Focus Adventure Pte Ltd
bd_7c90e2beb17f5c02 · schema v1 · pii pii-v1
Full breach record for Focus Adventure Pte Ltd →Regulator's decision — not a breach notification
This record is a regulator's decision, not the organisation's own breach notice. Breach-notification fields (discovery date, notification clock) are structurally absent — what this source establishes is the outcome and the provisions the decision cites.
Background On 10 January 2022, Personal Data Protection Commission (the “ Commission ”) reached out to Focus Adventure Pte. Ltd. (the “ Organisation ”) after receiving information that databases, containing personal data of individuals associated with the Organisation, were made available for sale on the dark web (the “Incident ”). Subsequently, the Organisation lodged a data breach notification on 12 January 2022. Investigation revealed that the Organisation had suffered a ransomware attack on its company servers on 19 December 2021. The Organisation restored its servers from backups. It was believed that the files in the server were exfiltrated by the threat actor(s) during this period. As a result of the Incident, the personal data of approximately 923 individuals, including their names, NRIC numbers, date of birth, phone numbers, email addresses and bank account details (for former and current employees) were encrypted and exfiltrated by the threat actor(s). The Organisation was found to be lacklustre in its cybersecurity and data protection practices, including the usage of end of life (“ EOL ”) software for its servers and for failing to carry out any periodic security reviews of its unpatched servers. In addition, there was no proper documentation for password policies, patch management policies or change management policies. Remedial Actions After the incident, the Organisation implemented the following: (a) Changed the password to its servers and firewall; and (b) Installed endpoint security solutions for all users. Voluntary Undertaking Having considered the circumstances of the case and the lack of knowledge by the Organisation in cybersecurity and data protection practices, the Commission accepted a voluntary undertaking (the “ Undertaking ”), which was executed on 19 July 2022, from the Organisation to engage an external service provider to improve its cy
P pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
May 23, 2024
Filed
—
No linked breach filing · watching
Compliance clocks stay unassessable until a breach filing is linked. This record is the regulator's action, not a breach notice. Dashed segments fill in automatically when corroboration arrives.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- outcome + obligations
- fine (SGD) and affected count where a grounds document states them
- discovery date
- notification clock
See the underlying breach notice, if any.