DisclosureLens
SINGAPOREUnknownLow

Japalang Pte Ltd

bd_c21d3b88ed14b682 · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Aug 2, 2024

To disclose

Affected

Not disclosed

Confidence

90%
Full breach record for Japalang Pte Ltd

Regulator's decision — not a breach notification

This record is a regulator's decision, not the organisation's own breach notice. Breach-notification fields (discovery date, notification clock) are structurally absent — what this source establishes is the outcome and the provisions the decision cites.

Background On 7 August 2023, Japalang Pte. Ltd. (the “ Organisation ”) notified the Personal Data Protection Commission (the “ Commission ”) of a ransomware attack on its servers, which led to the encryption of personal data of its staff and customers (the “ Incident ”). The Incident was first discovered on 2 August 2023 when employees found that some files were inaccessible. The Incident led to the potential unauthorised access and encryption of personal data of 70 customers and 30 employees. The types of personal data affected include name, address and contact number. For the affected employees, their NRIC number, passport number, date of birth and salary were affected as well. Investigations revealed that the Organisation failed to (i) implement adequate personal data protection measures and safeguards; (ii) put in place password and patch management policies; and (iii) appoint a Data Protection Officer. Remedial Actions After the Incident, the Organisation took the following remedial actions: (a) Reformatted all endpoint computers; (b) Engaged an IT firm to upgrade its Windows operating system and firewall; (c) Implemented password protection; and (d) Upgraded its VPN remote connection method to allow only computers with a digital certificate to connect remotely. Voluntary Undertaking Having considered the circumstances of the case and the lack of knowledge by the Organisation in cybersecurity and data protection practices, the Commission accepted a voluntary undertaking (the “ Undertaking ”), which was executed on 11 March 2024, from the Organisation to engage an external service provider to improve its cybersecurity set-up and its data protection practices and policies. As part of the Undertaking, the external service provider will assist the Organisation to first complete an initial set-up within 2 months. The initial set-up will include the appointment and reg

Incident timeline — partial

? — ?

Breach window unknown

Aug 2, 2024

Filed

No linked breach filing · watching

Compliance clocks stay unassessable until a breach filing is linked. This record is the regulator's action, not a breach notice. Dashed segments fill in automatically when corroboration arrives.

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

Source ceiling

  • outcome + obligations
  • fine (SGD) and affected count where a grounds document states them
  • discovery date
  • notification clock

See the underlying breach notice, if any.