DisclosureLens
SINGAPOREUnknownLow

Axxis Consulting (S) Pte Ltd

bd_7814528acae0874d · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Dec 4, 2025

To disclose

Affected

Not disclosed

Confidence

90%
Full breach record for Axxis Consulting (S) Pte Ltd

Regulator's decision — not a breach notification

This record is a regulator's decision, not the organisation's own breach notice. Breach-notification fields (discovery date, notification clock) are structurally absent — what this source establishes is the outcome and the provisions the decision cites.

Background Axxis Consulting (S) Pte Ltd (the “ Organisation ”), a reseller of SAP Enterprise Resource Planning (“ ERP ”) systems that provides installation and configuration of SAP services and cloud hosting services, discovered a ransomware attack within its data center environment on 22 June 2024 after corporate clients reported difficulties connecting to its cloud hosting platform. Nine (9) VMware ESXi servers (the “ ESXi servers ”) likely to contain personal data from its clients had been encrypted by ransomware (the “ Incident ”). The Personal Data Protection Commission (the “ Commission ”) was notified of the Incident through several of its affected clients on 12 July 2024. Investigations revealed that the threat actor (“ TA ”) had gained initial access to the Organisation’s network through SSL-VPN connectivity on the Organisation’s firewall using a local administrative account, likely stolen by exploiting known vulnerabilities in the firewall that had reached End-of-Life (“ EOL ”) support as of 11 October 2023. The TA subsequently created an unauthorised administrative-level account on the Organisation’s backup server and deleted backup data via Remote Desktop Protocol (“ RDP ”) connectivity. Other vulnerabilities in the Organisation’s server management software also were likely exploited by the TA to activate Secure Shell (“ SSH ”) connections to the ESXi servers and execute ransomware encryption. The TA had disabled the Organisation's data center environment by encrypting server configuration files and the virtual hard disk drives on the ESXi serves which affected user access of 74 corporate clients, including 54 Singapore-based companies, to their respective SAP ERP systems hosted on the ESXi servers. Investigations found that before the Incident, data on the SAP ERP software was encrypted at rest through SAP’s security controls and access to client database

Incident timeline — partial

? — ?

Breach window unknown

Dec 4, 2025

Filed

No linked breach filing · watching

Compliance clocks stay unassessable until a breach filing is linked. This record is the regulator's action, not a breach notice. Dashed segments fill in automatically when corroboration arrives.

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

Source ceiling

  • outcome + obligations
  • fine (SGD) and affected count where a grounds document states them
  • discovery date
  • notification clock

See the underlying breach notice, if any.