Safeware Glasswall APAC Partner
Book a demo

Explore

What is CDRZero TrustThe detection gapCapabilitiesUse cases

Products

ProductsIntegrationFile support

Compliance

Control alignmentAPAC regulatory landscape
Country guidesSingaporeAustraliaJapanSouth KoreaIndiaIndonesiaMalaysiaThailandVietnamPhilippinesTaiwanNew ZealandMongolia

More

Trust & certificationsInsightsPartnersAboutDocumentation Book a demo

Language

EnglishBahasa Indonesia日本語한국어Bahasa MelayuไทยTiếng Việt简体中文繁體中文

File-borne breach events · Southeast Asia

Singapore: documented file-borne breach events

Singapore's record pairs the country's largest breach, SingHealth, whose Committee of Inquiry traced entry to a phishing email carrying malicious code, with the 2019 ST Logistics incident, where the regulator's published decision names the exact malicious .doc attachment.

Overview

What the record shows

Singapore is rare in that its investigations publish detail. The SingHealth Committee of Inquiry produced a 454 page public report on the country's largest breach, and the Personal Data Protection Commission publishes grounds of decision that record vectors precisely: the 2019 ST Logistics decision names the date of the phishing wave, the .doc attachment, the number of users who opened it and the Emotet infection that followed.

The SingHealth entry reflects the Committee's own wording. It assessed that initial entry was "likely by way of a phishing email containing malicious code" while recording that the initial infection's source could not be conclusively determined; this page carries that qualification rather than flattening it. The email itself is a file crossing the boundary, which is why the event belongs on this record.

Documented events

File-borne incidents in Singapore

Most recent first. Every entry cites the public record it is drawn from.

  1. Email attachmentMedium impact

    ST Logistics Pte Ltd: Defence personnel data put at risk after staff opened a malicious .doc attachment carrying Emotet

    ST Logistics, a logistics vendor to Singapore's Ministry of Defence and armed forces, suffered an Emotet infection that placed unencrypted files holding personal data of about 2,400 MINDEF and SAF personnel at risk, with up to 4,000 individuals potentially affected. MINDEF disclosed the incident on 21 December 2019, and the Personal Data Protection Commission's grounds of decision, which documents the vector, imposed a financial penalty in 2021. No evidence of actual data leakage was found.

    The documented vector. Malicious .doc email attachments delivering the Emotet trojan. On 2 October 2019, ST Logistics staff received phishing emails spoofing internal senders, each carrying an attachment with the file extension .doc. The PDPC's published decision records that 13 users opened the malicious attachment, after which Emotet installed on laptops, harvested mailboxes and sent around 100 further phishing emails.

    How this class of vector is removed

    This class of vector, a macro-bearing document attachment delivering a commodity trojan, is removed by deterministic CDR rebuild: the .doc is rebuilt to the format's known-good specification and its macros and other active content are stripped before the file reaches a user, with no dependence on any recipient spotting the spoof. The Email CDR Relay applies that rebuild to inbound mail before delivery.

    Content Disarm and ReconstructionEmail CDR RelayGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine

    • logistics

    Source: Personal Data Protection Commission · Source: Personal Data Protection Commission · Source: Ministry of Defence Singapore

  2. Malicious emailHigh impact

    Singapore Health Services (SingHealth): 1.5 million patients' data taken in a breach the COI traced to a phishing email carrying malicious code

    Attackers compromised a front end workstation around 23 August 2017, moved laterally for months, and between 27 June and 4 July 2018 exfiltrated the personal particulars of about 1.5 million patients plus the outpatient dispensed medicine records of about 160,000, including the Prime Minister, who the Ministry of Health said was specifically and repeatedly targeted. The breach was disclosed on 20 July 2018, and the Committee of Inquiry's public report of January 2019 remains the authoritative account.

    The documented vector. Phishing email carrying malicious code, the message itself the carrier; a hacking tool was later installed via an unpatched Outlook vulnerability. The Committee of Inquiry's public report assessed that initial entry to SingHealth's network was "likely by way of a phishing email containing malicious code" which infected a front end workstation, while recording that CSA could not conclusively determine the source of the initial infection. The report also documents that a publicly available hacking tool was installed on that workstation by exploiting an unpatched Microsoft Outlook vulnerability, and that a later phishing email in the campaign would run automatically when previewed or read.

    How this class of vector is removed

    The vector class the Committee described, a phishing email carrying malicious code, crosses the trust boundary as a file: the message and whatever it carries. A CDR hop on the mail path rebuilds inbound attachments to their format's known good specification and applies policy outcomes, warn, quarantine or block, to inbound mail, so the malicious code class the report describes is removed from rebuilt content rather than waited on by detection. The mapping is held at medium confidence because the Committee itself qualified the finding on the initial infection's source.

    Content Disarm and ReconstructionEmail CDR RelayGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine

    • healthcare

    Source: Committee of Inquiry, Government of Singapore · Source: Ministry of Health Singapore

Scope

How to read this page

Every event on this page meets three tests before it is published. It is documented by reliable public sources: a regulator, an official inquiry, the affected organisation's own disclosure, or reputable press with named confirmation, and each entry links to those sources. The initial access or payload delivery travelled as a file, as the public record states it. An email is itself a file, so malicious code in a message and deceptive-hyperlink phishing carried by a message both count; credential attacks and pure network exploits are excluded. And the prevention analysis is conditional: where we say a capability removes a class of vector, that is a statement about how the control treats that class of content, not a claim about what any organisation ran, and not a judgement on the people who dealt with the incident.

This page is a working reference, not an incident report or legal advice. Details reflect the public record on the review date and organisations named here are cited from that record alone.

Elsewhere in the region

Other APAC territories

Files cross your boundary every day