Home Technology Security 70,000 people affected in SLA data breach

70,000 people affected in SLA data breach

The Singapore Land Authority (SLA) has been hit with a data breach through an IBM-managed cloud environment, affecting about 70,000 people, the agency announced July 3.

SLA said the stolen data set, created in 1998 and updated periodically over the years, was for the sole purpose of vendor development and testing. It was intended to contain only mock and anonymised testing data based on property ownership and lodgment records.

However, SLA has uncovered that it also contained the names, NRIC numbers, and then property addresses of an estimated 70,000 individuals.

“This information should have been anonymised but was not. Investigations are ongoing to determine how this occurred,” it said.

As the vendor appointed to support and maintain SLA’s Singapore Titles Automated Registration System and eLodgment System, IBM managed the development and systems-integration testing environment for STARS and ELS.

“The affected environment managed by the vendor is distinct and separate from SLA’s operational systems. There is no connection or compromise to the live systems used for operations of STARS, ELS or any other SLA systems. Property ownership and lodgment records in STARS and ELS remain secure and unaffected,” SLA assured.

The agency said IBM has revoked access associated with the affected development and testing environment to prevent any other unauthorised access.

SLA has identified the individuals whose information were compromised and has begun notifying them on how they can seek further information and assistance.

“SLA is working closely with IBM, the Government Technology Agency of Singapore and the Cyber Security Agency of Singapore to investigate the incident, establish the full facts and ensure that the necessary remedial measures are taken. SLA has also lodged a police report and notified the Personal Data Protection Commission,” the agency noted.

- Advertisement -