Jet Aviation (Asia Pacific) Pte. Ltd.
ent_8bc20cabc89927de1acf1237
Disclosures
2
Singapore PDPC · State AG · 2 jurisdictions
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
3
as filed · State AG NH
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Jet Aviation (Asia Pacific) Pte. Ltd.
- Normalized
- jet aviation asia pacific pte— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
- Corporate parent
- General Dynamics— per SEC Exhibit 21 filing
Disclosure history (2)newest first
- SINGAPORESingapore PDPCas victim2025-02-27
Background Jet Aviation (Asia Pacific) Pte Ltd (the “ Organisation ”) operates private jet charters for individuals and provides aircraft Maintenance, Repair and Overhaul (“ MRO ”) services. On 26 July 2024, the Organisation notified the Personal Data Protection Commission (the “ Commission ”) of unauthorised access to 5 of the Organisation’s email accounts containing personal data (the “ Incident ”). I nvestigations revealed that that the threat actor (“ TA ”) had likely gained access to the email accounts via spear phishing emails sent to specific employees. The TA had engineered the phishing emails to appear as legitimate requests for e-signatures from either trusted business partners or from within the Organisation. The TA used a cloud-based e-signature service, Adobe Acrobat Sign, to send documents containing a phishing link to the targeted employees. As the phishing link was contained within the document, the emails bypassed the Organisation’s security scans for malicious email content. The targeted employees were convinced on the authenticity of the emails as the emails also bore a legitimate sender email address from Adobe. After clicking on the link, the employees were directed to a phishing website which emulated the Microsoft Office logon page and displayed genuine email addresses associated with the Organisation. Believing that the website that they had been directed to was authentic, the targeted employees entered their Microsoft credentials and the necessary passwords and multi-factor authentication (“ MFA ”) tokens. The phishing website then employed a reverse proxy to relay this information to the genuine Microsoft website and intercepted the primary refresh tokens returned by the Microsoft website. With the intercepted tokens, the TA was able to bypass existing MFA and gain persistent access to the email accounts. The 5 affected email accounts contain
- New Hampshire State AGas victim2024-10-18
Jet Aviation (Asia Pacific) Pte. Ltd. experienced a business email compromise (BEC) incident where a threat actor gained unauthorized access to five email accounts to divert invoice payments. The company became aware of the incident on September 13, 2023. Although the primary motive was financial fraud, personal information of three New Hampshire residents may have been accessed. The company reset credentials, blocked malicious domains, and is offering credit monitoring.