Poh Heng Jewellery Pte Ltd
bd_e09a18eb6ea60139 · schema v1 · pii pii-v1
Full breach record for Poh Heng Jewellery Pte Ltd →Regulator's decision — not a breach notification
This record is a regulator's decision, not the organisation's own breach notice. Breach-notification fields (discovery date, notification clock) are structurally absent — what this source establishes is the outcome and the provisions the decision cites.
Background On 29 March 2024, Poh Heng Jewellery (Private) Limited (the “ Organisation ”) notified the Personal Data Protection Commission (the “ Commission ”) of a personal data breach involving a cyber incident where a threat actor (“ TA ”) had obtained the source code for its e-commerce website (the “ Affected Website ”) through exploiting vulnerabilities (the “ Incident ”). Investigations revealed that that the TA had likely probed the Affected Website requesting for “/git.” web resources and found an exposed link to a configuration folder containing the website deployment file. This information allowed the TA to find the integrated GitHub repository of the Organisation’s then-Website vendor, A&C Atelier Pte Ltd (“ A&C ”) and obtain the Affected Website’s source code. The source code contained hardcoded API keys and integration credentials which the TA had exploited to access a HubSpot Middleware application that was integrated to the Affected Website at the time. Subsequently, the TA downloaded the personal data of 81,465 customers. The types of personal data affected included the name, contact number, residential address, personal email address, date of birth, country of residence, membership ID number and transactional information of up to the last five purchase transactions. Facts of the Case The setup of the Affected Website included the affected GitHub repository, used by A&C to contain the source code for developing the Affected Website, and the Hubspot Middleware application previously serviced by another vendor, Onyx Island Pte Ltd (“ Onyx ”). The Hubspot Middleware application was set up by Onyx to transfer a customer’s data from the Affected Website to the Hubspot CRM software-as-a-service (“ SaaS ”) platform and also to delete the customer’s data from the Affected Website after the transfer was complete. A&C and Onyx were previously engaged by the Organ
P pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Mar 27, 2025
Filed
—
No linked breach filing · watching
Compliance clocks stay unassessable until a breach filing is linked. This record is the regulator's action, not a breach notice. Dashed segments fill in automatically when corroboration arrives.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- outcome + obligations
- fine (SGD) and affected count where a grounds document states them
- discovery date
- notification clock
See the underlying breach notice, if any.