Absolute Telecom Pte Ltd
bd_6dc647ef084f77e7 · schema v1 · pii pii-v1
Full breach record for Absolute Telecom Pte Ltd →Regulator's decision — not a breach notification
This record is a regulator's decision, not the organisation's own breach notice. Breach-notification fields (discovery date, notification clock) are structurally absent — what this source establishes is the outcome and the provisions the decision cites.
Background Absolute Telecom Pte Ltd (the “ Organisation ”) notified the Personal Data Protection Commission (the “ Commission ”) on 15 May 2024 that it came under a ransomware attack on 12 May 2024. The threat actor (“ TA ”) executed a SQL injection on the Organisation’s webpage and compromised administration rights (the “Incident”) . Investigation revealed that the Organisation’s website contained vulnerabilities , which allowed the TA to gain control of the system administrator account and exfiltrated the personal data of the affected individuals. As a result of the Incident, the personal data of approximately 578 individuals, including their names, address, NRIC numbers, phone numbers, email addresses and credit card information (number and expiry dates) were exfiltrated. The Commission found the Organisation to be lacking in its cybersecurity and data protection practices. The Organisation had engaged freelancers to develop its website in 2012, before the provisions relating to the protection of personal data under the Personal Data Protection Act 2012 came into force on 2 July 2014. The Organisation’s contract with the freelancers did not include any contractual requirements on the protection of personal data or the need to carry out any security testing before launch. Thereafter, the Organisation continued using the website and did not take steps to review whether the security arrangements for the website adequately protected its customers’ personal data. The Organisation also admitted that it did not have data protection policies or guidelines for its employees. Remedial Actions After the incident, the Organisation implemented the following: (a) Disconnected the server access to the public internet; (b) Reformatted the server to eliminate any potential malware; (c) Took down the affected web pages; (d) Notified affected individuals and filed a police report; an
P pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Oct 23, 2024
Filed
—
No linked breach filing · watching
Compliance clocks stay unassessable until a breach filing is linked. This record is the regulator's action, not a breach notice. Dashed segments fill in automatically when corroboration arrives.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- outcome + obligations
- fine (SGD) and affected count where a grounds document states them
- discovery date
- notification clock
See the underlying breach notice, if any.