DisclosureLens
SINGAPOREUnknownMedium

Citizen Watches (H.K.) Ltd

bd_b4d972ef80a65d26 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Filed

Jan 23, 2025

To disclose

Affected

Not disclosed

Confidence

90%
Full breach record for Citizen Watches (H.K.) Ltd

Regulator's decision — not a breach notification

This record is a regulator's decision, not the organisation's own breach notice. Breach-notification fields (discovery date, notification clock) are structurally absent — what this source establishes is the outcome and the provisions the decision cites.

Background The Singapore branch of Citizen Watches (H.K.) (the “ Organisation ”) Limited notified the Personal Data Protection Commission (the “ Commission ”) on 26 April 2024 of a data breach incident where a threat actor had allegedly gained unauthorised access to its membership database that subsequently led to the exposure of the personal data of 8,126 individuals on the dark web (the “ Incident ”). Investigations revealed that the threat actor gained access to the Organisation’s membership database via its website for registered members (the “ Members Website ”) on or around 24 April 2024. This was likely due to the lack of implementation of a password for the administrator account for the Members Website. The Members Website had not been tested for vulnerabilities before it went to production in August 2018. For clarity, the Members Website had been launched by the Organisation to cater to the region’s membership campaign and was not affiliated to the brand’s official websites which had not been affected by the Incident. The Incident affected the personal data of 8,126 individuals that included their names, telephone numbers, personal email addresses, members account passwords, date of birth, country region, job industry and income range. The Organisation was found to be lacklustre in its cybersecurity and data protection practices, including failing to implement password protection for privileged accounts and failing to carry out proper testing of and subsequent security reviews of its Member Website. In addition, there was no proper documentation for password policies, IT security policies and data protection policies. Remedial Actions After the Incident, the Organisation implemented the following: (a) Engaged a third party to conduct digital forensic investigations and incident response; (b) Permanently shut down the Members Website; and (c) Deleted the entir

Incident timeline — partial

? — ?

Breach window unknown

Jan 23, 2025

Filed

No linked breach filing · watching

Compliance clocks stay unassessable until a breach filing is linked. This record is the regulator's action, not a breach notice. Dashed segments fill in automatically when corroboration arrives.

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

Source ceiling

  • outcome + obligations
  • fine (SGD) and affected count where a grounds document states them
  • discovery date
  • notification clock

See the underlying breach notice, if any.