DisclosureLens
SINGAPOREUnknownLow

Focus Adventure Pte Ltd

bd_7c90e2beb17f5c02 · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

May 23, 2024

To disclose

Affected

Not disclosed

Confidence

90%
Full breach record for Focus Adventure Pte Ltd

Regulator's decision — not a breach notification

This record is a regulator's decision, not the organisation's own breach notice. Breach-notification fields (discovery date, notification clock) are structurally absent — what this source establishes is the outcome and the provisions the decision cites.

Background On 10 January 2022, Personal Data Protection Commission (the “ Commission ”) reached out to Focus Adventure Pte. Ltd. (the “ Organisation ”) after receiving information that databases, containing personal data of individuals associated with the Organisation, were made available for sale on the dark web (the “Incident ”). Subsequently, the Organisation lodged a data breach notification on 12 January 2022. Investigation revealed that the Organisation had suffered a ransomware attack on its company servers on 19 December 2021. The Organisation restored its servers from backups. It was believed that the files in the server were exfiltrated by the threat actor(s) during this period. As a result of the Incident, the personal data of approximately 923 individuals, including their names, NRIC numbers, date of birth, phone numbers, email addresses and bank account details (for former and current employees) were encrypted and exfiltrated by the threat actor(s). The Organisation was found to be lacklustre in its cybersecurity and data protection practices, including the usage of end of life (“ EOL ”) software for its servers and for failing to carry out any periodic security reviews of its unpatched servers. In addition, there was no proper documentation for password policies, patch management policies or change management policies. Remedial Actions After the incident, the Organisation implemented the following: (a) Changed the password to its servers and firewall; and (b) Installed endpoint security solutions for all users. Voluntary Undertaking Having considered the circumstances of the case and the lack of knowledge by the Organisation in cybersecurity and data protection practices, the Commission accepted a voluntary undertaking (the “ Undertaking ”), which was executed on 19 July 2022, from the Organisation to engage an external service provider to improve its cy

Incident timeline — partial

? — ?

Breach window unknown

May 23, 2024

Filed

No linked breach filing · watching

Compliance clocks stay unassessable until a breach filing is linked. This record is the regulator's action, not a breach notice. Dashed segments fill in automatically when corroboration arrives.

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

Source ceiling

  • outcome + obligations
  • fine (SGD) and affected count where a grounds document states them
  • discovery date
  • notification clock

See the underlying breach notice, if any.