Comwerkz Technology Pte Ltd
bd_7f8bbfae61169e45 · schema v1 · pii pii-v1
Full breach record for Comwerkz Technology Pte Ltd →Regulator's decision — not a breach notification
This record is a regulator's decision, not the organisation's own breach notice. Breach-notification fields (discovery date, notification clock) are structurally absent — what this source establishes is the outcome and the provisions the decision cites.
Background On 5 December 2023, the Personal Data Protection Commission (the “ PDPC ”) was notified by Comwerkz Technology Pte Ltd (the “ Organisation ”) of a personal data breach incident after the Organisation discovered that its files had been encrypted by ransomware on or about 1 December 2023. Investigations found that a work-issued laptop was infected with malware, and this had most likely occurred when an employee clicked on a malicious link (the “ Incident ”). As a result of the Incident, the personal data of approximately 48 employees, including their names, NRIC numbers (of 7 out of 48 employees), FIN numbers, date of birth, nationality, contact numbers and residential addresses were at risk of unauthorised access. There was no evidence of exfiltration of data. Investigations revealed that the Organisation did not appoint a data protection officer and had failed to properly document any data protection or IT security policies. Remedial Actions After the incident, the Organisation implemented the following remedial actions: (a) Promptly notified all employees about the Incident; (b) Reformatted the affected server, SSD storage and laptop; (c) Issued a warning to staff members to be cautious of phishing advertisments/ emails; and (d) Enrolled selected staff members to attend basic cybersecurity training. Voluntary Undertaking Having considered the circumstances of the case and the lack of knowledge by the Organisation in cybersecurity and data protection practices, the Commission accepted a voluntary undertaking (the “ Undertaking ”), which was executed on 1 March 2024, from the Organisation to engage an external service provider to improve its cybersecurity set-up and its data protection practices and policies. As part of the Undertaking, the external service provider will assist the Organisation to first complete an initial set-up within 2 months. The initial
P pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Aug 2, 2024
Filed
—
No linked breach filing · watching
Compliance clocks stay unassessable until a breach filing is linked. This record is the regulator's action, not a breach notice. Dashed segments fill in automatically when corroboration arrives.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- outcome + obligations
- fine (SGD) and affected count where a grounds document states them
- discovery date
- notification clock
See the underlying breach notice, if any.