The Hong Kong Police Cyber Security and Technology Crime Bureau and the Hong Kong Monetary Authority jointly published their annual cybersecurity threat assessment on Wednesday, documenting a 45 percent year-on-year increase in serious cyber incidents reported by Hong Kong organisations in 2025 and warning that the proliferation of AI-powered attack tools is fundamentally altering the threat landscape in ways that require urgent upgrading of both technical defences and human awareness.
The Threat Landscape
The most significant driver of the increase in recorded incidents is the democratisation of sophisticated cyberattack capabilities through AI-powered tools. Large language models, adapted for malicious purposes and increasingly available through dark web markets at prices accessible to non-expert attackers, have enabled the generation of highly personalised phishing emails that are grammatically impeccable, contextually convincing and tailored to the specific role and communications patterns of individual targets.
Traditional phishing detection approaches, which relied partly on identifying imperfect language, generic salutations and implausible scenarios, are increasingly ineffective against AI-generated attacks that precisely replicate the writing style of a known correspondent, include accurate personal and professional details drawn from open source intelligence, and construct plausible business pretexts tailored to the target's role and industry. Police data shows that the average financial loss per successful business email compromise incident increased from HK$480,000 in 2024 to HK$1.2 million in 2025, reflecting the higher quality of AI-generated attacks and the targeting of higher-value transactions.

AI-generated phishing attacks drove a 45% increase in serious cyber incidents in Hong Kong, with average business email compromise losses rising to HK$1.2M per incident.
Ransomware and Critical Infrastructure
Ransomware incidents targeting Hong Kong organisations increased 38 percent in 2025. The most significant incident involved a ransomware attack on a mid-sized logistics company whose 38 Hong Kong clients, including several major retailers and e-commerce platforms, experienced service disruptions over a 72-hour period before the company's backup systems were brought online. The attack, attributed by forensic investigators to a criminal group with suspected state sponsorship, caused an estimated HK$280 million in direct and indirect losses.
Critical infrastructure operators, including utilities, transport operators and financial market infrastructure, have been the subject of sustained reconnaissance activities that the assessment attributes to multiple state-sponsored threat actor groups. The Office of the Government Chief Information Officer has expanded the scope of the mandatory cybersecurity framework for operators of designated critical infrastructure to include enhanced incident reporting requirements and compulsory penetration testing at 12-month intervals.
Deepfake and Voice Cloning Fraud
A disturbing and rapidly growing category of cybercrime identified in the assessment is the use of AI-generated deepfake video and voice cloning to impersonate executives in video conference calls with financial staff, authorising fraudulent payment transfers. Two Hong Kong incidents in 2025, both subsequently reported widely in international media, involved deepfake video calls simulating the CEO and CFO of real Hong Kong companies, instructing finance staff to transfer funds totalling HK$340 million to fraudulent accounts. Both incidents would have been prevented by enhanced internal approval protocols that the assessment recommends all organisations implement.

Deepfake video call fraud has emerged as a major threat, with two Hong Kong incidents in 2025 resulting in fraudulent transfers totalling HK$340M.
Defensive Measures and Government Response
The assessment includes a comprehensive set of recommendations for organisations of all sizes. For large organisations and critical infrastructure operators, the priority measures include deploying AI-powered security operations centre tools capable of identifying AI-generated attack patterns, implementing zero-trust network architecture eliminating implicit internal network trust, and establishing robust out-of-band verification protocols for all significant financial authorisations.
For small and medium enterprises, the assessment recommends participation in the HKMA's Cyber Fortify programme, which provides subsidised cybersecurity assessments, staff awareness training and basic technical hardening assistance for eligible businesses. The programme, which attracted 2,400 SME participants in 2025, is being expanded with additional government funding of HK$120 million over the next two years.


