Beautiful Virgin Islands

Saturday, Feb 22, 2025

Cybercrime lurks as biggest work-from-home experiment puts state, corporate secrets in peril

Staff working at home or connected to public Wi-fi networks are more likely to be hacked, security analysts. Hong Kong weathered first month of working-from-home regime without any noticeable rise in cybercrime, according to privacy commissioner

Go to a coffee shop in Hong Kong and you will see office workers wearing masks to protect themselves from catching the new coronavirus, connecting to public Wi-fi and shuffling through papers downloaded from their office servers.

While that may be a common sight after the biggest shift in work culture ever, the risk from another form of attack has remained constant over time: cybercrime.

From stock traders to civil servants, more employees are handling confidential information off-site globally under less robust security safeguards as the viral outbreak brought on the biggest work-from-home experiment in decades. That poses a risk to governments and businesses who were not fully prepared for the shift on such a scale, security analysts say.

“I’ve seen a lot of individuals over the last few weeks working in coffee shops, using public Wi-fi,” Stuart Witchell, a managing director at risk consultancy firm Berkeley Research Group, said in an interview. “Data is obviously more vulnerable outside the corporate environment.”

More than 60 per cent of companies in major Chinese cities have not reopened offices since the Lunar New Year holiday, allowing employees in the world’s second-largest economy to work remotely from home, according to statistics from Baidu, which operates China’s biggest search engine.

The government of Hong Kong has been encouraging some of its 176,000 civil servants and private companies to work remotely to help contain the virus, while guarding against hackers.

“Fraud attempts are certainly up, especially with many more finance persons working from home with less than ideal technology or no secure connectivity,” Steve Vickers, chief executive of Steve Vickers & Associates, a specialist political and corporate risk consultancy based in Hong Kong.

While work-from-home is nothing new in the US, it is less common across Asia. This made the abrupt and urgent need to organise staff working from home en masse that much more difficult, said Sean Chen, director of strategy in Hong Kong at Blackpeak, an investigative research firm.

“Face-time is more important in Asia’s work culture,” said Chen, who grew up in Taiwan and has worked in Washington, Beijing and Shanghai. Accessing data from home leaves them vulnerable, especially as IT help desk professionals are responding less quickly to off-site threats, he added.

Even if Hongkongers have experienced working from home during the anti-government protests last year or even as far back as 2003 during the Sars (severe acute respiratory syndrome) outbreak, the current exercise across Asia is unprecedented in its magnitude.

As a result, the IT systems may struggle to cope with the extra load, some experts say. Moving large amounts of confidential data into drop boxes to overcome system bottlenecks can be detrimental, said Vickers.

“Many systems, whilst apparently technically sound, were never designed for the very significant numbers of additional users and the protracted periods involved,” he said. “This is dangerous and may lead to significant data loss or fraud” despite the good intentions, he added.

Staff without access externally to data on their company’s cloud may download data from a server onto potentially vulnerable personal devices, or print out hard copies of documents and carry them off-site, said Witchell of Berkeley Research.

To be sure, the Hong Kong government has not received any reports on data leakage from government departments during the past one month, according to a spokeswoman for its Chief Information Officer. Workers use secure communications channels and are trained in cybersecurity, she added.

The Hong Kong Monetary Authority said it has not observed increased threats of cyberattacks targeting banks, nor received any reports about customer data leakage resulting from banks’ work-from-home arrangements, a spokeswoman said.

Another high-risk group is stock brokers. Many investment banks are splitting trading teams into two, with one group working from the office and another from home, according to traders contacted by the Post.

“In today’s advanced tech environment, it should not be a problem for traders to work from home,” said Brock Silvers, managing director at Adamas Asset Management. “It may not be optimal for longer-term business purposes, but it should work from a compliance standpoint.”

Hong Kong’s Office of the Privacy Commissioner for Personal Data (PCPD) has received 10 notifications on data breach between January 29 and February 26, it said. One of them is related to cybercrime. It also received two complaints relating to cybercrime or loss of data.

These figures, however, do not represent a significant leap in data loss, it said.

“Hackers are watching every pitfall in mobile devices or Wi-fi connection to steal personal data or sensitive data,” said Stephen Wong Kai-yi, who oversees the PCPD office. The first line of defence may just be a routine change of Wi-fi password and proper antivirus and malware software, he added.

Many international firms with offices in Asia have robust data encryption in place. The weaker links in the chain, however, are likely among the smaller, local businesses, said risk analysts. Using social media apps such as WhatsApp or WeChat could produce untold damage, analysts warn.

“You do not know who is pinging what,” said Chen of Blackpeak. “Companies wouldn’t want employees to send each other documents via social media – that is not part of normal procedures.”

