logo
Credit reports among personal data of 190,000 breached, put for sale on Dark Web; IT vendor fined

Credit reports among personal data of 190,000 breached, put for sale on Dark Web; IT vendor fined

Straits Times15 hours ago
Sign up now: Get ST's newsletters delivered to your inbox
IT vendor Ezynetic was fined $17,500 for failing to protect its clients' data.
SINGAPORE - IT vendor Ezynetic has been fined $17,500 for failing to protect its clients' data, which resulted in more than 190,000 individuals' personal data being stolen and put for sale on the Dark Web.
Ezynetic had failed to put in place reasonable security arrangements to protect the personal data in its possession or under its control, the Personal Data Protection Commission (PDPC) said on July 3 via a statement on its website.
At the time of the breach, which Ezynetic uncovered on June 24, 2024, the company was operating an IT system linked to the Moneylenders Credit Bureau platform operated by Credit Bureau Singapore.
Enzynetic's affected clients –
previously identified as moneylenders Ban King Credit, Credit 21, Lending Bee, Katong Credit, Credit Thirty3, GS Credit, 1AP Capital, Creditmaster, BST Credit, U Credit, Horison Credit and Credit Matters – would input personal data of their prospective loan applicants and borrowers into the money lending system.
This would allow them to verify the applicants' and borrowers' loan eligibility, generate MLCB credit reports and profit and loss reports, as well as track loans, instalments, collections and payments.
In a judgment, the PDPC said that investigations found that a threat actor had exploited a vulnerable web service application to gain access and control of Ezynetic's system administrator account to access the money lending system. After gaining access to the money lending system, the threat actor obtained the personal data of the affected individuals.
The data stolen included a combination of the name, address, e-mail address, telephone number, NRIC number, date of birth and the financial information available in the MLCB credit reports of 190,589 individuals. These individuals were notified of the incident on July 1, 2024.
Top stories
Swipe. Select. Stay informed.
Singapore Asean needs 'bolder reforms' to attract investments in more fragmented global economy: PM Wong
Singapore CPF members can make housing, retirement and health insurance plans with new digital platform
Singapore CPF's central philosophy of self-reliance remains as pertinent as ever: SM Lee
Asia Dalai Lama hopes to live beyond 130 years, much longer than predicted
Sport Liverpool will move on after Jota's tragic death, but he will never be forgotten
Singapore Tan Cheng Bock, Hazel Poa step down from PSP leadership; party launches 'renewal plan'
Singapore Rock climbing fan suddenly could not jump, get up from squats
Life Japanese food in Singapore under $20: 5 hawker stalls serving restaurant-quality sashimi and donburi
PDPC, which was informed of the incident on June 26, 2024, said its investigations revealed that Ezynetic had failed to disable or adequately secure the system administrator account, which is often targeted by malicious users.
The account password at the time of the incident, which was p@ssword1 or Password@1, was susceptible to brute force attacks, wherein hackers repeatedly try to gain access to systems by trying different passwords.
Ezynetic was also found not to have performed any periodic vulnerability assessment or penetration testing of its infrastructure, said the commission.
Following the incident, Ezynetic rebuilt its entire network and migrated to a cloud environment for its servers, and implemented enhanced security measures for the new network after consultations with the Cyber Security Agency of Singapore and the Ministry of Law.
PDPC's decision
Under the Personal Data Protection Act (PDPA), which Ezynetic was found to have breached, organisations must protect personal data in its possession or under its control by making reasonable security arrangements to prevent unauthorised access, collection, use, disclosure, copying, modification or disposal, or similar risks.
Its failure to conduct a reasonable periodic security review also amounted to a breach of the PDPA; according to PDPC's checklists to guard against common types of data breaches, organisations should, as a basic practice, periodically conduct web application vulnerability scanning and assessments.
PDPC said that a fine was appropriate, as Ezynetic was a Software-as-a-Service provider, which should possess the necessary technical expertise to implement reasonable cyber security measures to address the evolving threats.
According to Microsoft's cloud computing platform Azure, Software-as-a-Service, or SaaS for short, is a cloud-based model where software applications are hosted by a service provider and accessed over the internet. SaaS providers manage the underlying infrastructure, security, maintenance, and updates.
Ezynetic was also directed by the PDPC to obtain Cyber Security Agency of Singapore's Cyber Trustmark Certification for its new IT network and report to the Commission on its completion. Such marks certify
good cyber-security practices , helping companies benchmark and show their preparedness to meet new risks,
On Dec 2, Ezynetic was informed of PDPC's preliminary decision, and the following day, it sought a waiver or reduction to the fine. The firm cited its financial commitment to mitigating the breach, its losses as a result of ongoing disruptions caused by the breach, and that it had cooperated with all regulatory bodies throughout the investigation.
However, PDPC rejected this, as Ezynetic's financial commitment was a 'necessary part of its obligation to implement reasonable security arrangement' under its protection obligation, and that Ezynetic's cooperativeness was already taken into account while determining the fine amount.
'Whilst (Ezynetic) did provide some invoices showing that it had incurred expenses to implement remedial measures, these did not show that (Ezynetic) is in such a dire financial situation that the imposition of a financial penalty of $17,500 would adversely impact its ability to continue its business,' said PDPC.
As a result, the PDPC said Ezynetic was required to pay the fine within 30 days of from the date of the relevant notice accompanying its decision. If it does not do so, interest will be accrued until the fine is paid in full.
The firm will also be required to obtain Cyber Trustmark Certification for its new IT network within 9 months from the date of PDPC's decision, and has to report to the commission within 14 days of doing so.
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

