ComGateway
bd_2050a0080c050aa5 · schema v1 · pii pii-v1
Full breach record for ComGateway →Regulator's decision — not a breach notification
This record is a regulator's decision, not the organisation's own breach notice. Breach-notification fields (discovery date, notification clock) are structurally absent — what this source establishes is the outcome and the provisions the decision cites.
A financial penalty of $10,000 was imposed on ComGateway for not protecting its webpage against URL manipulation, which resulted in unauthorised disclosure of its customers' personal data. Click here to find out more.
P pin to compareR raw source
Incident timeline
Jul 2, 2014
Begins
Dec 29, 2017
Filed
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- outcome + obligations
- fine (SGD) and affected count where a grounds document states them
- discovery date
- notification clock
See the underlying breach notice, if any.