Ardent IT Pte Ltd
bd_80ea72dd72201aaf · schema v1 · pii pii-v1
Full breach record for Ardent IT Pte Ltd →Regulator's decision — not a breach notification
This record is a regulator's decision, not the organisation's own breach notice. Breach-notification fields (discovery date, notification clock) are structurally absent — what this source establishes is the outcome and the provisions the decision cites.
Background Ardent IT Pte Ltd (the “ Organisation ”) is a system integrator providing IT infrastructure implementation and maintenance services to its clients. The Organisation provides Infrastructure as a Service (“ IaaS ”), including virtual servers, as a data storage solution. The Organisation processes personal data on behalf of its clients. As part of the Organisation’s services, virtual machine(s) stored as virtual hard disk (“ VHD ”) files were provided to the clients to house their data. On 15 August 2024, the Organisation notified the Personal Data Protection Commission (the “ Commission ”) that its VHD files had been encrypted by LockBit ransomware, rendering it inaccessible to its clients (the “ Incident ”). Investigations revealed that that the threat actor (“ TA ”) gained access on 4 August 2024 into the Organisation’s hypervisor hosts through the integrated Dell Remove Access Controller (“ iDRAC ”) by way of compromised root account credentials. Due to a lack of Windows event logs, the Organisation could not definitively determine how the TA obtained the root account credentials. After gaining access, the TA triggered a malicious encryptor to encrypt the VHD files, rendering them inaccessible to its clients. Investigations suggest that the following could have led to the TA gaining unauthorised access into the Organisation’s hypervisor hosts: (a) There were 91,939 attempts at password spraying and user enumeration made on the hypervisor hosts from 5 August 2024 to 9 August 2024. Many login attempts were successful during this period, which suggests that the TA could have obtained the credentials via this route. (b) The default iDRAC root account was used for all iDRAC logins. Default accounts are often targeted by threat actors. Organisations are reminded that it is a good practice to disable default accounts, and to create a custom account with appropria
P pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Dec 4, 2025
Filed
—
No linked breach filing · watching
Compliance clocks stay unassessable until a breach filing is linked. This record is the regulator's action, not a breach notice. Dashed segments fill in automatically when corroboration arrives.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- outcome + obligations
- fine (SGD) and affected count where a grounds document states them
- discovery date
- notification clock
See the underlying breach notice, if any.