Personal info of 70,000 people compromised in data breach involving SLA’s vendor IBM
Sign up now: Get ST's newsletters delivered to your inbox
Preliminary investigations indicate that there was unauthorised access to a data set created for the sole purpose of vendor development and testing.
PHOTO: ST FILE
SINGAPORE – The personal details of around 70,000 people in Singapore, including NRIC numbers and addresses, have been compromised following a data breach involving the Singapore Land Authority’s (SLA) vendor, IBM.
On July 3, SLA said it was informed about the data security incident by IBM, which it had appointed to support and maintain the Singapore Titles Automated Registration System (STARS) and eLodgment System (ELS).
IBM also managed the development and systems-integration testing environment for STARS and ELS.
In response to queries from The Straits Times, SLA said that the vendor had informed the government agency of a security incident on June 12, and possible unauthorised access of personal information on June 15.
Preliminary investigations found that there was unauthorised access to a data set created for vendor development and testing, SLA said.
The data set, which was created in 1998 and updated periodically over the years, was intended to contain only mock and anonymised testing data based on property ownership and lodgment records, SLA said.
However, the authority said it has since uncovered that the data set also contained the names, NRIC numbers, and property addresses of about 70,000 individuals.
“This information should have been anonymised but was not. Investigations are ongoing to determine how this occurred,” it added.
SLA added that the data had been encrypted, but did not explain how the malicious actor obtained the personal data. Investigations are ongoing.
As a precautionary measure, SLA has identified the individuals whose information was contained in the affected data set. It has started notifying them and advising them on how they can seek further information and assistance.
“As the data set was created in 1998, the majority of the addresses are not the current place of residence of the affected individuals,” said the authority.
SLA said the affected environment managed by IBM is distinct and separate from its operational systems. The live systems used to operate STARS, ELS or any other SLA systems have not been compromised, it added.
Property ownership and lodgment records in STARS and ELS also remain secure and unaffected.
IBM has revoked access associated with the affected development and testing environment to prevent any other unauthorised access.
“SLA is working closely with IBM, the Government Technology Agency of Singapore (GovTech) and the Cyber Security Agency of Singapore to investigate the incident, establish the full facts and ensure that the necessary remedial measures are taken,” the authority said.
It has also lodged a police report and notified the Personal Data Protection Commission.
In its statement, SLA advised the public to remain vigilant against phishing e-mails, phishing websites, text messages or telephone calls from parties claiming to represent government agencies or other organisations.
GovTech said that there is no evidence to suggest that other government systems or datasets have been similarly affected by this incident. “We apologise for the concern and inconvenience this incident may cause,” the SLA said.
It is not clear whether SLA or IBM is responsible for the dataset.
Private sector organisations are governed under the Personal Data Protection Act, which requires them to put in place reasonable security mechanisms to prevent unauthorised access to data.
Government agencies and public officers come under the Public Sector Governance Act, which holds individuals accountable for unauthorised disclosure, misuse and unauthorised re-identification of anonymised information, among others.
GovTech and CSA said that they were unable to provide more details as investigations are still ongoing.