With workers gradually drifting back to the office as the number of new coronavirus cases ebbs in mainland China, lessons can be learned from the experiment as long term, the working from home trend gains traction as part of business continuity plans.

Best practice would be for companies to store data on the cloud and allow staff to access it externally, according to data security consultants. They should have protocols in place for working remotely and train staff regularly on them, as well as staying out of public Wi-fi networks. Still, it is hard to protect against human error, said Witchell of Berkeley Research.

“Once people start bringing laptops home, inevitably they leave them on the bus or train,” he said.

Newsletter

Related Articles

Beautiful Virgin Islands
0:00
0:00
Close
Good News: Senate Confirms Kash Patel as FBI Director
Officials from the U.S. and Hungary Engage in Talks on Economic Collaboration and Sanctions Strategy
James Bond Franchise Transitions to Amazon MGM Studios
Technology Giants Ramp Up Lobbying Initiatives Against Strict EU Regulations
Alibaba Exceeds Quarterly Projections Fueled by Growth in Cloud and AI
Tequila Sector Faces Surplus Crisis as Agave Prices Dive Sharply
Residents of Flintshire Mobile Home Park Grapple with Maintenance Issues and Uncertain Future
Ronan Keating Criticizes Irish Justice System Following Fatal Crash Involving His Brother
Gordon Ramsay's Lucky Cat Restaurant Faces Unprecedented Theft
Israeli Family Mourns Loss of Peace Advocate Oded Lifschitz as Body Returned from Gaza
Former UK Defense Chief Calls for Enhanced European Support for Ukraine
Pope Francis Admitted to Hospital in Rome Amid Rising Succession Speculation
Senate Republican Leader Mitch McConnell, at the age of 83, Declares His Retirement.
Whistleblower Reveals Whitehall’s Focus on Kabul Animal Airlift Amid Crisis
Politicians Who Deliberately Lie Could Face Removal from Office in Wales
Scottish Labour Faces Challenges Ahead of 2026 Holyrood Elections
Leftwing Activists Less Likely to Work with Political Rivals, Study Finds
Boris Johnson to Host 'An Evening with Boris Johnson' at Edinburgh's Usher Hall
Planned Change in British Citizenship Rules Faces First Legal Challenge
Northumberland Postal Worker Sentenced for Sexual Assaults During Deliveries
British Journalist Missing in Brazil for 11 Days
Tesco Fixes Website Glitch That Disrupted Online Grocery Orders
Amnesty International Critiques UK's Predictive Policing Practices
Burglar Jailed After Falling into Home-Made Trap in Blyth
Sellafield Nuclear Site Exits Special Measures for Physical Security Amid Ongoing Cybersecurity Concerns
Avian Influenza Impact on Seals in Norfolk: Four Deaths Confirmed
First Arrest Under Scotland's Abortion Clinic Buffer Zone Law Amidst International Controversy
Meghan Markle Rebrands Lifestyle Venture as 'As Ever' Ahead of Netflix Series Launch
Inter-Island Ferry Services Between Guernsey and Jersey Set to Expand
Significant Proportion of Cancer Patients in England and Wales Not Receiving Recommended Treatments
Final Consultation Launched for Vyrnwy Frankton Power Line Project
Drug Misuse Deaths in Scotland Rise by 12% in 2023
Failed £100 Million Cocaine Smuggling Operation in the Scottish Highlands
Central Cee Equals MOBO Awards Record; Bashy and Ayra Starr Among Top Honorees
EastEnders: Four Decades of Challenging Social Norms
Jonathan Bailey Channels 'Succession' in Bold Richard II Performance
Northern Ireland's First Astronaut Engages in Rigorous Spacewalk Training
Former Postman Sentenced for Series of Sexual Offences in Northumberland
Record Surge in Anti-Muslim Hate Crimes Across the UK in 2024
Omagh Bombing Inquiry Concludes Commemorative Hearings with Survivor Testimonies
UK Government Introduces 'Ronan's Law' to Combat Online Knife Sales to Minors
Metal Detectorists Unearth 15th-Century Coin Hoard in Scottish Borders
Woman Charged in 1978 Death of Five-Year-Old Girl in South London
Expanding Sinkhole in Godstone, Surrey, Forces Evacuations and Road Closures
Bangor University Announces Plans to Cut 200 Jobs Amid £15 Million Savings Target
British Journalist Charlotte Peet Reported Missing in Brazil
UK Inflation Rises to 3% in January Amid Higher Food Prices and School Fees
Starmer Defends Zelensky Amidst Trump's 'Dictator' Allegation
Zelensky Calls on World Leaders to Back Peace Efforts in Light of Strains with Trump
UK Prime minister, Mr. Keir Starmer, has stated that any peace agreement aimed at ending the conflict in Ukraine "MUST" include a US security guarantee to deter Russian aggression
×