DisclosureLens
SINGAPOREUnknownLow

TJ Assurance Partners PAC

bd_97d10ed666195526 · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Aug 7, 2025

To disclose

Affected

Not disclosed

Confidence

90%
Full breach record for TJ Assurance Partners PAC

Regulator's decision — not a breach notification

This record is a regulator's decision, not the organisation's own breach notice. Breach-notification fields (discovery date, notification clock) are structurally absent — what this source establishes is the outcome and the provisions the decision cites.

Background TJ Assurance Partners PAC (the “ Organisation ”) notified the Personal Data Protection Commission (the “ Commission ”) on 12 March 2025 of a data breach involving an unauthorized access to one of the Organisation’s corporate email accounts. The Threat Actor (“ TA ”) subsequently used the compromised email account to send phishing emails to the Organisation’s clients (the “ Incident ”). The Organisation established that the Incident occurred when a staff member fell victim to a phishing attack, enabling the TA to gain access to the mailbox of the compromised email account for about one hour. During the access period, the TA accessed a number of emails and used the mailbox to send phishing emails to contacts in the address book. Based on the log analysis performed with Microsoft support, no file downloads were detected. The personal data was contained in email attachments within the email correspondence of the compromised mailbox, affecting 71 individuals. The affected personal data included full name, address, NRIC number, passport number, nationality, and financial information. Upon discovery of the Incident, the Organisation took prompt remedial actions including: (a) Notified recipients of the phishing emails purportedly sent out by the Organisation; (b) Forced logout of all Microsoft 365 users across the Organisation to invalidate active sessions; and (c) Reset the password and revoking the Microsoft 365 license associated with the compromised mailbox. Voluntary Undertaking Having considered the circumstances of the case, the Commission accepted a voluntary undertaking (the “ Undertaking ”) from the Organisation to improve its compliance with the Personal Data Protection Act 2012 (the “ PDPA ”). The Undertaking was executed on 26 June 2025. As part of the Undertaking, the Organisation will be implementing the following including: (a) Conduct phishing sim

Incident timeline — partial

? — ?

Breach window unknown

Aug 7, 2025

Filed

No linked breach filing · watching

Compliance clocks stay unassessable until a breach filing is linked. This record is the regulator's action, not a breach notice. Dashed segments fill in automatically when corroboration arrives.

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

Source ceiling

  • outcome + obligations
  • fine (SGD) and affected count where a grounds document states them
  • discovery date
  • notification clock

See the underlying breach notice, if any.