Particle.news
Download on the App Store

SLA Vendor Cloud Held Personal Data of About 70,000 People

Police, the data regulator and national cyber agencies are investigating how a legacy 1998 testing dataset came to include real identity and address records.

Overview

  • SLA said on Friday that preliminary checks found unauthorised access to an IBM‑managed development and testing cloud that contained a dataset created in 1998 which was supposed to be anonymised.
  • The authority found the dataset held real names, NRIC numbers and past property addresses for about 70,000 people rather than only mock data used for vendor testing.
  • IBM has revoked access to the affected testing environment and SLA says its live land‑registration systems, including STARS and ELS, were not compromised.
  • SLA has begun notifying identified individuals, has lodged a police report, has informed the Personal Data Protection Commission, and has asked GovTech and the Cyber Security Agency to help investigate and remediate.
  • The incident raises questions about long‑running vendor data governance for test systems and could increase phishing or identity‑fraud risk for those affected, so the public is urged to remain vigilant.