DisclosureLens
SINGAPOREUnknownMedium

JLegal Pte Ltd

bd_5cb08634d8347225 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Filed

Aug 28, 2024

To disclose

Affected

Not disclosed

Confidence

90%
Full breach record for JLegal Pte Ltd

Regulator's decision — not a breach notification

This record is a regulator's decision, not the organisation's own breach notice. Breach-notification fields (discovery date, notification clock) are structurally absent — what this source establishes is the outcome and the provisions the decision cites.

Background JLegal Pte. Ltd. (the “ Organisation ”) is a specialist legal recruitment company. The Organisation notified the Personal Data Protection Commission (the “ Commission ”) on 17 May 2024 that a threat actor had gained unauthorised access to and deleted files containing personal data of 1,798 jobseekers that the Organisation stored on its Synology Network Attached Storage (“ NAS ”) (the “ Incident ”). The Organisation managed to recover the deleted files from the recycle bin. The breakdown of the types of affected personal data is as follows: Type of Personal Data Number of Affected Individuals Name 1,798 Email Address 1,685 Mailing Address 715 Telephone Number 1,551 Identification Number (i.e. NRIC, FIN, and foreign IC) 176 Passport Number 8 Photograph 453 Date of Birth 219 Salary Data 501 The Organisation engaged a forensic investigator to assist in its investigations. The forensic investigator was unable to determine if the personal data had been exfiltrated as the NAS’s logging feature was not enabled. The Organisation’s investigations suggested that four factors enabled the threat actor to gain access to the NAS: (a) First, the Organisation had enabled the Quick Connect feature for the NAS (which allows client application to connect to the NAS via the internet). (b) Second, the credentials of the NAS had been compromised. (c) Third, the Organisation did not enable two-factor authentication for the NAS. (d) Finally, the firewall settings had allowed internet access to the NAS. Upon discovery of the Incident, the Organisation took prompt remedial actions. This included moving all personal data from the NAS server to offline portable storage disks and ceasing the use of the NAS server and all online storage. The Organisation also implemented administrative measures to protect the personal data stored in the portable storage disks, and to periodically review

Incident timeline — partial

? — ?

Breach window unknown

Aug 28, 2024

Filed

No linked breach filing · watching

Compliance clocks stay unassessable until a breach filing is linked. This record is the regulator's action, not a breach notice. Dashed segments fill in automatically when corroboration arrives.

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

Source ceiling

  • outcome + obligations
  • fine (SGD) and affected count where a grounds document states them
  • discovery date
  • notification clock

See the underlying breach notice, if any.