SINGAPORESingapore PDPCas victim2026-09-21 Background Grace Orchard School (the “Organisation”), a special education school operating under Presbyterian Community Social Services Ltd., notified the Personal Data Protection Commission (the “Commission”) on 12 November 2025 of a personal data breach involving its servers (the “Incident”). It was established that the threat actor (“TA”) gained administrator-level access to the Organisation’s perimeter firewall on or around 4 September 2025 by exploiting a critical firmware vulnerability. The TA then created new administrator accounts and moved laterally into the internal network, harvesting password hashes and accessed a file server and files containing personal data. The Incident affected 1,011 individuals comprising current and former students including minors, and current and former staff of the Organisation. Personal data affected included names and full NRIC numbers for students. For the staff, the affected personal data extended beyond names and full NRIC numbers to addresses, personal email addresses, telephone numbers, photographs, dates of birth, financial information (such as bank account details), insurance information (such as insurer names and claim amounts), and health information (such as discharge summaries). There was no evidence of exfiltration of the personal data. Upon discovery of the Incident, the Organisation took prompt remedial actions including resetting all administrator and domain administrator passwords on the affected servers, disconnecting affected servers and conducting full virus scans, hardening the firewall configuration, removing all rogue administrator accounts not created by the Organisation and engaging the firewall vendor to verify the integrity of the firewall's operating system. The Organisation also later notified all affected individuals of the Incident. 5. The Incident likely resulted from a combination of security gap