Grace Orchard School
bd_6e20e86ce99b4a06 · schema v1 · pii pii-v2
Full breach record for Grace Orchard School →Regulator's decision — not a breach notification
This record is a regulator's decision, not the organisation's own breach notice. Breach-notification fields (discovery date, notification clock) are structurally absent — what this source establishes is the outcome and the provisions the decision cites.
Background Grace Orchard School (the “Organisation”), a special education school operating under Presbyterian Community Social Services Ltd., notified the Personal Data Protection Commission (the “Commission”) on 12 November 2025 of a personal data breach involving its servers (the “Incident”). It was established that the threat actor (“TA”) gained administrator-level access to the Organisation’s perimeter firewall on or around 4 September 2025 by exploiting a critical firmware vulnerability. The TA then created new administrator accounts and moved laterally into the internal network, harvesting password hashes and accessed a file server and files containing personal data. The Incident affected 1,011 individuals comprising current and former students including minors, and current and former staff of the Organisation. Personal data affected included names and full NRIC numbers for students. For the staff, the affected personal data extended beyond names and full NRIC numbers to addresses, personal email addresses, telephone numbers, photographs, dates of birth, financial information (such as bank account details), insurance information (such as insurer names and claim amounts), and health information (such as discharge summaries). There was no evidence of exfiltration of the personal data. Upon discovery of the Incident, the Organisation took prompt remedial actions including resetting all administrator and domain administrator passwords on the affected servers, disconnecting affected servers and conducting full virus scans, hardening the firewall configuration, removing all rogue administrator accounts not created by the Organisation and engaging the firewall vendor to verify the integrity of the firewall's operating system. The Organisation also later notified all affected individuals of the Incident. 5. The Incident likely resulted from a combination of security gap
P pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Sep 21, 2026
Filed
—
No linked breach filing · watching
Compliance clocks stay unassessable until a breach filing is linked. This record is the regulator's action, not a breach notice. Dashed segments fill in automatically when corroboration arrives.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- outcome + obligations
- fine (SGD) and affected count where a grounds document states them
- discovery date
- notification clock
See the underlying breach notice, if any.