Singtel data breached through hack on third-party file-sharing vendor

Singtel data breached through hack on third-party file-sharing vendor
Singtel said that its core operations remain "unaffected and sound".
PHOTO: The Straits Times

A third-party file-sharing system used by Singapore’s largest telco, Singtel, has been hacked and customer information may have been compromised, the company said early on Thursday (Feb 11 2021).

The breach occurred on Jan 20 but, for now, the telco assured that its core operations are not affected.

The hack was part of a wider global breach of the File Transfer Appliance (FTA) file-sharing system that recently affected other organisations including New Zealand’s central bank, the Australian Securities and Investments Commission and the Washington State Auditor’s Office in the US.

Singtel said on Thursday that an impact assessment on the extent of the data breach is being carried out.

“Our priority is to work directly with customers and stakeholders whose information may have been compromised to keep them supported and help them manage any risks,” it said.

The company did not provide details on the data and how many customers were affected.

Singtel is contacting affected customers “at the earliest opportunity once we identify which files relevant to them were illegally accessed”.

The FTA file-sharing system is provided by cloud-sharing company Accellion, which informed its customers, including Singtel, of the hack on Dec 23 last year.

Describing FTA as a 20-year-old product near the end of its functionality, Accellion said it suffered a “sophisticated cyberattack” which included exploiting a previously unknown vulnerability. The US firm said last month that fewer than 50 customers were affected.

Singtel said it applied an FTA patch from Accellion on Dec 24 and another one on Dec 27. On Jan 23, Accellion said the Dec 27 patch was ineffective against a new vulnerability, and Singtel took the product offline.

Accellion put out another patch on Jan 30 but Singtel said it received an “anomaly alert” when applying it. The vendor said Singtel’s system could have been breached and the telco confirmed this occurred on  Jan 20.

“Given the complexity of the investigations, it was only confirmed on Feb 9 that files were taken,” Singtel added.

Read Also
Lazada data breach: Personal data of 1.1 million RedMart accounts stolen and put up for sale
singapore
Lazada data breach: Personal data of 1.1 million RedMart accounts stolen and put up for sale

The telco said the breach was an isolated incident involving the third-party system, and its core operations remained “unaffected and sound”. The FTA system is used to share information internally within Singtel and externally to other stakeholders.

The telco has suspended use of FTA and is investigating with cybersecurity experts and the authorities, including the Cyber Security Agency of Singapore (CSA).

CSA’s Singapore Computer Emergency Response Team advised users to disconnect the FTA system to perform a thorough check. They should also regularly check for updates, apply patches quickly and monitor their networks for unusual activities, which may suggest data is being stolen from the FTA.

CSA said it has not received reports from other Singapore organisations on the FTA incident.

The Personal Data Protection Commission said it is investigating the incident.

Accellion told The Straits Times that it could not comment on specific customers “for their protection”. But it was “conducting a full assessment” of the FTA hack with “an industry-leading cybersecurity forensics firm”.

The company previously said it has been encouraging all FTA customers to migrate to its latest secure file-sharing kiteworks platform and has fast-tracked plans to end FTA following the cyberattacks.

It remains unclear why Singtel was still using FTA. But Accellion told IT security news site BankInfoSecurity earlier that customers might be reluctant to switch because it meant moving data, which would entail changes to procedures and having to train workers on the new system.

The identity of the hackers and their motives are not yet known.

IT security experts said Singtel’s hack is part of a trend of crooks targeting vendors and suppliers of major organisations.

“Companies like Singtel are like fortresses... and very hard to penetrate. However, attackers always go after the weakest link like vendors,” said Mr Shane Chiang, the chief executive of local cybersecurity firm Momentum Z. He said last year’s SolarWinds hacking incident was such a “supply chain attack”.

Read Also
digicult
ShopBack and RedDoorz investigating data breaches

Mr Chiang advised firms to have a way to vet and monitor their vendors on cybersecurity, and try to ensure company IT systems and physical workplaces are secure even from inside jobs, like verifying if access requests are legitimate.

“There is no perfect solution and no such thing as being unhackable,” he added.

Mr Stas Protassov, co-founder and technology president of Acronis, said that if customer data was compromised, it could be used by cybercrooks to access a person’s bank details, masquerade as the victim to forge identity documents or commit crimes in his name.

