The Incident

In February 2024, C2 Computer fell victim to a sophisticated financial fraud scheme involving fraudulent payment instructions. The attackers impersonated a trusted vendor relationship and manipulated payment routing details, resulting in an unauthorized transfer of HKD 800,000.

The fraud was identified through internal review shortly after the transaction. C2 Computer took immediate action to contain the situation, investigate the full scope, and prevent recurrence.

Incident Summary
Date: February 2024
Incident Type: Sophisticated financial fraud (vendor impersonation / payment redirection)
Financial Impact: HKD 800,000 capital loss
Service Impact: None — no disruption to client services or infrastructure operations
Data Impact: No client data was accessed or compromised
Police Report: Filed with Hong Kong Police (Case #ERC2403281021451)

Key Details:

Our Response

Immediate Actions Taken:

• Notified Hong Kong Police and filed an official report

• Engaged cybersecurity and forensic accounting experts to investigate

• Froze affected accounts and conducted a full audit of recent transactions

• Notified our bank and initiated recovery procedures

Ongoing Investigation:

• Active cooperation with law enforcement

• Insurance claims filed to recover partial losses

• Legal counsel engaged for potential civil recovery

What We’ve Changed

This incident exposed vulnerabilities in our financial controls that we have since addressed. No system is perfect, but we’ve significantly strengthened our defenses:

A Message from Management

“This was a difficult experience, but we chose to be transparent about it rather than hide it. Fraud is becoming increasingly sophisticated in Hong Kong and globally — no business is immune. By sharing what happened to us and the steps we’ve taken, we hope to help other companies strengthen their own defenses.

Business Continuity

We want to assure our clients, partners, and vendors:

No disruption to any client services, orders, or infrastructure operations occurred

No client or partner data was accessed or compromised in any way

All financial obligations to vendors and staff were met on schedule

2024 growth strategy remains unchanged — this incident has not slowed our business trajectory

Insurance claims are in progress to recover a portion of the losses

Additions for Stakeholder Communications:

  1. Client Version: Emphasize zero service disruption and strengthened client data protections.

  2. Investor Briefing: Detail financial contingency plans and long-term risk mitigation.

  3. Media Statement: Focus on corrective actions and industry collaboration against fraud.

If your business receives a request to change payment or banking details from a vendor:

1. Do not act on the email alone — even if it looks legitimate

2. Call your known contact directly using a phone number you already have on file (not from the email)

3. Verify in writing — request official company letterhead confirmation

4. Implement a delay — a 24-hour hold on banking changes costs nothing but can save millions

5. Report suspicious activity to the Hong Kong Police Anti-Deception Coordination Centre at 18222