pressure, and deepfake-enabled payment fraud that bypasses email filters by using voice, video, or AI-rewritten invoices.
Neither pattern is new. What changed is speed — attackers use GenAI to personalise lures, while lean IT teams still share admin accounts and keep backups on the same network as production.
This is an HKISG security news briefing for operators and boards. It is not an HKCERT advisory. For active compromise, escalate through your incident path and HKCERT. Role clarity: HKCERT and HKISG.
Hong Kong implications
- Finance and EA staff often approve payments on WhatsApp-style channels where classical DLP is weak.
- MSP/MSSP access without MFA multiplies ransomware blast radius across clients.
- Personal data in stolen mailboxes can trigger PDPO considerations after exfiltration.
- Boards that only hear “AI risk” without inventory decisions leave residual risk unowned — see CISO AI Security Briefing.
Practical guidance
Verify these five controls this month:
- Timed restore of one critical system (date the result).
- Dual control for payments above a published threshold — no voice/video-only wires.
- Out-of-band check for any supplier bank-detail change.
- MFA on email, VPN, cloud admin, and MSP privileged paths.
- One-page impersonation rule for CEO/CFO requests.
Deep dives: Ransomware for Hong Kong SMEs, Deepfake Fraud in Hong Kong, Prompt Injection.
Operator checklist
- Confirm whether your estate matches the patterns above.
- Assign owners and a 30-day review date for the five controls.
- Capture evidence if you later enter a Trust Review.
- Brief leadership with a dated one-pager (Board Briefing Pack).
Related
Editorial note
Published by HKISG for educational and early-warning purposes. Not legal advice and not a substitute for bank fraud procedures or national CERT coordination. See Policies.