Skip to main content

Geographic intelligence

Singapore cybersecurity signals

Follow 1 current cybersecurity signal linked to Singapore through an affected location, a profiled company's country, or both, with source reporting.

Affected-country links use structured victim-country data. Company-country links use a reviewed profile based on the organisation's headquarters or the local operating entity represented by its domain. A signal linked in both ways is counted once in the total; actor origin and locations inferred from prose remain excluded.

🇸🇬

Country context

About Singapore

Reference details that help place the cybersecurity reporting in its geographic and economic context.

Region
East Asia & Pacific
Capital
Singapore
Income group
High income
ISO codes
SG / SGP
ISO numeric
702

1

Total linked signals

Linked through an affected location, company headquarters, or both.

Not classified

Signals affecting this country

Victim-country data is unavailable in this reporting window.

1

Signals from companies based here

Based on reviewed company headquarters.

1

High or critical

Severity classifications among linked signals.

Explore related intelligence

Explore this reporting from another angle

Based on all published signals currently linked to Singapore through an affected location, a profiled company's country, or both. Counts describe this reporting set, not overall incident prevalence.

Company-linked signals

Current reporting linked to Singapore

High

Singapore Land Authority Data Breach Exposes 70,000 Records via IBM Testing Environment

Singapore Land Authority data breach exposes 70,000 records after IBM testing environment compromised SINGAPORE, July 3 — Personal data belonging to about 70,000 individuals has been compromised in a cybersecurity incident involving the Singapore Land Authority (SLA) and a cloud environment managed by IBM. SLA said the breach stemmed from unauthorised access to a dataset created for vendor development and systems integration testing, CNA reported. IBM oversees the testing environment for the Singapore Titles Automated Registration System (STARS) and eLodgment System (ELS), which are used to submit property transfer and caveat documents. Preliminary checks showed the dataset, first created in 1998 and updated periodically, was intended to contain only mock and anonymised records. It was later discovered to include real information such as names, NRIC numbers and past property addresses of around 70,000 people. SLA stressed that the affected environment is separate from its live operational systems, adding that property ownership and lodgment records in STARS and ELS remain secure. IBM has revoked access to the compromised system to prevent further unauthorised entry. As a precaution, SLA has begun notifying affected individuals and advising them on assistance measures. The authority said it is working with IBM, the Government Technology Agency of Singapore and the Cyber Security Agency of Singapore to investigate the incident and implement remedial steps. According to CNA, a police report has been lodged and the Personal Data Protection Commission has been notified. SLA has not yet disclosed when the breach occurred or how many affected individuals have been contacted. Singapore’s first dedicated hospital for native wildlife opens at Mandai Singapore bookie aged 69 jailed for illegal betting on Hong Kong horse races Fatal dispute between Singapore Redhill flat neighbours leads to murder charge PDRM prepares security operations for Negeri Sembilan state election Defence weighs AGC appeal for driver in fatal Klang crash Amirudin: Pakatan banks on micro-campaign strategy to win over Negeri Sembilan voters ÑеÑгей ÑаÑанÑÑа - stock.adobe.com The Singapore Land Authority (SLA) has revealed that the personal information of about 70,000 individuals was exposed following unauthorised access to a cloud environment managed by IBM, its technology supplier. IBM was appointed to support and maintain SLA’s Singapore Titles Automated Registration System (Stars) and eLodgment System (ELS), which underpin property title registration and the lodgement of property documents in the city-state. As part of that work, the supplier managed the development and systems integration testing environment for the two systems. In a statement on 3 July 2026, SLA said it had been informed by IBM of the incident, with preliminary investigations indicating that a dataset created solely for development and testing purposes had been accessed without authorisation. The dataset, created in 1998 and updated periodically over the years, was meant to contain only mock and anonymised testing data based on property ownership and lodgement records. However, SLA said it has since uncovered that the dataset also contained the names, National Registration Identity Card (NRIC) numbers and property addresses of the affected individuals at the time. “This information should have been anonymised but was not,” the agency said, adding that investigations are ongoing to determine how this occurred. SLA noted that the affected environment is “distinct and separate” from its operational systems, with no connection to, or compromise of, the live systems that run Stars, ELS or any other SLA systems. Property ownership and lodgement records remain secure and unaffected, it added. IBM has revoked access associated with the affected environment to prevent further unauthorised access, while SLA has identified the individuals whose information was contained in the dataset, and has begun notifying them and advising them on how to seek further information and assistance. Singapore mobilised over 100 cyber defenders to neutralise a sophisticated APT actor which infiltrated Singtel, StarHub, M1 and Simba networks in the country’s  largest coordinated cyber incident response to date . Japan’s Nikkei has confirmed a major data breach that potentially  exposed the personal information of more than 17,000 employees  and business partners after hackers infiltrated its internal Slack messaging platform. Australian privacy commissioner warns that the  human factor is a growing threat  as notifications caused by staff mistakes rose significantly even as total breaches declined 10% from a record high. Philippine bank  BDO is shoring up its cyber security capabilities  to protect its data and systems as it moves more services to the cloud and expands its physical presence into remote areas of the archipelago. The agency is working with IBM, the Government Technology Agency and the Cyber Security Agency of Singapore (CSA) to establish the full facts and ensure remedial measures are taken. It has also lodged a police report and notified the Personal Data Protection Commission, and urged the public to remain vigilant against phishing emails, websites, text messages and phone calls from parties claiming to represent government agencies or other organisations. “We apologise for the concern and inconvenience this incident may cause,” the SLA said. The incident underscores the long-standing risk of real personal data finding its way into development and test environments , which are typically less closely guarded than production systems – a risk that is compounded when those environments are operated by third parties. It is also the latest in a series of supply chain security incidents in Singapore in recent years. In April 2025, Toppan Next Tech, a printing supplier for DBS Bank and the Singapore branch of Bank of China, was hit by a ransomware attack that saw customer data stolen by the threat actor . Some 8,200 DBS customers – mostly holders of DBS Vickers trading accounts and Cashline loans – and around 3,000 Bank of China customers were potentially affected. A year earlier, in August 2024, a hacker who gained unauthorised access to Mobile Guardian , a mobile device management platform then deployed across Singapore’s schools, remotely wiped the iPads and Chromebooks of about 13,000 students from 26 secondary schools. The Ministry of Education subsequently removed the software from all student devices and terminated its contract with the supplier.

FAQ

Questions about Singapore cybersecurity signals

What is included on the Singapore page?

This page brings together current signals connected to Singapore through an affected location, a reviewed company profile, or both.

Does a signal prove the attacker is based in Singapore?

No. The country connection describes affected locations or profiled company locations. It does not claim actor origin unless a source explicitly establishes that separately.

Why can the number of signals change?

The page follows the rolling current-reporting window. Counts change as new incidents are added, evidence is reviewed, and older signals leave that window.