DisclosureLens
SINGAPOREUnknownHigh

MARINA BAY SANDS PTE. LTD.

bd_b7908b1836a01d09 · schema v1 · pii pii-v1

Severity

High

Financial impact

$333K

Discovered

Filed

Oct 28, 2025

To disclose

Affected

665,495

Confidence

90%
Full breach record for MARINA BAY SANDS PTE. LTD.

Regulator's decision — not a breach notification

This record is a regulator's decision, not the organisation's own breach notice. Breach-notification fields (discovery date, notification clock) are structurally absent — what this source establishes is the outcome and the provisions the decision cites.

EXECUTIVE SUMMARY (MARINA BAY SANDS PTE LTD) Decision The Personal Data Protection Commission (“PDPC”) has imposed a financial penalty of $315,000 on integrated resort operator Marina Bay Sands Pte Ltd (“MBS”) for breaching the Protection Obligation under the Personal Data Protection Act (“PDPA”). The penalty was determined in accordance with the revised Financial Penalty framework introduced by the Personal Data Protection (Amendment) Bill 2021. Incident In October 2023, 665,495 MBS patrons had their personal data illegally accessed and exfiltrated by unknown threat actor(s). The affected data, which included names and contact details that identified MBS’ patrons, was later found offered for sale on the dark web. Such data leaks can be further exploited in phishing scams or identity theft. Cause MBS admitted to breaching the Protection Obligation by failing to take reasonable security measures to protect the personal data in its possession. This occurred during a large-scale software migration exercise in March 2023. It was necessary for MBS to ensure that security policies (eg. who could access the data) were applied when migrating from the old software to the new. This meant that all related applications accessed through its Application Programming Interfaces (“ APIs ”) and respective identifiers, needed to be duly covered before and after the migration. However, one of the identifiers affecting the Art Science Friends webpage was omitted during the migration. As the webpage no longer had proper security policies in place, this allowed malicious threat actor(s) to access and exfiltrate its patrons’ personal data . Despite the clear risks involved in such a massive migration exercise, MBS had: • made a single employee responsible; • for manually compiling the list of API configurations; • without due second layer checks. MBS failed to discover and correct the omissi

Incident timeline — partial

? — ?

Breach window unknown

Oct 28, 2025

Filed

No linked breach filing · watching

Compliance clocks stay unassessable until a breach filing is linked. This record is the regulator's action, not a breach notice. Dashed segments fill in automatically when corroboration arrives.

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

Source ceiling

  • outcome + obligations
  • fine (SGD) and affected count where a grounds document states them
  • discovery date
  • notification clock

See the underlying breach notice, if any.