Shangri-La Hotel Ltd
bd_e9147158731db788 · schema v1 · pii pii-v1
Full breach record for Shangri-La Hotel Ltd →Regulator's decision — not a breach notification
This record is a regulator's decision, not the organisation's own breach notice. Breach-notification fields (discovery date, notification clock) are structurally absent — what this source establishes is the outcome and the provisions the decision cites.
Background On 16 July 2022, the Personal Data Protection Commission (the “ Commission ”) received a data breach notification from Shangri-La Hotel Limited (the “ Organisation ”) informing that unknown threat actor(s) had accessed and likely exfiltrated personal data from the Organisation’s property management system on or around 27 June 2022 (the “ Incident ”). The Organisation is a Singapore-incorporated subsidiary of the Shangri-La Group, which is headquartered in Hong Kong. The Shangri-La Group operates through a consolidated IT infrastructure located overseas. The personal data of approximately 1,076,899 guests was affected in the Incident. The affected datasets included guests’ names, phone numbers, email addresses, addresses, countries of residence, and/or membership information. Sensitive information such as guests’ identity document details and credit card details were encrypted by the Organisation and there was no evidence that these were affected. As the threat actor(s) alleged that they had also exfiltrated data from a number of other Shangri-La entities, the Shangri-La Group notified the relevant authorities as required, including the Office of the Privacy Commissioner for Personal Data in Hong Kong, China where the Shangri-La Group is headquartered. Investigations The Organisation engaged two third party forensic experts to investigate the Incident. Investigations revealed evidence of the threat actor’s activity in the Shangri-La Group’s network in Hong Kong as early as 26 November 2019. However, given the unavailability of forensic evidence before 26 November 2019, and steps taken by the sophisticated threat actor(s) to avoid detection, both forensic experts could not establish how the threat actor initially gained access to the Shangri-la Group’s network in Hong Kong. By 1 November 2021, the threat actor(s) compromised an account with domain level admin
P pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Sep 25, 2024
Filed
—
No linked breach filing · watching
Compliance clocks stay unassessable until a breach filing is linked. This record is the regulator's action, not a breach notice. Dashed segments fill in automatically when corroboration arrives.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- outcome + obligations
- fine (SGD) and affected count where a grounds document states them
- discovery date
- notification clock
See the underlying breach notice, if any.