DisclosureLens
SINGAPOREUnknownLow

McJim Marketing Pte Ltd

bd_f94370493fd3f8df · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Jul 4, 2024

To disclose

Affected

Not disclosed

Confidence

90%
Full breach record for McJim Marketing Pte Ltd

Regulator's decision — not a breach notification

This record is a regulator's decision, not the organisation's own breach notice. Breach-notification fields (discovery date, notification clock) are structurally absent — what this source establishes is the outcome and the provisions the decision cites.

Background On 26 May 2023, the Personal Data Protection Commission (the “ Commission ”) received a data breach notification from McJim Marketing Pte. Ltd. (the “ Organisation ”) regarding a ransomware attack on their network-attached storage device on or about 19 May 2023, causing 500GB of files to be encrypted and inaccessible (the “Incident”) . Personal data of 100 individuals were likely affected by the Incident. Based on the connection logs of the affected network-attached storage (“ NAS ”) of the Organisation, there were suspicious login attempts between 17 May 2023 and 19 May 2023 suggesting that a brute force attack had occurred. Investigation found that the threat actor likely gained initial entry to the NAS on 19 May 2023 prior to performing encryption of the Organisation’s files. As a result of the Incident, the personal data of approximately 100 former and current employees and their next-of-kin, including their names, address, NRIC numbers, date of birth, phone numbers, passport numbers and financial information (including bank account numbers) were likely affected. The Organisation was found to be lacklustre in its cybersecurity and data protection practices, including using a default password for the affected NAS and for failing to carry out any periodic security reviews of its network and failing to appoint a Data Protection Officer. In addition, there was no proper documentation for personal data protection policies and procedures and password policies. Remedial Actions After the incident, the Organisation implemented the following: (a) Engaged a third-party IT vendor to install a new server and router with antivirus software, firewall and auto-backup function; (b) Implemented a strong password with restricted access to the new server to selected management staff; and (c) Reviewed company’s policy to mandate that personal data information should not be

Incident timeline — partial

? — ?

Breach window unknown

Jul 4, 2024

Filed

No linked breach filing · watching

Compliance clocks stay unassessable until a breach filing is linked. This record is the regulator's action, not a breach notice. Dashed segments fill in automatically when corroboration arrives.

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

Source ceiling

  • outcome + obligations
  • fine (SGD) and affected count where a grounds document states them
  • discovery date
  • notification clock

See the underlying breach notice, if any.