The Incident
In February 2024, C2 Computer fell victim to a sophisticated financial fraud scheme involving fraudulent payment instructions. The attackers impersonated a trusted vendor relationship and manipulated payment routing details, resulting in an unauthorized transfer of HKD 800,000.
The fraud was identified through internal review shortly after the transaction. C2 Computer took immediate action to contain the situation, investigate the full scope, and prevent recurrence.
• Date: February 2024
• Incident Type: Sophisticated financial fraud (vendor impersonation / payment redirection)
• Financial Impact: HKD 800,000 capital loss
• Service Impact: None — no disruption to client services or infrastructure operations
• Data Impact: No client data was accessed or compromised
• Police Report: Filed with Hong Kong Police (Case #ERC2403281021451)
Key Details:
Our Response
Immediate Actions Taken:
• Notified Hong Kong Police and filed an official report
• Engaged cybersecurity and forensic accounting experts to investigate
• Froze affected accounts and conducted a full audit of recent transactions
• Notified our bank and initiated recovery procedures
Ongoing Investigation:
• Active cooperation with law enforcement
• Insurance claims filed to recover partial losses
• Legal counsel engaged for potential civil recovery
What We’ve Changed
This incident exposed vulnerabilities in our financial controls that we have since addressed. No system is perfect, but we’ve significantly strengthened our defenses:
…A Message from Management
“This was a difficult experience, but we chose to be transparent about it rather than hide it. Fraud is becoming increasingly sophisticated in Hong Kong and globally — no business is immune. By sharing what happened to us and the steps we’ve taken, we hope to help other companies strengthen their own defenses.
Business Continuity
We want to assure our clients, partners, and vendors:
• No disruption to any client services, orders, or infrastructure operations occurred
• No client or partner data was accessed or compromised in any way
• All financial obligations to vendors and staff were met on schedule
• 2024 growth strategy remains unchanged — this incident has not slowed our business trajectory
• Insurance claims are in progress to recover a portion of the losses
Additions for Stakeholder Communications:
Client Version: Emphasize zero service disruption and strengthened client data protections.
Investor Briefing: Detail financial contingency plans and long-term risk mitigation.
Media Statement: Focus on corrective actions and industry collaboration against fraud.
If your business receives a request to change payment or banking details from a vendor:
1. Do not act on the email alone — even if it looks legitimate
2. Call your known contact directly using a phone number you already have on file (not from the email)
3. Verify in writing — request official company letterhead confirmation
4. Implement a delay — a 24-hour hold on banking changes costs nothing but can save millions
5. Report suspicious activity to the Hong Kong Police Anti-Deception Coordination Centre at 18222
