Read More
Morning Recap - September 17, 2026
3 hours ago
Four arrested over Pokémon card scams involving $101,000
15-09-2026 18:26 HKT
All government bureaus and departments have been asked to remove all sensitive and personal information from public cloud servers and report back to the Office of the Government Chief Information Officer within one week amid recent government data leaks.
This came after the Electrical and Mechanical Services Department found that a server - storing the personal information of around 17,000 citizens collected during mandatory Covid-19 lockdown between March and July in 2022 - can be accessed without inputting any passwords.
The information included their names, telephone numbers, ID card numbers and addresses - although they were not downloadable.
The EMSD said it had requested the service provider of the online server platform to remove the data, and had reported the leak to the OGCIO, police and the Security Bureau.
The information breach is also being investigated by the Office of the Privacy Commissioner for Personal Data, with Privacy Commissioner Ada Chung Lai-ling saying last Friday whether the leak occurred back in 2022 or recently is also one of their investigation directions.
She recommended relevant government departments to conduct a comprehensive review to see if the data stored in their servers has been leaked.
A day later, the Companies Registry announced that it leaked data of around 110,000 people last month, including their name, full passport and ID card number, address, contact number and email address.
The registry only indicated on April 19 that urgent maintenance was required upon identifying the risk of personal data leakage in the e-Search Services of its e-Services Portal - a single integrated online platform to facilitate searches on registered information of companies and entities kept by the registry - and that it had not received any report of personal data leakage. But after investigation, the registry said people might obtain additional personal details if they utilize a web developer tool or via a "robotic search," involving the personal information of around 110,000 people - mainly company directors.
In response to the recent data leak incidents, the OGCIO said it attached great importance to information security breaches within government departments and public entities, particularly those involving leakage of personal data.
In addition to offering technical support, the office also reminded all users and systems under the departments that they must "stringently comply with the government's rules, policies and guidelines on data security in handling sensitive and personal information."
Replying to media inquiry, at least 14 government departments said they had already deleted the personal data collected during lockdown.
stacy.shi@singtaonewscorp.com
