Australian police arrest two over TeamPCP supply-chain hacks
Australian Federal Police arrest two men in Perth over the TeamPCP hacking spree that compromised open source tools to steal credentials from over 1,000 organisations.
Insights for Asia, including India, and for Australia, New Zealand, and the Pacific.
Australian Federal Police arrest two men in Perth over the TeamPCP hacking spree that compromised open source tools to steal credentials from over 1,000 organisations.
Hong Kong authorised institutions must now be operationally resilient, meeting the HKMA’s OR-2 requirements.
New Zealand’s new IPP3A requires notification when personal information is collected indirectly from third parties.
ShinyHunters claims a breach of Instructure’s Canvas platform, affecting nearly 9,000 schools and universities, then defaces login pages during exams.
Hong Kong’s first cyber security law now requires designated critical infrastructure operators to manage cyber risks and report incidents.
Vietnam’s Personal Data Protection Law No. 91/2025/QH15 takes effect, replacing Decree 13/2023.
India notifies its Digital Personal Data Protection Rules, starting a phased implementation with most obligations applying from May 2027.
Taiwan’s amended Personal Data Protection Act establishes an independent commission and strengthens breach reporting.
Singapore’s amended Cybersecurity Act extends oversight to virtual and third-party-owned Critical Information Infrastructure.
Australia’s CPS 230 now requires APRA-regulated entities to manage operational risk, critical operations and material service providers.
Malaysia’s mandatory DPO appointment and data breach notification requirements under the amended PDPA take effect.
Japan enacts its Active Cyber Defense Act, requiring critical infrastructure operators to report incidents and share information.