
Authorities respond to breach involving internal IT system as investigation and security review are launched
Hong Kong’s Correctional Services Department has confirmed that its internal information technology system was targeted in a cyberattack, resulting in the exposure of personal data belonging to approximately 6,800 staff members.
Officials said the incident involved unauthorised access to parts of the department’s system, leading to the compromise of certain employee information.
The affected data is understood to include details related to staff records, prompting immediate action to contain the breach and assess its scope.
Authorities have launched an investigation into the incident, working to determine how the system was accessed and whether any vulnerabilities were exploited.
Measures have been put in place to strengthen cybersecurity protections and prevent further unauthorised activity.
The government emphasised that the breach was taken seriously and that affected individuals would be notified, with support provided where necessary.
Efforts are also underway to review and enhance system safeguards, including updates to security protocols and monitoring procedures.
While the incident has raised concerns about data protection, officials highlighted the importance of maintaining robust digital infrastructure in the face of increasingly sophisticated cyber threats.
The response reflects a broader focus on reinforcing resilience across public sector systems.
The case underscores the growing challenges faced by institutions in safeguarding sensitive information and the need for continuous investment in cybersecurity capabilities.
Officials said the incident involved unauthorised access to parts of the department’s system, leading to the compromise of certain employee information.
The affected data is understood to include details related to staff records, prompting immediate action to contain the breach and assess its scope.
Authorities have launched an investigation into the incident, working to determine how the system was accessed and whether any vulnerabilities were exploited.
Measures have been put in place to strengthen cybersecurity protections and prevent further unauthorised activity.
The government emphasised that the breach was taken seriously and that affected individuals would be notified, with support provided where necessary.
Efforts are also underway to review and enhance system safeguards, including updates to security protocols and monitoring procedures.
While the incident has raised concerns about data protection, officials highlighted the importance of maintaining robust digital infrastructure in the face of increasingly sophisticated cyber threats.
The response reflects a broader focus on reinforcing resilience across public sector systems.
The case underscores the growing challenges faced by institutions in safeguarding sensitive information and the need for continuous investment in cybersecurity capabilities.














