Customer data could also be sold on the black market or to carry out a targeted attack on the victim’s company. For now, he added that no FTA data has been dumped on the dark web yet, where, among other things, stolen data is sold.

“If it does contain critical information, the price for that on the dark web could be several millions of dollars,” said Mr Protassov.

Timeline of Singtel hacking

Dec 23: Accellion first informs FTA users about a previously unknown vulnerability.

Dec 24: Singtel installs patch from Accellion to plug the vulnerability.

Dec 27: Singtel installs the last available patch from Accellion; no further patch was provided after that.

Jan 23: Accellion advisory cites a new vulnerability that the Dec 27 patch was not effective against. Singtel immediately takes the system offline.

Jan 30: Singtel attempts to install a new patch to plug the new vulnerability but receives an anomaly alert. The system is kept offline and investigations confirmed a Jan 20 breach.

Feb 9: Singtel establishes that files were taken as a result of the breach.

Feb 11: Singtel announces the FTA breach.

This article was first published in The Straits Times.

homepage

trending

trending
    'I tried to save her': Friend weeps beside coffin of 23-year-old woman killed in Yishun car crash
    5 durians for $488: Punggol residents accuse door-to-door salesman of selling them sour, unripe fruits
    Wife of man who died in Bedok North accident looking for good Samaritan who administered CPR
    SIA plane bound for Seoul encounters technical issue, returns to Singapore
    'Did you have to go this far?' Malaysia's TV3 slammed after Bella Astillah made to present award to actress in ex-husband's scandal
    BlueSG is shutting down - what happens next?
    Pritam gets candid with kids’ questions on his worst subjects and favourite song in radio interview
    'Best job ever': Netizens tickled by NParks contractors using gel blasters to chase away monkeys
    'We wanted to try somewhere with footfall': Ben Yeo opens new fish soup stall at Orchard Towers
    Parents reject $30k settlement from kindergarten in JB after son suffocates to death in school van
    'I quit': Zhao Lusi voices out alleged ill-treatment by management agency
    Bro-code before go-mode: Meet the duo leading NDP 2025

Singapore

Singapore
    • 'Important to take a longer term view': DPM Gan announces 5 new committees to strengthen Singapore's economic relevance
    • 'On the verge of losing $10k': Vendors voice concerns about poor business at Bayfront SG60 food fair
    • Ex-minister Iswaran's case: Ong Beng Seng pleads guilty to abetting obstruction of justice, seeks judicial mercy
    • Tanjong Katong sinkhole: President Tharman thanks migrant workers for saving driver who fell in
    • 25-minute delay on East-West MRT Line between Boon Lay and Buona Vista due to track point fault
    • More than 578,000 crossings made on June 20 at Woodlands and Tuas checkpoints: ICA
    • Over $108k lost in prepayments to beauty businesses in first half of 2025, 464% increase from last year: Case
    • 'She had a whole life ahead of her': Boyfriend mourns Yishun fatal crash victim
    • 'They have to think 3D': All recruits at BMTC will be trained to fly drones, says Chan Chun Sing
    • Daily roundup: No plans to 'fully liberalise' cross-border ride-hail services, says LTA — and other top stories today

Entertainment

Entertainment
    • 'I was worried whether our bodies would keep up': J-pop boy band Ballistik Boyz recall filming for new music video
    • K-drama regular Song Young-kyu found dead following drink-driving incident
    • Dilraba's new drama on missing kids under fire for using childhood photo of BTS' Suga
    • 'We loved without regret': Sora Ma remembers late husband following son's first birthday celebration
    • Fan collapses onstage at Katy Perry concert
    • Heidi Klum planning to cleanse body of worms and parasites
    • Jessie J readmitted to hospital with fluid in lungs
    • Oasis 'shocked and saddened' after fan dies at their concert
    • Mark Ruffalo to join Tom Holland in Spider-Man: Brand New Day
    • The Fantastic Four: First Steps star Ralph Ineson on how his costume change felt like he was in a 'Formula One pit'

