Commonwealth Capital Pte Ltd
ent_c22449db2d45c400a0d4c7a6
Disclosures
2
Singapore PDPC · Leak Site · 2 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
—
no filed count in sample
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- Commonwealth Capital Pte Ltd
- Normalized
- commonwealth capital pte— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- commonwealthcapital.com.sg
Disclosure history (2)newest first
- SINGAPORESingapore PDPCas victim2024-08-02
Background Commonwealth Capital Pte. Ltd. (the “ Organisation ”) notified the Personal Data Protection Commission (the “ Commission ”) on 4 January 2024 of a personal data breach involving the unauthorised exfiltration of personal data (the “ Incident ”). Investigation revealed that a threat actor had gained unauthorised access to the Organisation’s servers through Remote Desktop Protocol (“ RDP ”) brute force of two local administrator accounts. The local administrator accounts were created by the Organisation to allow its vendor to assist in the migration of the Organisation’s on-premise servers to cloud servers. A malicious actor exfiltrated the personal data of 2,951 individuals who were the Organisation’s and its related companies’ former and current employees, tenants and contractors. For 1,675 individuals, the personal data affected is limited to their name, NRIC/FIN /passport number, address, telephone number, email address, photo, and date of birth/age. For the remaining 1,276 individuals, the affected personal data included their salary and/or bank account details. Upon discovering the Incident, the Organisation took prompt remedial actions including engaging a vendor to investigate, implement containment and recovery measures, and improved its existing security measures. Voluntary Undertaking H aving considered the circumstances of the case, the Commission accepted a voluntary undertaking (the “ Undertaking ”) from the Organisation to improve its compliance with the Personal Data Protection Act 2012 (the “ PDPA ”). The Undertaking was executed on 17 April 2024. As part of the Undertaking, the Organisation will be implementing the following: (a) Measures to detect and alert the Organisation on unusually large volume of outgoing traffic; (b) A backup solution for key data stores and servers that is safe from ransomware deployments; (c) Network segmentation an
- GLOBALLeak Siteas victim2023-12-14
Commonwealth Capital Pte Ltd (CCPL) is a Singapore-based investment company with a F&B portfolio from end-to-end manufacturing, logistics to retail services.