DisclosureLens
SINGAPOREUnknownLow

Grace Orchard School

bd_6e20e86ce99b4a06 · schema v1 · pii pii-v2

Severity

Low

Discovered

—

Filed

Sep 21, 2026

To disclose

—

Affected

Not disclosed

Confidence

95%
Full breach record for Grace Orchard School →

Regulator's decision — not a breach notification

This record is a regulator's decision, not the organisation's own breach notice. Breach-notification fields (discovery date, notification clock) are structurally absent — what this source establishes is the outcome and the provisions the decision cites.

Background Grace Orchard School (the “Organisation”), a special education school operating under Presbyterian Community Social Services Ltd., notified the Personal Data Protection Commission (the “Commission”) on 12 November 2025 of a personal data breach involving its servers (the “Incident”). It was established that the threat actor (“TA”) gained administrator-level access to the Organisation’s perimeter firewall on or around 4 September 2025 by exploiting a critical firmware vulnerability. The TA then created new administrator accounts and moved laterally into the internal network, harvesting password hashes and accessed a file server and files containing personal data. The Incident affected 1,011 individuals comprising current and former students including minors, and current and former staff of the Organisation. Personal data affected included names and full NRIC numbers for students. For the staff, the affected personal data extended beyond names and full NRIC numbers to addresses, personal email addresses, telephone numbers, photographs, dates of birth, financial information (such as bank account details), insurance information (such as insurer names and claim amounts), and health information (such as discharge summaries). There was no evidence of exfiltration of the personal data. Upon discovery of the Incident, the Organisation took prompt remedial actions including resetting all administrator and domain administrator passwords on the affected servers, disconnecting affected servers and conducting full virus scans, hardening the firewall configuration, removing all rogue administrator accounts not created by the Organisation and engaging the firewall vendor to verify the integrity of the firewall's operating system. The Organisation also later notified all affected individuals of the Incident. 5. The Incident likely resulted from a combination of security gap

Incident timeline — partial

? — ?

Breach window unknown

Sep 21, 2026

Filed

—

No linked breach filing · watching

Compliance clocks stay unassessable until a breach filing is linked. This record is the regulator's action, not a breach notice. Dashed segments fill in automatically when corroboration arrives.

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

Source ceiling

  • outcome + obligations
  • fine (SGD) and affected count where a grounds document states them
  • discovery date
  • notification clock

See the underlying breach notice, if any.

Grace Orchard School — PDPA enforcement decision (2026) · DisclosureLens