DisclosureLens
SINGAPOREUnknownMedium

Low Keng Huat (Singapore) Limited

bd_e0954c2be217bcb7 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Filed

Mar 22, 2024

To disclose

Affected

1,400

Linked

2 filings

Confidence

90%
Full breach record for Low Keng Huat (Singapore) Limited

Regulator's decision — not a breach notification

This record is a regulator's decision, not the organisation's own breach notice. Breach-notification fields (discovery date, notification clock) are structurally absent — what this source establishes is the outcome and the provisions the decision cites.

Background The Personal Data Protection Commission (the “ Commission ”) was notified by Low Keng Huat (Singapore) Limited (“ LKHS ”) on 4 July 2023 of a personal data breach involving the unauthorised access and exfiltration of personal data . Investigations revealed that a malicious actor had gained initial access to LKHS's IT environment remotely. The firewall was not configured and therefore unable to block malicious traffic. The vendor was responsible for managing the firewall system, and no testing was conducted before the system went live after an upgrade. As a result, server logs were missing during that period, and security threat protection was not enabled in the system. The malicious actor likely exploited a critical vulnerability to obtain LKHS's workstation credentials and compromise email accounts. The malicious actor successfully deployed ransomware, encrypting and/or exfiltrating the personal data of 1,400 individuals (the “ Incident ”). The personal data affected included their personal contact information, emails, IC and passport scans, date of birth, sale and purchase agreements, and option to purchase documents. LKHS has been conducting monitoring and has not found any evidence to suggest that the personal data affected in the incident has been misused. Remedial Actions After the Incident, as part of a remediation plan, LKHS put in place the following measures: (a) Patched all software and outdated firmware. (b) Updated and completed all IT hardware and software asset lists. (c) Implemented clear vendor management and account responsibilities processes. (d) Reviewed and resolved firewall issues and eliminated the need for VPN. (e) Implemented strong security settings for servers and updated all workstations with endpoint protection. (f) Implemented 2FA and more stringent password policies. (g) All LKHS’s accounts have undergone a successful security

Incident timeline — partial

? — ?

Breach window unknown

Mar 22, 2024

Filed

Corroborated · see linked filings

Compliance clocks stay unassessable until a breach filing is linked. This record is the regulator's action, not a breach notice. Dashed segments fill in automatically when corroboration arrives.

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Ransomware claims (1)

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

Source ceiling

  • outcome + obligations
  • fine (SGD) and affected count where a grounds document states them
  • discovery date
  • notification clock

See the underlying breach notice, if any.