DisclosureLens
SINGAPOREUnknownLow

Geodis Logistics Singapore Pte Ltd

bd_d89c74bffe4796f1 · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Aug 2, 2024

To disclose

Affected

Not disclosed

Confidence

90%
Full breach record for Geodis Logistics Singapore Pte Ltd

Regulator's decision — not a breach notification

This record is a regulator's decision, not the organisation's own breach notice. Breach-notification fields (discovery date, notification clock) are structurally absent — what this source establishes is the outcome and the provisions the decision cites.

Background On 21 October 2022 and 28 October 2022, the Personal Data Protection Commission (the “ Commission ”) received notifications from Geodis Logistics Singapore Pte. Ltd. (the “ Organisation ”) and Keppel Telecommunications & Transportation Ltd (“ KTT ”) respectively about a data breach incident involving unauthorised access and exfiltration of personal data from two servers belonging to the Organisation (the “ Incident ”). Investigations revealed that a malicious actor had logged on to a remote desktop application, using a vendor’s account. Through privilege escalation, the malicious actor successfully deployed ransomware and exfiltrated the personal data of 6,337 individuals. The personal data affected included 6,287 images of proof of delivery of parcel recipients, which contained their name, delivery address, contact number, product delivered, signature, order number and sales bill number. In addition, the personal data of 64 directors and 26 employees including their name, date of birth, address, contact number, NRIC number, passport number, bank details, and tax file number was exfiltrated. Investigations could not determine how the malicious actor was able to obtain the username and password. The vendor engaged by the Organisation to maintain its warehouse management and web servers found no unauthorised access from its systems to Organisation’s network. There were also no malicious files or programmes present on the vendor’s computers, and no indication of compromise, data exfiltration, or unauthorised access on its systems. Remedial Actions After the Incident, as part of a remediation plan, Organisation took the following actions: (a) Took affected systems offline, scanned affected environments, rebuilt compromised servers/ endpoints, and reset passwords for affected IT environment; ( b) Monitored dark web for uploads of exfiltrated data; (c) Decommissi

Incident timeline — partial

? — ?

Breach window unknown

Aug 2, 2024

Filed

No linked breach filing · watching

Compliance clocks stay unassessable until a breach filing is linked. This record is the regulator's action, not a breach notice. Dashed segments fill in automatically when corroboration arrives.

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

Source ceiling

  • outcome + obligations
  • fine (SGD) and affected count where a grounds document states them
  • discovery date
  • notification clock

See the underlying breach notice, if any.