First published: 21st November 2013
The Treasury of Hong Kong has warned that fraudulent emails were sent from their email account ra@try.gov.hk, and that a document attached to the emails contained "computer viruses". The Treasury claims it has no connection with the emails. The Police are investigating.
Yui Kee Chief Consultant Allan Dyer commented, "It is well-known that email messages are trivial to spoof, sending a message that has any arbitrary address in the From: field is easy, but the Government press release specifically says the messages were sent from their email account. This, and the Police investigation, seem to indicate that Government computers were used to send the messages, so this might be an extremely serious security breach. Hopefully, this is just sloppy writing by a non-technical press officer".