The Singapore government announced that attackers had stolen personal data of around 1.5 million patients of SingHealth, the country’s largest group of healthcare institutions. Prime Minister Lee Hsien Loong‘s data was specifically targeted. Officials described the attack as deliberate, targeted, and well planned.
What happened
- The attack took place between late June and early July 2018.
- Names, identity card numbers, addresses, and dates of birth were taken, along with outpatient medication records of around 160,000 people.
- The government called it the most serious breach of personal data in Singapore’s history and set up a Committee of Inquiry.
- Singapore’s data protection regulator later fined SingHealth and its IT provider a combined S$1m.
Why it mattered
The breach showed that healthcare data is a high-value target and that well-resourced attackers will single out prominent individuals. The Committee of Inquiry later identified staff and system weaknesses, including delays in escalating the incident.
Lessons for organisations
Healthcare organisations should apply strong privileged access management, patch endpoints, and monitor for data exfiltration. Supplier roles and responsibilities, including who escalates suspicious activity, should be clearly defined.
Source: Al Jazeera
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.