Lifestyle

Lifestyle
    • I try 11 new Michelin Bib Gourmand 2025 eateries to see if they're worth the hype, here's my honest take
    • Bak kut teh ramen, laksa shakshuka and chilli crab burgers: Celebrate National Day with these exclusive SG60 meals
    • Japanese restaurant Umi Nami to shutter, in yet another F&B business closure at Holland Village
    • Uniqlo launching T-shirt collection in collab with Pokemon Trading Card Game
    • US could require up to $19k bonds for some tourist visas under pilot programme
    • Travelling to New Zealand soon? It's likely you'll have to pay more at popular tourist sites
    • This avid runner takes the lead in SAFVC's first full contingent at NDP 2025
    • ZipZap car subscription service launches in Singapore
    • National Day promotions 2025: NDP eCoupons, $0.60 deals, $60 off and more
    • We found freehold landed homes from $4m in the east, but would you live here?

Digicult

Digicult
    • Slim, sleek, but slightly too short-lived: Samsung Galaxy S25 Edge review
    • World's best Dota 2 teams to compete for $1m prize pool in Singapore in November
    • Sony RX1R III brings back the compact full-frame but not the Sony playbook
    • China's Premier Li proposes global AI co-operation organisation
    • 'They don't gaslight you': Why some Singaporean women like to spend on these virtual men
    • Elon Musk's Starlink network suffers rare global outage
    • Spy cockroaches and AI robots: Germany plots the future of warfare
    • 'Give a positive review': Hidden AI prompt found in academic paper by NUS researchers
    • 'Report 1 shop, another 10 appear': Hoyo Fest artists on copyright struggles
    • NTU penalises 3 students over use of AI tools; they dispute university's findings

Money

Money
    • Up 4.3%: Singapore's economy grew in Q2 despite US tariff fears
    • Electric car-sharing firm BlueSG to wind down current operations on Aug 8
    • Singapore's most expensive neighbourhoods are changing - 4 buyer trends that prove it in 2025
    • Should you buy a used car in Singapore? Pros, pitfalls and price comparisons
    • Why I bought 7 properties in Johor Bahru, and will still buy more
    • Trump says US will set 15% tariff on South Korean imports under new deal
    • Cathay Cineplexes operator mm2 hires debt restructuring specialist as it faces more payment demands; CEO Chang Long Jong to retire
    • 6 best travel insurance plans in Singapore (July 2025)
    • How to claim travel insurance? A comprehensive beginner's guide (2025)
    • Britain and India sign free trade pact during Modi visit

Latest

Latest
  • Daily roundup: Chinese EV brand JMEV officially launches in Singapore with the Elight sedan — and other top stories today
  • Japan sets record high temperatures, worries mount over rice crops
  • US government restricts sports visas for transgender women
  • Vietnam facing worsening African swine fever outbreaks
  • Chinese government has 'final say' in Dalai Lama reincarnation, Tibetan official says
  • Hong Kong issues highest weather warning, as rains shut schools, courts and hospital wards
  • Israel to decide next steps in Gaza after ceasefire talks collapse
  • China's military conducted patrols in South China Sea, spokesperson says
  • Italy arrests 13 people in nationwide raids against Chinese mafia groups

In Case You Missed It

In Case You Missed It
  • Part-time PHV driver who stopped suicide attempt among 38 recipients of MHA’s public spiritedness award
  • Discrimination and bias less likely than violence and insults to be viewed as unacceptable conduct between races: AsiaOne poll
  • Australian man, 82, arrested for alleged March thefts at Changi Airport upon return to Singapore  
  • JB car wash operators say 'unfair' after business declines amid govt clampdown over prioritising Singapore-registered cars
  • 3-room and bigger Tampines, Toa Payoh BTO flats most popular with first-timers in July HDB launch
  • 'Count his lucky stars': Youth struck by taxi while dashing across Yio Chu Kang Road, netizens react
  • Tanjong Katong sinkhole: ItsRainingRaincoats raises $72,000 within 2 days for migrant workers who rescued woman
  • Tanjong Katong sinkhole: It should not have happened, says Grace Fu as panel convened to probe incident
  • Love scam: Man transfers $120k to online 'China girlfriend' of 2 years after sale of Ang Mo Kio flat
This website is best viewed using the latest versions of web browsers.