SINGAPORESingapore PDPCas victim2026-06-05 Background Olam Group Limited (the “ Organisation ”) notified the Personal Data Protection Commission (the “ Commission ”) on 4 December 2024 of a ransomware incident involving its servers (the “ Incident ”). The Organisation established that the threat actor (“ TA ”) had successfully connected to the VPN located in one of its overseas entities using valid credentials from a user account. By leveraging the user account, the TA gained the privileges of user accounts which enabled lateral movement across the Organisation’s network and data exfiltration from the Organisation’s servers. The Incident affected 42,351 individuals (largely involving the Organisation’s former, existing and potential employees) and the types of personal data affected varied by individuals, including a combination of names, addresses, personal email addresses, telephone numbers, dates of birth, photographs, national identification numbers, health information, financial information, life/health insurance information, demographic information, and professional and educational information. Upon discovery of the Incident, the Organisation took prompt remedial actions including disabling the specific VPN service to which the initial access was traced to, resetting the passwords, blocking outbound and inbound internet access to servers by the TA, and implemented dark web monitoring. The Organisation also notified the relevant affected individuals. The Incident had likely occurred due to delay in the renewal process of the VPN license in one of many jurisdictions where the Organisation operates, which enabled the validation of domain membership. The Organisation also did not have proper Multi-factor Authentication (“ MFA ”) processes as the second check of authentication had been configured but was not enforced due to the license expiry as noted. The Organisation also had weak password policies in place