Home Blog Page 308

Moody’s and Team8 join hands to launch a Joint Venture

Partnership

Moody’s Corporation recently announced that it has collaborated with the cybersecurity think tank and company creation platform Team8 to establish a global standard for evaluating and assessing cyber risk for enterprises. Moody’s is an American based financial corporation providing credit ratings, research, tools, and analysis that help for transparent and integrated financial markets.

The new joint venture will integrate Moody’s experience in measuring risk with Team8’s expertise in cybersecurity technologies and unique access to cyber talent. The venture will focus on the development of innovative methods and technologies that effectively measure and analyze cyber risks facing in financial markets.

Founded by ex-leaders of Israel’s military intelligence Unit 8200, Team8 develops companies that address cybersecurity issues. In the process of creating advanced cybersecurity solutions/startups, Team8 partners with other security firms who later become their clients.

According to Team8’s company-building model, the chief information officers and engineers from its corporate partners are involved in the creation of the cybersecurity companies. So far, Team8 created eight cybersecurity startups in which four startups are working in stealth mode.

The joint venture will be led by Derek Vadala, the Chief Executive Officer at Moody’s. “The combination of Team8’s industry-leading knowledge and experience in cybersecurity and Moody’s expertise in analyzing and quantifying financial risk allows for the creation of a unique capability to serve as a standard for cyber risk assessment,” said Derek Vadala.

“There is a real necessity in the marketplace for an efficient, objective and independent assessment mechanism to assess the cyber posture of companies around the world. We are excited to embark on this journey with Moody’s and are confident that together we can establish a first-of-its-kind global standard for evaluating the complex cyber risk facing enterprises,” said Nadav Zafrir, the Co-Founder and CEO of Team8.

Team8 recently announced that it has raised $85 million investment to create eight cybersecurity startups last year. The investment round was led by Walmart, Airbus, SoftBank, Moody’s, Dimension Data, Munich Re, and Scotiabank along with the existing investors Cisco Investments, Nokia, and Microsoft’s venture arm M12.

“The commitment from our new partners illustrates the significance of our work to galvanize digital transformation across all industries,” said Team8 CEO Nadav Zafrir in a statement. “The synergy and insight from leaders in retail, aerospace, insurance, financial services and technology combined with our unrivalled attacker perspective and data expertise at Team8 will enable companies to adopt new data-driven methods of working, ensuring they can retain their competitive advantage and thrive, in spite of cyber threats.”

 

Cloud Hopper hits several tech firms in Spyware attack

Spyware

Security researchers stated that a global hacking campaign backed by China’s Ministry of State Security broke into various technology service providers to steal commercial secrets from their clients.

According to the Reuters investigation report, a group of Chinese cyberspies, known as Cloud Hopper, hacked eight of the world’s biggest technology service providers years ago. The attack exploited the vulnerabilities in those companies’ network systems, spied on their intellectual properties and their customers’ personal data.

The Reuters report revealed the compromised companies list that included Hewlett Packard Enterprise, IBM, Fujitsu, Tata Consultancy Services, NTT Data, Dimension Data, Computer Sciences Corporation, and DXC Technology.

Apart from the service providers, the investigation also identified the victims who were clients of the service providers, which include Swedish telecoms giant Ericsson, U.S. Navy shipbuilder Huntington Ingalls Industries, and travel reservation system Sabre.

Reuters stated that it was unable to discover the full extent of the damage done by Cloud Hopper campaign and many of the victims are uncertain of exactly what information was stolen.

“While there have been attacks on our enterprise network, we have found no evidence in any of our extensive investigations that Ericsson’s infrastructure has ever been used as part of a successful attack on one of our customers,” Ericsson said in a statement.

But the Chinese government denied all the accusations of their involvement in the hacking campaign. “The Chinese government has never in any form participated in or supported any person to carry out the theft of commercial secrets,” The Chinese Foreign Ministry said in a statement.

Recently, the popular messaging app Telegram criticized the Chinese government after it suffered a DDoS (Distributed Denial of Service attack) attack that affected the users in the United States, Hong Kong, and in other countries. Telegram, well-known for its encryption, privacy, and self-destructive private messages, stated the users might have experienced connection issues due to the attack.

Telegram took to Twitter to notify its users. “We’re currently experiencing a powerful DDoS attack, Telegram users in the Americas and some users from other countries may experience connection issues,” Telegram said in a Twitter post. Describing the attack Telegram said, “A DDoS is a “Distributed Denial of Service attack”: your servers get GADZILLIONS of garbage requests which stop them from processing legitimate requests. Imagine that an army of lemmings just jumped the queue at McDonald’s in front of you – and each is ordering a whopper.”