IT vendor fined over data stolen from 190,000, sold on Dark Web
IT vendor fined over data stolen from 190,000, sold on Dark Web

New Paper

time4 hours ago

  • New Paper

IT vendor fined over data stolen from 190,000, sold on Dark Web

IT vendor Ezynetic has been fined $17,500 for failing to protect its clients' data, which resulted in more than 190,000 individuals' personal data being stolen and put for sale on the Dark Web. Ezynetic had failed to put in place reasonable security arrangements to protect the personal data in its possession or under its control, the Personal Data Protection Commission (PDPC) said on July 3 via a statement on its website. At the time of the breach, which Ezynetic uncovered on June 24, 2024, the company was operating an IT system linked to the Moneylenders Credit Bureau platform operated by Credit Bureau Singapore. Enzynetic's affected clients - previously identified as moneylenders Ban King Credit, Credit 21, Lending Bee, Katong Credit, Credit Thirty3, GS Credit, 1AP Capital, Creditmaster, BST Credit, U Credit, Horison Credit and Credit Matters - would input personal data of their prospective loan applicants and borrowers into the money lending system. This would allow them to verify the applicants' and borrowers' loan eligibility, generate MLCB credit reports and profit and loss reports, as well as track loans, instalments, collections and payments. In a judgment, the PDPC said that investigations found that a threat actor had exploited a vulnerable web service application to gain access and control of Ezynetic's system administrator account to access the money lending system. After gaining access to the money lending system, the threat actor obtained the personal data of the affected individuals. The data stolen included a combination of the name, address, e-mail address, telephone number, NRIC number, date of birth and the financial information available in the MLCB credit reports of 190,589 individuals. These individuals were notified of the incident on July 1, 2024. PDPC, which was informed of the incident on June 26, 2024, said its investigations revealed that Ezynetic had failed to disable or adequately secure the system administrator account, which is often targeted by malicious users. The account password at the time of the incident, which was p@ssword1 or Password@1, was susceptible to brute force attacks, wherein hackers repeatedly try to gain access to systems by trying different passwords. Ezynetic was also found not to have performed any periodic vulnerability assessment or penetration testing of its infrastructure, said the commission. Following the incident, Ezynetic rebuilt its entire network and migrated to a cloud environment for its servers, and implemented enhanced security measures for the new network after consultations with the Cyber Security Agency of Singapore and the Ministry of Law. PDPC's decision Under the Personal Data Protection Act (PDPA), which Ezynetic was found to have breached, organisations must protect personal data in its possession or under its control by making reasonable security arrangements to prevent unauthorised access, collection, use, disclosure, copying, modification or disposal, or similar risks. Its failure to conduct a reasonable periodic security review also amounted to a breach of the PDPA; according to PDPC's checklists to guard against common types of data breaches, organisations should, as a basic practice, periodically conduct web application vulnerability scanning and assessments. PDPC said that a fine was appropriate, as Ezynetic was a Software-as-a-Service provider, which should possess the necessary technical expertise to implement reasonable cyber security measures to address the evolving threats. According to Microsoft's cloud computing platform Azure, Software-as-a-Service, or SaaS for short, is a cloud-based model where software applications are hosted by a service provider and accessed over the internet. SaaS providers manage the underlying infrastructure, security, maintenance, and updates. Ezynetic was also directed by the PDPC to obtain Cyber Security Agency of Singapore's Cyber Trustmark Certification for its new IT network and report to the Commission on its completion. Such marks certify good cyber-security practices, helping companies benchmark and show their preparedness to meet new risks, On Dec 2, Ezynetic was informed of PDPC's preliminary decision, and the following day, it sought a waiver or reduction to the fine. The firm cited its financial commitment to mitigating the breach, its losses as a result of ongoing disruptions caused by the breach, and that it had cooperated with all regulatory bodies throughout the investigation. However, PDPC rejected this, as Ezynetic's financial commitment was a "necessary part of its obligation to implement reasonable security arrangement" under its protection obligation, and that Ezynetic's cooperativeness was already taken into account while determining the fine amount. "Whilst (Ezynetic) did provide some invoices showing that it had incurred expenses to implement remedial measures, these did not show that (Ezynetic) is in such a dire financial situation that the imposition of a financial penalty of $17,500 would adversely impact its ability to continue its business," said PDPC. As a result, the PDPC said Ezynetic was required to pay the fine within 30 days of from the date of the relevant notice accompanying its decision. If it does not do so, interest will be accrued until the fine is paid in full. The firm will also be required to obtain Cyber Trustmark Certification for its new IT network within 9 months from the date of PDPC's decision, and has to report to the commission within 14 days of doing so.

Early start to heritage studies for Bukit Timah Turf City housing site is paying off
Early start to heritage studies for Bukit Timah Turf City housing site is paying off

Straits Times

time8 hours ago

  • Straits Times

Early start to heritage studies for Bukit Timah Turf City housing site is paying off

