Overview
- SLA said on Friday that preliminary checks found unauthorised access to an IBM‑managed development and testing cloud that contained a dataset created in 1998 which was supposed to be anonymised.
- The authority found the dataset held real names, NRIC numbers and past property addresses for about 70,000 people rather than only mock data used for vendor testing.
- IBM has revoked access to the affected testing environment and SLA says its live land‑registration systems, including STARS and ELS, were not compromised.
- SLA has begun notifying identified individuals, has lodged a police report, has informed the Personal Data Protection Commission, and has asked GovTech and the Cyber Security Agency to help investigate and remediate.
- The incident raises questions about long‑running vendor data governance for test systems and could increase phishing or identity‑fraud risk for those affected, so the public is urged to remain vigilant.