DisclosureLens
SINGAPOREUnknownLow

Fire Safety Managers' Association Singapore

bd_0bd1472fdf61b55c · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Aug 2, 2024

To disclose

Affected

Not disclosed

Confidence

90%
Full breach record for Fire Safety Managers' Association Singapore

Regulator's decision — not a breach notification

This record is a regulator's decision, not the organisation's own breach notice. Breach-notification fields (discovery date, notification clock) are structurally absent — what this source establishes is the outcome and the provisions the decision cites.

Background The Fire Safety Managers’ Association Singapore (the “ Organisation ”) notified the Personal Data Protection Commission (the “ Commission ”) of a personal data breach on 17 April 2024 after its members received phishing emails purportedly sent by the Organisation (the “ Incident ”). The phishing emails contained the members’ NRIC number and invited the recipient to scan a QR code to receive credit card promotions and discounts, when the QR code was in fact an attempt by the threat actor to obtain the individual’s bank details. Investigations revealed that the Organisation’s website contained vulnerabilities, which allowed the threat actor(s) to exfiltrate the personal data of the affected individuals. As a result of the Incident, the personal data of approximately 2,000 individuals, including their names, NRIC numbers, membership numbers, email addresses, and addresses, could have been exfiltrated by the threat actor(s). The Organisation had engaged a vendor to develop its website in 2012 but did not take any steps thereafter to review whether the security arrangements for the website adequately protected its members’ personal data. The Organisation also admitted that it did not have a data protection officer (“ DPO ”) appointed. Remedial Actions After the incident, the Organisation decommissioned its website. Voluntary Undertaking Having considered the circumstances of the case, in particular, the fact that the Organisation is a society run by volunteers, the Commission accepted a voluntary undertaking (the “ Undertaking ”) on 13 June 2024 from the Organisation to engage an external service provider to improve its cybersecurity set-up and its data protection practices and policies. As part of the Undertaking, the external service provider will assist the Organisation to first complete an initial set-up within 2 months. The initial set-up will include the a

Incident timeline — partial

? — ?

Breach window unknown

Aug 2, 2024

Filed

No linked breach filing · watching

Compliance clocks stay unassessable until a breach filing is linked. This record is the regulator's action, not a breach notice. Dashed segments fill in automatically when corroboration arrives.

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

Source ceiling

  • outcome + obligations
  • fine (SGD) and affected count where a grounds document states them
  • discovery date
  • notification clock

See the underlying breach notice, if any.