Sign up now: Get ST's newsletters delivered to your inbox SINGAPORE – A study published in 2021 found a swimming pool complex in the Old Police Academy at Mount Pleasant to be among the most significant in terms of heritage value, second to only a Senior Police Officers' Mess. The heritage study – meant to guide the development of the 33ha Mount Pleasant housing estate – said the complex was where trainees learnt swimming and life-saving skills, and police officers and their families spent their leisure time. Despite the findings, demolition work began on the complex within the past year, close to five decades after it was completed in 1976. Six buildings in Mount Pleasant have been conserved in all – four will be repurposed within the upcoming housing estate, while the other two, including the Senior Police Officers' Mess, are just outside of it. In contrast, 22 buildings are slated for conservation within an upcoming residential estate at the old 176ha Bukit Timah Turf City, including two grandstands that a separate heritage study identified as the site's most exceptional buildings. The differing outcomes for the two sites' most significant buildings can be explained largely by the timing of the two studies vis-a-vis planning and building works for the future estates. When the Old Police Academy study started in 2018, six buildings and ancillary structures had already been demolished after the Land Transport Authority began work on Mount Pleasant MRT station within the academy's compound in early 2015. Top stories Swipe. Select. Stay informed. Singapore Asean needs 'bolder reforms' to attract investments in more fragmented global economy: PM Wong Singapore CPF members can make housing, retirement and health insurance plans with new digital platform Singapore CPF's central philosophy of self-reliance remains as pertinent as ever: SM Lee Singapore Credit reports among personal data of 190,000 breached, put for sale on Dark Web; IT vendor fined Asia Dalai Lama hopes to live beyond 130 years, much longer than predicted Singapore Tan Cheng Bock, Hazel Poa step down from PSP leadership; party launches 'renewal plan' Sport Liverpool will move on after Jota's tragic death, but he will never be forgotten Singapore Rock climbing fan suddenly could not jump, get up from squats The underground station's location – just next to the swimming pool complex – had been fixed since 2014, under the Urban Redevelopment Authority's (URA) masterplan. In comparison, heritage studies on the area near the two grandstands in Turf City were completed before the Government announced in September 2022 that a future MRT station will be located near the two stands . Work on the station site began only after Turf City closed in late 2023 , and the station's location was reflected for the first time in URA's plans on June 25, when the agency unveiled the Draft Master Plan 2025. The Turf City study was the first implemented under the Government's Heritage Impact Assessment (HIA) framework, which was announced in 2022 and for which the Old Police Academy study served as a pilot . The conservation of 22 buildings in the upcoming Turf City estate shows that the Government's move to start heritage studies sufficiently early in the planning process – and make decisions based on their findings – is paying off. Based on initial plans, future visitors to the North Grandstand – set to be part of a mixed-used development, along with the South Grandstand – could dine at the spectators' area, which overlooks a field and park. The south stand was completed in 1933, and the north stand in 1981. A former housing area for racecourse workers called Fairways Quarters, and the Bukit Timah Saddle Club Clubhouse, could be put to