DisclosureLens
SINGAPOREUnknownLow

Absolute Telecom Pte Ltd

bd_6dc647ef084f77e7 · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Oct 23, 2024

To disclose

Affected

Not disclosed

Confidence

90%
Full breach record for Absolute Telecom Pte Ltd

Regulator's decision — not a breach notification

This record is a regulator's decision, not the organisation's own breach notice. Breach-notification fields (discovery date, notification clock) are structurally absent — what this source establishes is the outcome and the provisions the decision cites.

Background Absolute Telecom Pte Ltd (the “ Organisation ”) notified the Personal Data Protection Commission (the “ Commission ”) on 15 May 2024 that it came under a ransomware attack on 12 May 2024. The threat actor (“ TA ”) executed a SQL injection on the Organisation’s webpage and compromised administration rights (the “Incident”) . Investigation revealed that the Organisation’s website contained vulnerabilities , which allowed the TA to gain control of the system administrator account and exfiltrated the personal data of the affected individuals. As a result of the Incident, the personal data of approximately 578 individuals, including their names, address, NRIC numbers, phone numbers, email addresses and credit card information (number and expiry dates) were exfiltrated. The Commission found the Organisation to be lacking in its cybersecurity and data protection practices. The Organisation had engaged freelancers to develop its website in 2012, before the provisions relating to the protection of personal data under the Personal Data Protection Act 2012 came into force on 2 July 2014. The Organisation’s contract with the freelancers did not include any contractual requirements on the protection of personal data or the need to carry out any security testing before launch. Thereafter, the Organisation continued using the website and did not take steps to review whether the security arrangements for the website adequately protected its customers’ personal data. The Organisation also admitted that it did not have data protection policies or guidelines for its employees. Remedial Actions After the incident, the Organisation implemented the following: (a) Disconnected the server access to the public internet; (b) Reformatted the server to eliminate any potential malware; (c) Took down the affected web pages; (d) Notified affected individuals and filed a police report; an

Incident timeline — partial

? — ?

Breach window unknown

Oct 23, 2024

Filed

No linked breach filing · watching

Compliance clocks stay unassessable until a breach filing is linked. This record is the regulator's action, not a breach notice. Dashed segments fill in automatically when corroboration arrives.

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

Source ceiling

  • outcome + obligations
  • fine (SGD) and affected count where a grounds document states them
  • discovery date
  • notification clock

See the underlying breach notice, if any.