· Cybersecurity

A Hong Kong Law Firm Hit by Ransomware: What We Saw and What Helps

By 3 min read Updated

Originally published May 1, 2025 by Tony Phung. Updated October 2026.

I met a paralegal at a trade show in Hong Kong who works for a local law firm. When I told her about our ransomware protection services, the firm wasn’t ready to talk about it, which is completely fair. We kept in touch over the months that followed. Then she reached out with a screenshot of a ransom note, and we jumped in to help.

What we found

The note said the network was encrypted and offered a decryptor in exchange for payment. It looked like one of the known ransomware families, possibly LockBit 3.0, DoNex or Black Busta, though we’re still confirming that.

The firm has a Fortinet 100F firewall, but nobody had the login for it, which made it hard to see what had happened. They haven’t chosen a full assessment yet, and we hope they will soon. We gathered what we could and did a quick check for possible decryptors.

Here is what the setup looked like:

  • A tower server sitting in a nice server rack, which is a bit of a mismatch.
  • No virtualization. We think of Hyper-V as a must-have for production servers, because it makes backups and recovery much easier.
  • Storage on a mirrored pair of drives (RAID 1), with an 8TB drive.
  • No domain controller and no separate application server.
  • A NAS that may have been affected too. We haven’t been able to confirm that yet.

About 65 staff were cut off from client files and couldn’t work. In the first rush, the firm shut down its whole setup, which took the VoIP phones offline as well.

What usually helps

  • Run servers on Hyper-V, with a domain controller and a dedicated application server.
  • For storage, we recommend RAID 10, or RAID 6 when budget or capacity matters more. Either way, RAID is not a backup.
  • Keep tested 3-2-1 backups, with a copy offsite and immutable copies that can’t be changed or deleted for a set period.
  • Keep the firewall login and documentation somewhere safe and current.
  • Have an incident response plan and round-the-clock monitoring, which can help limit the damage when something does happen.

Where things stand

We felt we had a solid lead on decrypting the files. The principal lawyer was understandably shaken and wasn’t sure about going down that route, and we respect that. The firm has also heard other advice, including wiping all the computers and starting over. That is one option, but we’d usually suggest finding out where the attack came from first, so the same gap doesn’t stay open. We’ll keep following up with them.

If you’re dealing with ransomware, don’t give up. There may be help. At the very least, get good advice and pay for an assessment so you know where it came from.

We offer full-cycle managed IT and cybersecurity services for businesses in Hong Kong and beyond. Call (604) 813-7881 for a free consult with Tony. No pressure, no jargon.

Leave a comment

Tony Phung, Founder and CEO of Benson Hunt

I write up what we find in real offices. If it sounds like your setup, call me.Tony Phung, Founder and CEO

Built on ITIL best practices. 40+ years of combined experience. Proudly Canadian.

Talk to a person.

(604) 813-7881

Mon to Fri, 7am to 5pm MT. Emergency support 24/7 at (604) 813-7881, always answered by a person.
Or contact us