Menu
Browse

Cyber Incident Victim: Hongkong Post

Date:

Jul 2025

Location:

Hong Kong

Summary

Hongkong Post reported a cyberattack involving robotic access to the address books of its EC‑Ship account holders. Upon detection, it blocked the unauthorized access and notified the police, the Digital Policy Office, the Office of the Privacy Commissioner for Personal Data and the Security Bureau. The EC‑Ship service has been restored to normal operation. A preliminary assessment indicates that the compromised data may include senders’ and recipients’ names, addresses, phone numbers, fax numbers and email addresses. Investigations continue to determine how many accounts were affected and whether any personal data was leaked. The service said it is seeking advice from the Digital Policy Office and will strengthen its security measures. It also noted that it does not send embedded hyperlinks in emails, SMS or social media for collecting personal information or requesting payment.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 0 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

On July 21, 2025 Hongkong Post disclosed that it had detected an information security incident involving robotic access to the address books of users of its EC‑Ship service. Upon identification of the unauthorized access, the organization immediately blocked the activity and initiated its incident response procedures. Hongkong Post reported the case to the Police, the Digital Policy Office, the Office of the Privacy Commissioner for Personal Data and the Security Bureau on the same day. The EC‑Ship service was restored to normal operation after the containment measures were applied. The post office emphasized that it was cooperating closely with law‑enforcement investigators.

Cyber Incident Image

Based on a preliminary assessment, Hongkong Post stated that the compromised data could include senders’ and recipients’ names, addresses, phone numbers, fax numbers and email addresses stored in the EC‑Ship address books. Investigations are continuing to determine the exact number of affected account holders and whether any personal data has been leaked. Hongkong Post said it will notify affected users as soon as further information becomes available. The organization is seeking guidance from the Digital Policy Office to support its investigation and plans to strengthen overall system security. Hongkong Post also reminded the public that it does not send embedded hyperlinks in emails, SMS or social‑media messages for collecting personal information or requesting payments, and advised citizens to avoid clicking such links or providing personal or financial details in response to suspicious messages purporting to be from Hongkong Post. For any enquiries, the public can contact Hongkong Post at 2921 2222.

Sources
Sources available to members
1 source