DisclosureLens
SINGAPOREUnknownLow

Poh Heng Jewellery Pte Ltd

bd_e09a18eb6ea60139 · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Mar 27, 2025

To disclose

Affected

Not disclosed

Confidence

90%
Full breach record for Poh Heng Jewellery Pte Ltd

Regulator's decision — not a breach notification

This record is a regulator's decision, not the organisation's own breach notice. Breach-notification fields (discovery date, notification clock) are structurally absent — what this source establishes is the outcome and the provisions the decision cites.

Background On 29 March 2024, Poh Heng Jewellery (Private) Limited (the “ Organisation ”) notified the Personal Data Protection Commission (the “ Commission ”) of a personal data breach involving a cyber incident where a threat actor (“ TA ”) had obtained the source code for its e-commerce website (the “ Affected Website ”) through exploiting vulnerabilities (the “ Incident ”). Investigations revealed that that the TA had likely probed the Affected Website requesting for “/git.” web resources and found an exposed link to a configuration folder containing the website deployment file. This information allowed the TA to find the integrated GitHub repository of the Organisation’s then-Website vendor, A&C Atelier Pte Ltd (“ A&C ”) and obtain the Affected Website’s source code. The source code contained hardcoded API keys and integration credentials which the TA had exploited to access a HubSpot Middleware application that was integrated to the Affected Website at the time. Subsequently, the TA downloaded the personal data of 81,465 customers. The types of personal data affected included the name, contact number, residential address, personal email address, date of birth, country of residence, membership ID number and transactional information of up to the last five purchase transactions. Facts of the Case The setup of the Affected Website included the affected GitHub repository, used by A&C to contain the source code for developing the Affected Website, and the Hubspot Middleware application previously serviced by another vendor, Onyx Island Pte Ltd (“ Onyx ”). The Hubspot Middleware application was set up by Onyx to transfer a customer’s data from the Affected Website to the Hubspot CRM software-as-a-service (“ SaaS ”) platform and also to delete the customer’s data from the Affected Website after the transfer was complete. A&C and Onyx were previously engaged by the Organ

Incident timeline — partial

? — ?

Breach window unknown

Mar 27, 2025

Filed

No linked breach filing · watching

Compliance clocks stay unassessable until a breach filing is linked. This record is the regulator's action, not a breach notice. Dashed segments fill in automatically when corroboration arrives.

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

Source ceiling

  • outcome + obligations
  • fine (SGD) and affected count where a grounds document states them
  • discovery date
  • notification clock

See the underlying breach notice, if any.