For many Hong Kong companies,Phishing is by no means an unfamiliar topic. While most organizations have already implemented email filtering,,Endpoint Protection, Multi-Factor Authentication (MFA)up toTechnical safeguards such as network monitoring, and we arrange regular annual information security training for our employees. However, as hacker threats have evolved, attack methods no longer rely solely on technical vulnerabilities but frequently involve impersonating corporate executives, customers, financial institutions, logistics companies, suppliers, and even Microsoft 365 system notifications in business contexts. In this context, the traditional compliance training model—which focuses on “checking off attendance and completing courses”—is no longer sufficient to comprehensively defend against highly covert, real-world cyber risks.
QuoteAccording to official data released by the Hong Kong Computer Emergency Response Team (HKCERT), Hong Kong recorded a cumulative total of 15,877 cybersecurity incidents in 2025.According to the report, the figure surged significantly by 27% year-over-year, breaking the all-time high. Among them,Phishing AttacksAt 57%, it continues to rank as the top security threat to businesses. HKCERT issues a special warning that the widespread adoption of generative AI technology has greatly increased the realism of phishing emails and deceptive messages, making them significantly harder to detect. At the same time, the scope of phishing attacks has expanded significantly beyond traditional email to include instant messaging apps (such as WhatsApp, accounting for 34%) and cryptocurrency platforms (accounting for 18%).
On the other hand, the Office of the Privacy Commissioner for Personal Data (PCPD) in Hong KongThe 2025 Work Report noted that a total of 246 cases were received throughout the yearReports of data breaches increased by 21% compared to 2024. Among all reported cases, 81 data breaches were caused by hacker intrusions, accounting for 33% of the total incidents; The remaining primary causes of data breaches included the loss of documents or portable devices, accidental disclosure of personal data via email or fax, employee violations of operating procedures, and system configuration errors. In addition, the Office received 1,163 inquiries related to suspected phishing of personal data during that year.
The statistics cited above clearly demonstrate that the security challenges companies face today have long since moved beyond the simple question of “whether employees will click on suspicious emails”; rather, they now extend to “how employee behavior comprehensively impacts corporate account security, personal data protection, payment processes, business continuity, and incident reporting mechanisms.”