MARINA BAY SANDS PTE. LTD.
bd_b7908b1836a01d09 · schema v1 · pii pii-v1
Full breach record for MARINA BAY SANDS PTE. LTD. →Regulator's decision — not a breach notification
This record is a regulator's decision, not the organisation's own breach notice. Breach-notification fields (discovery date, notification clock) are structurally absent — what this source establishes is the outcome and the provisions the decision cites.
EXECUTIVE SUMMARY (MARINA BAY SANDS PTE LTD) Decision The Personal Data Protection Commission (“PDPC”) has imposed a financial penalty of $315,000 on integrated resort operator Marina Bay Sands Pte Ltd (“MBS”) for breaching the Protection Obligation under the Personal Data Protection Act (“PDPA”). The penalty was determined in accordance with the revised Financial Penalty framework introduced by the Personal Data Protection (Amendment) Bill 2021. Incident In October 2023, 665,495 MBS patrons had their personal data illegally accessed and exfiltrated by unknown threat actor(s). The affected data, which included names and contact details that identified MBS’ patrons, was later found offered for sale on the dark web. Such data leaks can be further exploited in phishing scams or identity theft. Cause MBS admitted to breaching the Protection Obligation by failing to take reasonable security measures to protect the personal data in its possession. This occurred during a large-scale software migration exercise in March 2023. It was necessary for MBS to ensure that security policies (eg. who could access the data) were applied when migrating from the old software to the new. This meant that all related applications accessed through its Application Programming Interfaces (“ APIs ”) and respective identifiers, needed to be duly covered before and after the migration. However, one of the identifiers affecting the Art Science Friends webpage was omitted during the migration. As the webpage no longer had proper security policies in place, this allowed malicious threat actor(s) to access and exfiltrate its patrons’ personal data . Despite the clear risks involved in such a massive migration exercise, MBS had: • made a single employee responsible; • for manually compiling the list of API configurations; • without due second layer checks. MBS failed to discover and correct the omissi
P pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Oct 28, 2025
Filed
—
No linked breach filing · watching
Compliance clocks stay unassessable until a breach filing is linked. This record is the regulator's action, not a breach notice. Dashed segments fill in automatically when corroboration arrives.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- outcome + obligations
- fine (SGD) and affected count where a grounds document states them
- discovery date
- notification clock
See the underlying breach notice, if any.