community use. An illustration of how the former Bukit Timah Saddle Club Clubhouse can be repurposed to form a new amenity node for future residents. PHOTO: URBAN REDEVELOPMENT AUTHORITY Under the HIA framework, large-scale public redevelopment projects impacting clusters of buildings and structures with potential heritage value are subject to studies by external consultants, who generally assess the heritage significance of a site, identify impacts that a proposed development project would have on it, and recommend strategies to mitigate the impact. The Turf City study was conducted by the National University of Singapore's (NUS) Department of Architecture and heritage consultant Purcell. Subsequently, more granular studies on 27 buildings and structures were done , before the decision to conserve 22 – a figure that pleasantly surprised heritage observers. Retaining this many buildings allows future residents of the estate to appreciate its history, and step into various spaces that the racecourse's visitors, senior leaders and workers once used. Founding chair of non-profit heritage group Docomomo Singapore Ho Weng Hin said the phased studies – from a broader study to more site-specific ones – meant that plans could be refined and adjusted. For instance, NUS professor Ho Puay Peng, who was involved in the HIA for Turf City, said minor tweaks were made to the design of the upcoming MRT station there so that the North Grandstand's facade would not be blocked. An artist's impression of Bukit Timah Turf City's North Grandstand in the future housing estate. PHOTO: URBAN REDEVELOPMENT AUTHORITY Deciding to keep the buildings is also just the start of a long process of ensuring that future users can meaningfully enjoy them. Planners and architects now have the task of making that happen. How will the greenery and openness of Fairways Quarters be preserved, with new high-rise housing blocks expected in the estate? Mr Ho of Docomomo Singapore suggested putting in place a conservation management plan to guide future developments in the sprawling estate and ensure the former racecourse's significance is retained. Another question is what planners and developers will decide to house within the two grandstands, which will be part of a neighbourhood that is envisioned as the estate's 'civic heart', with sports, recreational, commercial and community amenities. Building an integrated facility like Our Tampines Hub from scratch is relatively simple, but inserting new and varied uses into the purpose-built grandstands necessitates creativity. An artist's impression of how the former Fairways Quarters could be integrated in community node. PHOTO: URBAN REDEVELOPMENT AUTHORITY Conservation buildings should ultimately benefit the public, and URA's early plans are promising, with most of the 22 in sites that are likely to be publicly accessible. The agency has also said that it will commemorate and mark the original extent of Turf City's racetracks – an idea put forth by heritage groups. Considering the HIA framework's success in guiding the redevelopment of Bukit Timah Turf City thus far, the authorities should apply it to other large sites set for a makeover, such as Sembawang Shipyard and Paya Lebar Air Base. On this front, the Draft Master Plan 2025 exhibition shows that URA's planners already have one eye on the future. There are plans to integrate Paya Lebar's old airport structures and a section of the runway into a new town there, while repurposing a dry dock in Sembawang for sports and recreation has been mooted as a possibility. If treated like Turf City, the development of these towns will demonstrate Singapore's ability to meet future growth needs, while remaining grounded in its heritage.

