Kingsmen Creatives Ltd.
ent_3dfa6997df7711e0d0fe7eaf
Disclosures
3
Singapore PDPC · Leak Site · 2 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
—
no filed count in sample
Leak-site claims
2
unverified actor claims
Identity resolution
- Canonical name
- Kingsmen Creatives Ltd.
- Normalized
- kingsmen creatives— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- kingsmen-int.com
Disclosure history (3)newest first
- SINGAPORESingapore PDPCas victim2026-05-07
Background On 29 April 2025, Kingsmen Creatives Ltd. (the “ Organisation ”) notified the Personal Data Protection Commission (the “ Commission ”) of a personal data breach involving a ransomware attack which affected multiple servers and a user’s laptop (the “ Incident ”). The Organisation established that the threat actor (“ TA ”) likely gained access to its system on 26 April 2025 using credentials from a compromised Virtual Private Network (“VPN”) account. Exploiting other system vulnerabilities, the TA encrypted the Organisation’s files containing the personal data of 445 individuals, who were the Organisation’s current (342 individuals) and former (103 individuals) employees. The types of personal data affected included names, NRIC numbers, NRIC copies, dates of birth, contact information (mobile numbers, email addresses and home addresses), bank account details (bank name and bank account number) and next-of-kin details (names, mobile numbers and relationship to the employee). Upon discovery of the Incident, the Organisation took prompt remedial actions including isolating affected network systems, blocking all incoming traffic from the firewall while allowing only outbound connectivity on weekdays, resetting all account passwords and retaining only a single administrative account on the Domain Controller. The Organisation also notified the affected individuals. The Incident had likely occurred as the Organisation had inadequate security measures prior to the Incident including a weak password policy, absence of regular access reviews, absence of a documented incident response plan and no implementation of multi -factor authentication (“MFA”) for VPN and privileged accounts. Voluntary Undertaking Having considered the circumstances of the case, the Commission accepted a voluntary undertaking (the “ Undertaking ”) from the Organisation to improve its compliance w
- GLOBALLeak Siteas victim2025-05-02
Kingsmen Creatives designs roll-out retail environments based off their clients' needs and conceptualize events for their clients. Established in 1976 and headquartered in Singapore, the Group has a network of 21 offices and full service facilities serving global clients today. -
- GLOBALLeak Siteas victim2025-04-30
Kingsmen Creatives designs roll-out retail environments based off their clients' needs and conceptualize events for their clients. Established in 1976 and headquartered in Singapore, the Group has a network of 21 offices and full service facilities serving global clients today. -