SINGAPORESingapore PDPCas victim2024-05-23 Background Protemps Employment Services Pte Ltd (the “ Organisation ”) lodged a data breach notification with the Personal Data Protection Commission (the “ Commission ”) on 18 October 2021 after it found out that personal data of individuals in the possession or control of the Organisation was available on the dark web (the “ Incident ”). Investigations revealed that the Organisation’s website had suffered a ransomware attack on 4 October 2021. The Organisation’s own investigations revealed that its website contained vulnerabilities, which allowed the threat actor(s) to access the website infrastructure and exfiltrate the personal data of the affected individuals. As a result of the Incident, the personal data of approximately 19,361 individuals, including their names, residential addresses, NRIC images, nationality, date of birth, phone numbers, email addresses and passport number, was exfiltrated by the threat actor(s). The breakdown of each type of personal data affected is as follows: Personal data affected No. of Individuals affected Name 19,361 Residential Address 3,608 Nationality 4,092 Contact number 987 Email address 19,360 Birthday 3,299 Passort number 3,898 Race 3,383 Religion 2,528 Highest qualification 3,261 Last Salary 3,258 CVs 2541 2499 of these CVs contained NRIC numbers and 400 contained the NRIC images The Commission found the Organisation to be wanting in its cybersecurity and data protection practices. First, the Organisation did not carry out any periodic security reviews with vulnerability scans to test its website vulnerability prior to the Incident. Second, there were deficiencies in vendor management for security maintenance, as data protection and job specifications were not clearly defined. Finally, the Organisation lacked proper documentation for password policies, patch management policies or change management policies. Remedial Actions