Hong Kong bucks APAC trend as targeted cyberattacks outpace ransomware
APT activity made up 37.6% of cyber incidents in the city.
Hong Kong experienced more advanced persistent threat (APT) attacks than ransomware incidents, unlike other Asia-Pacific markets, according to a ThreatBook report.
APT activity, or prolonged and targeted attacks, accounted for 37.6% of cybersecurity incidents recorded in the city, compared with 16.2% for ransomware.
Such incidents focused on long-term espionage and intellectual property theft, with stolen data used for cross-border fraud, targeted phishing, theft of funds, and attacks on high-value individuals.
Attackers also sought access to critical infrastructure networks that could be used in future operations, the report said.
ThreatBook identified 329 incidents in the city between June 2025 and June 2026, ranking it 14th amongst the markets covered.
The main methods included social engineering targeting virtual-asset and technology workers, theft of information from multinational companies, and remote access followed by data wiping from mobile devices.
Meanwhile, ransomware incidents were more focused on data extortion than encryption-based shutdowns.
“An attack proven against a bank in Singapore lands just as well on a Hong Kong bank running the same stack,” said Chase Li, ThreatBook’s co-founder and managing director for international business.
He added that breaches could spread through multinational companies, suppliers, and shared technology platforms across different markets.