Hong Kong prison department's IT system hacked, 6,800 employees' data compromised

Hong Kong's Correctional Services Department revealed that a hacker illegally accessed its IT system on Tuesday, compromising personal data of 6,800 current and former employees. The department stated there is no evidence of data leakage so far and has notified affected individuals.

Hong Kong's Correctional Services Department announced on Friday evening that a hacker had gained illegal access to one of its IT systems on Tuesday.

"After a preliminary investigation, the Correctional Services Department believes the incident involved unauthorised access to the internal Knowledge Management System by a hacker, through which the hacker then gained entry to another IT system maintaining personal data of [the department] staff," it said.

The breach affected 6,800 current and former employees, compromising their names, gender, date of birth, academic qualifications, employment history in the department, and email addresses, the department added.

It stressed that there was no evidence so far suggesting the data had been leaked or disclosed. The department informed all potentially affected individuals of the situation and reminded them to report any suspicious circumstances to police as soon as possible.

It also reported the case to police, the Security Bureau, the city's privacy watchdog, and the Digital Policy Office.

Articles connexes

Police raid Coupang headquarters in Seoul over massive data breach suspecting former employee.
Image générée par IA

Police investigate Coupang data breach suspecting former employee

Rapporté par l'IA Image générée par IA

Police conducted a second day of raids at e-commerce giant Coupang's headquarters over a massive data breach affecting 33.7 million customers. The suspect is a former Chinese developer who worked on the company's authentication system. Prime Minister Kim Min-seok described the incident as 'beyond serious' and vowed strict action.

The operator of Hong Kong's Ngong Ping 360 cable car attraction detected irregularities in its internal network on Thursday and alerted police and the Office of the Privacy Commissioner for Personal Data. An investigation confirmed that certain data had been stolen, with the company facing a ransom demand. The firm has apologised to guests, employees, and stakeholders for the incident.

Rapporté par l'IA

A massive data breach at South Korea's leading e-commerce firm Coupang has exposed personal information of 33.7 million customers. Police are tracking a Chinese former employee suspect using an IP address, while the government considers fines up to 1 trillion won. The breach, starting in June, went undetected for five months.

Hong Kong's privacy watchdog plans to consult lawmakers this year on introducing mandatory data breach reporting and related penalties, after the legislative reform was put on hold in 2024 due to concerns over the local business environment. Privacy Commissioner for Personal Data Ada Chung Lai-ling revealed details of the proposed amendments to the city's privacy ordinance on Saturday, suggesting the measures could be implemented in phases.

Rapporté par l'IA

Korean Air, une importante compagnie aérienne sud-coréenne, a été touchée par une attaque de la chaîne d'approvisionnement provenant d'Oracle, entraînant l'exposition des informations de milliers de ses employés. L'incident met en lumière les vulnérabilités des services logiciels tiers. Les détails ont émergé dans un rapport de sécurité récent.

Canada Computers & Electronics a divulgué une violation de données qui a exposé des informations clients. Certains clients affectés ont également vu leurs détails de carte de crédit compromis. L’entreprise a annoncé l’incident le 2 février 2026.

Rapporté par l'IA

Le Bureau du commissaire à la protection des données (ODPC) a mis en garde les entreprises de sécurité privées au Kenya contre la collecte illégale de données personnelles excessives auprès des visiteurs. Dans une note d'orientation provisoire, l'ODPC indique que seuls les noms, numéros d'identification et heures d'entrée doivent être collectés pour l'accès aux bâtiments. Cet avertissement intervient alors que les cybermenaces et les violations massives de données augmentent dans le pays.

 

 

 

Ce site utilise des cookies

Nous utilisons des cookies pour l'analyse afin d'améliorer notre site. Lisez notre politique de confidentialité pour plus d'informations.
Refuser