RIWAY (SINGAPORE) PTE. LTD.
bd_ce9029ce7ff3557b · schema v1 · pii pii-v1
Full breach record for RIWAY (SINGAPORE) PTE. LTD. →Regulator's decision — not a breach notification
This record is a regulator's decision, not the organisation's own breach notice. Breach-notification fields (discovery date, notification clock) are structurally absent — what this source establishes is the outcome and the provisions the decision cites.
Background Riway (Singapore) Pte Ltd (the “ Organisation ”) notified the Personal Data Protection Commission (the “ Commission ”) on 14 November 2024 of a personal data breach involving an unauthorised access to their database. The Threat Actor (“ TA ”) compromised the Organisation’s system through SQL injection via their membership portal (the “ Incident ”). The Organisation established that inadequate system configuration, specifically the lack of adequate data validation and parameterised queries as security features, allowed the TA to bypass other implemented security measures, making the system vulnerable to SQL injections. The affected system, which uses a SQL-based database, had been in operation since 2008 . T he TA accessed the Organisation's database through SQL injections via the membership portal by manipulating the input parameters of a backend function. Through this method, the TA obtained access to the Organisation's administrator account. The membership portal did not have a direct function for bulk data export or download, even with administrator access. However, the TA could have extracted data through manual screenshots or automated page-by-page recording. The Incident affected 3,636 individuals, compromising the name, NRIC/ passport number, address, contact number, ID images and username/ member ID. Upon discovery of the Incident, the Organisation took prompt remedial actions including: (a) Identifying root causes and implementing mitigation measures to block unauthorised access and prevent further data exposure; (b) Resetting all administrator passwords to deny access to all unauthorised users; (c) Immediately patching the identified SQL injection vulnerability and other related security gaps; (d) Conducting security configuration to enable the SQL injection protection rules within the Web Application Firewall; and (e) Notifying all affected indiv
P pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Sep 3, 2025
Filed
—
No linked breach filing · watching
Compliance clocks stay unassessable until a breach filing is linked. This record is the regulator's action, not a breach notice. Dashed segments fill in automatically when corroboration arrives.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- outcome + obligations
- fine (SGD) and affected count where a grounds document states them
- discovery date
- notification clock
See the underlying breach notice, if any.