DisclosureLens
SINGAPOREUnknownLow

Jet Aviation (Asia Pacific) Pte. Ltd.

bd_49c799d3369e1aa3 · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Feb 27, 2025

To disclose

Affected

Not disclosed

Confidence

90%
Full breach record for Jet Aviation (Asia Pacific) Pte. Ltd.

Regulator's decision — not a breach notification

This record is a regulator's decision, not the organisation's own breach notice. Breach-notification fields (discovery date, notification clock) are structurally absent — what this source establishes is the outcome and the provisions the decision cites.

Background Jet Aviation (Asia Pacific) Pte Ltd (the “ Organisation ”) operates private jet charters for individuals and provides aircraft Maintenance, Repair and Overhaul (“ MRO ”) services. On 26 July 2024, the Organisation notified the Personal Data Protection Commission (the “ Commission ”) of unauthorised access to 5 of the Organisation’s email accounts containing personal data (the “ Incident ”). I nvestigations revealed that that the threat actor (“ TA ”) had likely gained access to the email accounts via spear phishing emails sent to specific employees. The TA had engineered the phishing emails to appear as legitimate requests for e-signatures from either trusted business partners or from within the Organisation. The TA used a cloud-based e-signature service, Adobe Acrobat Sign, to send documents containing a phishing link to the targeted employees. As the phishing link was contained within the document, the emails bypassed the Organisation’s security scans for malicious email content. The targeted employees were convinced on the authenticity of the emails as the emails also bore a legitimate sender email address from Adobe. After clicking on the link, the employees were directed to a phishing website which emulated the Microsoft Office logon page and displayed genuine email addresses associated with the Organisation. Believing that the website that they had been directed to was authentic, the targeted employees entered their Microsoft credentials and the necessary passwords and multi-factor authentication (“ MFA ”) tokens. The phishing website then employed a reverse proxy to relay this information to the genuine Microsoft website and intercepted the primary refresh tokens returned by the Microsoft website. With the intercepted tokens, the TA was able to bypass existing MFA and gain persistent access to the email accounts. The 5 affected email accounts contain

Incident timeline — partial

? — ?

Breach window unknown

Feb 27, 2025

Filed

No linked breach filing · watching

Compliance clocks stay unassessable until a breach filing is linked. This record is the regulator's action, not a breach notice. Dashed segments fill in automatically when corroboration arrives.

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

Source ceiling

  • outcome + obligations
  • fine (SGD) and affected count where a grounds document states them
  • discovery date
  • notification clock

See the underlying breach notice, if any.