⚠️ Active Data Breach? Isolate device immediately. Don't turn off power. Call HKCERT: 8105 6060.

Data Leak Response

Guidelines for Individuals & SMEs (Updated 2026)

For Individuals: Protect Your Identity

If you lost your phone, laptop, or suspect hacking, follow these steps immediately (first 24 hours).

1
Detection & Analysis

Spot signs: 2FA codes you didn't request, slow performance, ransom notes.
Tools: Check HaveIBeenPwned.com and ESET Online Scanner.

2
Containment

Isolate device: Disconnect Wi-Fi/LAN/Bluetooth. Do not power off (forensics).
Change passwords from a different, clean device.

3
Protection (Financial & Biometric)

Freeze credit cards. Notify banks. If HKID/FaceID data is lost, report to Immigration Dept immediately (Deepfake risk).
Resource: Use CyberDefender (Scameter+).

4
Voluntary Reporting

Notify PCPD voluntarily if personal data is at risk (Identity Theft). Report to Police if theft involved.

For SMEs: Business & Client Protection

SMEs (5-50 staff) must act fast to protect client trust and minimize PDPO risks.

Phase 1: Immediate Response (0-24 Hrs)

  • 🔴 Isolate: "Air Gap" the network. Pull the network cables. Do NOT reboot servers (RAM contains evidence).
  • 🔍 Assess Double Extortion: In 2026, Ransomware doesn't just lock data; it steals it. Check exfiltration logs.
  • 📞 Triage: Call HKCERT Hotline (8105 6060) for technical help.

Phase 2: Notification & Compliance

💡 Notification Strategy:
  • Clients: Notify immediately if high risk (e.g., credit cards/HKID leaked). Transparency reduces lawsuits.
  • PCPD: "Voluntary" for general SMEs, but highly expected within 72 hours.
  • Police: Report to Cyber Security Bureau (CSTCB) if criminal hacking is suspected.

Phase 3: Recovery

Restore from clean Offline/Immutable Backups (3-2-1 rule). Patch vulnerabilities. Anonymize data per 2026 PCPD Guidelines.

🎓 Knowledge Check: 2026 Guidelines

Test your understanding of the current threats and laws.

Loading Question...