Japan tariff negotiator held in-depth talks with Lutnick, Japanese government says
Japan tariff negotiator held in-depth talks with Lutnick, Japanese government says

Straits Times

time9 hours ago

  • Straits Times

Japan tariff negotiator held in-depth talks with Lutnick, Japanese government says

Sign up now: Get ST's newsletters delivered to your inbox (From right) Japan's Economic Revitalisation Minister Ryosei Akazawa poses with US Treasury Secretary Scott Bessent, Commerce Secretary Howard Lutnick and US Trade Representative Jamieson Greer in Washington on May 1. TOKYO/BRIDGEWATER, New Jersey - Japan's tariff negotiator Ryosei Akazawa held 'in-depth exchanges' over the phone with US Commerce Secretary Howard Lutnick on July 3 and July 5, the Japanese government said. A pause on a 24 per cent reciprocal tariff on imports from Japan expires on July 9, although US President Donald Trump has suggested the rate could be even higher. The Japanese government also said in a statement that it intends to continue actively coordinating with the US side on the matter, as it worked to avert higher tariffs. The White House declined to comment on the report, referring only to Mr Trump's recent comments on Japan. Mr Trump this week hammered Japan over what he said was Tokyo's reluctance to import US-grown rice, and accusing Japan of engaging in 'unfair' autos trade. Japan has in fact imported historically high volumes of US rice in recent months as domestically grown rice has skyrocketed in price since last year. It was unclear if Mr Trump would make good his pledge to skip further trade negotiations with Japan and send it a letter with a specific tariff rate, on top of the 10 per cent already in effect on most trading partners. On July 4 he said he had signed letters to 12 countries and they would be going out on July 7, but did not identify them. Top stories Swipe. Select. Stay informed. Singapore Asean needs 'bolder reforms' to attract investments in more fragmented global economy: PM Wong Singapore CPF members can make housing, retirement and health insurance plans with new digital platform Singapore CPF's central philosophy of self-reliance remains as pertinent as ever: SM Lee Singapore Credit reports among personal data of 190,000 breached, put for sale on Dark Web; IT vendor fined Asia Dalai Lama hopes to live beyond 130 years, much longer than predicted Singapore Tan Cheng Bock, Hazel Poa step down from PSP leadership; party launches 'renewal plan' Sport Liverpool will move on after Jota's tragic death, but he will never be forgotten Singapore Rock climbing fan suddenly could not jump, get up from squats He expressed doubt that a deal could be reached with Japan on July 8, and suggested he could impose a tariff of 30 per cent or 35 per cent on imports from Japan - well above the 24 per cent tariff rate he announced on April 2. Japanese Prime Minster Shigeru Ishiba on July 2 said he was determined to protect his country's national interests as trade negotiations with the US struggled, noting that his country was the largest investor in the United States. Tokyo has yet to secure a trade deal after nearly three months of negotiations as it scrambles to find ways to get Washington to exempt Japan's automakers from 25 per cent automobile industry-specific tariffs, which are hurting the country's manufacturing sector. REUTERS

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store