Advertisement
Advertisement
Hong Kong society
Get more with myNEWS
A personalised news feed of stories that matter to you
Learn more
Hong Kong’s Companies Registry is consulting the Office of the Privacy Commissioner for Personal Data regarding the incident. Photo: Jelly Tse

Personal data of 110,000 people leaked after breach at Hong Kong’s Companies Registry, investigation finds

  • Case is third public body security breach announced in a week, after revelation of leaks at Electrical and Mechanical Services Department as well as the Consumer Council
  • Lawmaker Elizabeth Quat says back-to-back occurrences highlight serious cybersecurity issues within government departments
Ezra Cheung

An investigation into Hong Kong’s Companies Registry has revealed the online portal leaked personal data of 110,000 people, including names, passport and identity card numbers and residential addresses.

It was the third reported public body security breach in a week, and accountancy sector lawmaker Edmund Wong Chun-sek called it “truly a serious mistake”.

The registry said telephone numbers and email addresses were also disclosed, and it had started notifying victims with explanations and apologies.

“The Companies Registry is very concerned about the risk of personal data leakage,” a spokesman said.

“It is consulting the Office of the Privacy Commissioner for Personal Data and the Office of the Government Chief Information Officer, with a view to conducting a comprehensive review of the incident.”

Hong Kong privacy watchdog to grill authorities over leak of 17,000 people’s data

The registry spokesman added that its contractor’s system design provided the client with not only search-related information but also additional personal information.

“Although such additional personal data would not be displayed on the search result pages, it could be obtained using a web developer tool on the said pages,” he said, adding that some personal data could also be obtained via a “robotic search”.

The registry announced on April 19 that it would suspend access to its online portal for urgent maintenance, saying risks of personal data leakage had been identified.

At the time, the registry said it had not received any personal data leakage report following a preliminary investigation.

The registry noted that affected residents could contact its helpline at 8201 8273 or email [email protected].
Three security breaches have been reported in the past week. Photo: Shutterstock

The Office of the Privacy Commissioner for Personal Data said that considering the vast scope of people affected, it had immediately commenced an investigation.

As of Friday, the watchdog had not received any inquiries or complaints regarding the incident, a spokesman added.

He also urged those affected to change the passwords of their online accounts and activate multi-factor authentication function if possible, watch out for unusual logins and review bank statements for any unauthorised transactions.

Lawmaker Wong has also called on the registry to comprehensively review all existing systems and eliminate all possible loopholes.

Hacker-hit Hong Kong watchdog ordered to fix security issues within 2 months

The breach at the registry followed an announcement earlier in the day by the privacy watchdog that it would investigate a security failure of the Electrical and Mechanical Services Department.

The personal information of 17,000 residents collected during the Covid-19 pandemic, including names, telephone numbers, ID numbers and addresses, was leaked due to an error in a government department’s password login system.

Data was collected by the department during “restriction-testing declaration” operations between March and July of 2022.

On Thursday, the office revealed that the Consumer Council breached privacy rules when the personal information of more than 470 people was leaked in a cybersecurity attack.

Hong Kong police sound alarm over surge in fraudsters hijacking WhatsApp accounts

The office said hackers managed to obtain access to an administrator account belonging to the council’s IT staff on September 4 last year, and used the account to carry out various malicious activities weeks later while trying to force the watchdog to pay a ransom of US$500,000.

Lawmaker Elizabeth Quat, the chairwoman of the Legislative Council’s information technology and broadcasting panel, said the back-to-back occurrences revealed serious issues with cybersecurity within government departments.

She also urged authorities to conduct security breach drills to boost awareness and response capabilities among the civil service.

2