Citizen Watches (H.K.) Ltd
bd_b4d972ef80a65d26 · schema v1 · pii pii-v1
Full breach record for Citizen Watches (H.K.) Ltd →Regulator's decision — not a breach notification
This record is a regulator's decision, not the organisation's own breach notice. Breach-notification fields (discovery date, notification clock) are structurally absent — what this source establishes is the outcome and the provisions the decision cites.
Background The Singapore branch of Citizen Watches (H.K.) (the “ Organisation ”) Limited notified the Personal Data Protection Commission (the “ Commission ”) on 26 April 2024 of a data breach incident where a threat actor had allegedly gained unauthorised access to its membership database that subsequently led to the exposure of the personal data of 8,126 individuals on the dark web (the “ Incident ”). Investigations revealed that the threat actor gained access to the Organisation’s membership database via its website for registered members (the “ Members Website ”) on or around 24 April 2024. This was likely due to the lack of implementation of a password for the administrator account for the Members Website. The Members Website had not been tested for vulnerabilities before it went to production in August 2018. For clarity, the Members Website had been launched by the Organisation to cater to the region’s membership campaign and was not affiliated to the brand’s official websites which had not been affected by the Incident. The Incident affected the personal data of 8,126 individuals that included their names, telephone numbers, personal email addresses, members account passwords, date of birth, country region, job industry and income range. The Organisation was found to be lacklustre in its cybersecurity and data protection practices, including failing to implement password protection for privileged accounts and failing to carry out proper testing of and subsequent security reviews of its Member Website. In addition, there was no proper documentation for password policies, IT security policies and data protection policies. Remedial Actions After the Incident, the Organisation implemented the following: (a) Engaged a third party to conduct digital forensic investigations and incident response; (b) Permanently shut down the Members Website; and (c) Deleted the entir
P pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Jan 23, 2025
Filed
—
No linked breach filing · watching
Compliance clocks stay unassessable until a breach filing is linked. This record is the regulator's action, not a breach notice. Dashed segments fill in automatically when corroboration arrives.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- outcome + obligations
- fine (SGD) and affected count where a grounds document states them
- discovery date
- notification clock
See the underlying breach notice, if any.