SINGAPORESingapore PDPCas victim2024-09-25 Background On 16 July 2022, the Personal Data Protection Commission (the “ Commission ”) received a data breach notification from Shangri-La Hotel Limited (the “ Organisation ”) informing that unknown threat actor(s) had accessed and likely exfiltrated personal data from the Organisation’s property management system on or around 27 June 2022 (the “ Incident ”). The Organisation is a Singapore-incorporated subsidiary of the Shangri-La Group, which is headquartered in Hong Kong. The Shangri-La Group operates through a consolidated IT infrastructure located overseas. The personal data of approximately 1,076,899 guests was affected in the Incident. The affected datasets included guests’ names, phone numbers, email addresses, addresses, countries of residence, and/or membership information. Sensitive information such as guests’ identity document details and credit card details were encrypted by the Organisation and there was no evidence that these were affected. As the threat actor(s) alleged that they had also exfiltrated data from a number of other Shangri-La entities, the Shangri-La Group notified the relevant authorities as required, including the Office of the Privacy Commissioner for Personal Data in Hong Kong, China where the Shangri-La Group is headquartered. Investigations The Organisation engaged two third party forensic experts to investigate the Incident. Investigations revealed evidence of the threat actor’s activity in the Shangri-La Group’s network in Hong Kong as early as 26 November 2019. However, given the unavailability of forensic evidence before 26 November 2019, and steps taken by the sophisticated threat actor(s) to avoid detection, both forensic experts could not establish how the threat actor initially gained access to the Shangri-la Group’s network in Hong Kong. By 1 November 2021, the threat actor(s) compromised an account with domain level admin