NOEL GIFTS INTERNATIONAL LTD.
bd_ac577415f7254aad · schema v1 · pii pii-v1
Full breach record for NOEL GIFTS INTERNATIONAL LTD. →Regulator's decision — not a breach notification
This record is a regulator's decision, not the organisation's own breach notice. Breach-notification fields (discovery date, notification clock) are structurally absent — what this source establishes is the outcome and the provisions the decision cites.
Background On 13 February 2025, Noel Gifts International Ltd. (the “ Organisation ”) notified the Personal Data Protection Commission (the “ Commission ”) that a threat actor (“ TA ”) had gained unauthorised access to the web management consoles belonging to the Organisation and its subsidiary. This led to exfiltration of the personal data contained within the web management consoles (the “ Incident ”). The Organisation established that the TA had likely gained access to both web management consoles by exploiting login credentials belonging to one of the authorised accounts which allowed the TA to access the Sales Report function within. The TA then exfiltrated files containing personal data of approximately 200,000 former and existing customers belonging to the Organisation and its subsidiary . Only the personal email addresses of customers used to facilitate the sending of order confirmation had been affected in this Incident. Upon discovery of the Incident, the Organisation took prompt remedial actions including, but not limited to, enhancing their password requirements across all accounts, introducing email based one-time password authentication, implementing account lockout and comprehensive login activity to monitor and track all system-access attempts, including management consoles and conducting a thorough review of management console access permissions, with access rights revised based on a need-to basis. Voluntary Undertaking Having considered the circumstances of the case, the Commission accepted a voluntary undertaking (the “ Undertaking ”) from the Organisation to improve its compliance with the Personal Data Protection Act 2012 (the “ PDPA ”). The Undertaking was executed on 29 May 2025. As part of the Undertaking, the Organisation will implement the following: (a) Additional multi-factor authentication for administrative accounts to servers and systems
P pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Dec 4, 2025
Filed
—
No linked breach filing · watching
Compliance clocks stay unassessable until a breach filing is linked. This record is the regulator's action, not a breach notice. Dashed segments fill in automatically when corroboration arrives.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- outcome + obligations
- fine (SGD) and affected count where a grounds document states them
- discovery date
- notification clock
See the underlying breach notice, if any.