TOM GROUP has disclosed a cybersecurity incident affecting its servers in Taiwan and Hong Kong, with an ongoing investigation into the potential impact.
According to a company announcement, the group detected a network attack on or around September 8, 2026, targeting servers in Taiwan that support the "Business Weekly" division of its major subsidiary, Cite Publishing Ltd. The attack resulted in the encryption of certain data stored on those servers.
The following day, the security breach extended to Hong Kong, impacting the group's servers there and leading to the encryption of additional data. In response, the company immediately isolated and disconnected all affected systems in both Taiwan and Hong Kong from the internet to contain the spread of the attack.
The group has engaged cybersecurity specialists and consulting firms to assist in investigating the cause and scope of the incident, assessing data integrity, and reviewing the security of its information systems. As of the announcement date, the investigation remains active, and it is not yet possible to confirm whether any data has been leaked or lost, or to determine the extent of any such loss if it occurred.
The company plans to take appropriate further actions once the investigation concludes. It is working closely with its cybersecurity experts and advisers to advance the inquiry and is conducting a comprehensive assessment of the incident's impact on its business operations.
The group emphasizes its strong commitment to data security and states it will continue to strengthen its information system safeguards to prevent similar incidents in the future. Further updates will be provided as appropriate.
Additionally, the company has notified the relevant authorities in Taiwan and Hong Kong about the data security incident. It will continue to evaluate its legal and regulatory obligations, make further notifications to other authorities as needed, and cooperate promptly with official investigations.