Meanwhile, the Telegram founder Pavel Durov stated the Chinese government may have been behind the DDoS attack. Durov described the incident as a “state actor-sized DDoS” which came mainly from IP addresses located in China. The attack coincided with the ongoing protests in Hong Kong, where people are using Telegram to avoid detection while coordinating their protests.

New Malware campaign ViceLeaker targeting Android Devices: Researchers

Rootkits, Mobile Malware in Asia

Security researchers revealed an ongoing Android malware campaign dubbed ViceLeaker that has been active since 2016. According to the researchers from Kaspersky, a hacker group has been found targeting Israel citizens and other Middle East countries with surveillance malware named Triout.

The malware is designed to steal sensitive information, including call recordings, text messages, photos, videos, and location data without users’ knowledge. Apart from spying features, the malware also has backdoor capabilities, including upload, download, delete files, record surrounding audio, takeover camera, and make calls or send messages to specific numbers, according to the researchers.

The researchers said that attackers used Smali injection technique, that allows hackers to disassemble the code of an original application and add malicious code.

“In May 2018, we discovered a campaign targeting dozens of mobile Android devices belonging to Israeli citizens. Kaspersky spyware sensors caught the signal of an attack from the device of one of the victims; and a hash of the APK involved (Android application) was tagged in our sample feed for inspection. Once we investigated the file, we quickly found out that the inner workings of the APK included a malicious payload, embedded in the original code of the application. This was an original spyware program, designed to exfiltrate almost all accessible information,” Kaspersky said in a statement.

A similar research from Kaspersky revealed that the number of Distributed Denial of Service (DDoS) attacks increased by 84 percent in the first quarter of 2019 compared to Q4 of 2018. In its research report dubbed DDoS Attacks in Q1 2019, Kaspersky stated that cybercriminals are once again turning to DDoS attacks after a sustained time period.

The Moscow-based cybersecurity firm also revealed that it discovered a considerable growth in the number of attacks that lasted more than an hour. According to the research findings, China reported the highest number of DDoS attacks (67%) while the U.S. reported the second largest attacks (17.17%) and Hong Kong stood third (4.81%).

Earlier, Kaspersky uncovered AppleJeus, a malicious operation by North Korea’s cyber-hacking outfit ‘Lazarus Group’ to intrude on cryptocurrency exchanges and applications. According to an official report, Kaspersky Lab’s Global Research and Analysis Team (GReAT) discovered the unusual activity of attackers who penetrated the network of an Asia-based cryptocurrency exchange using Trojanized trading software to steal cryptocurrencies. Vitaly Kamlut, the head of GReAT, stated that the cryptocurrency exchange did not encounter any financial losses during the incident.

UltraSoC raises £5m investment to enhance its safety and security applications

Startup funding

Technology company UltraSoC recently closed £5 million (around $6.3 million) equity funding round led by cybersecurity-focused venture capital firm eCAPITAL and Seraphim Capital along with the participation from the existing UltraSoC investors Indaco Venture Partners, Octopus Ventures, Oxford Capital, Techgate, and business angel Guillaume d’Eyssautier.

Headquartered in the United Kingdom, UltraSoC makes complex circuits for automotive parts and is a developer of analytics and monitoring technology of the systems-on-chip (SoCs). The company claims that its embedded analytics technology platform allows product designers to add advanced cybersecurity and performance tuning features in order to resolve critical security issues.

Speaking on the new investment Rupert Baines, the CEO of UltraSoC, stated the new funding will be used to accelerate its growth globally to address emerging opportunities in the cybersecurity, high-reliability, and safety-critical systems markets.

“UltraSoC is already established as the solution of choice for semiconductor companies who need to understand how their system-on-chip (SoC) products are behaving – yielding dramatically reduced development and debug costs and faster time to market. But those same customers – and investors – are now recognizing the strategic potential for our technology in implementing functional safety and cybersecurity features. This funding round will enable us to grasp that opportunity, which I believe we are uniquely equipped to address,” Baines said.

“Developers are struggling to cope with the need for trusted solutions for cybersecurity and functional safety. UltraSoC is uniquely able to provide such features at the fundamental hardware level. eCAPITAL and Seraphim add sector-specific focus and expertise in cybersecurity and in the aerospace ecosystem, where functional safety and reliability are paramount. I’m delighted to have secured their support alongside our existing major investors who have recommitted in this latest funding round,” said UltraSoC’s Chairman, Alberto Sangiovanni-Vincentelli.

Accenture acquires cybersecurity company BCT Solutions

Accenture

Technology company Accenture recently entered into a decisive agreement to acquire cybersecurity company BCT Solutions to bolster the Defence, National Security and Public Safety capabilities in Australia and New Zealand.

Founded in 2015 by defense force veterans Patrick Batch and Angus Heatly, BCT Solutions is specialized in command and control, cyber security, and cyber defense services. The latest acquisition help Accenture strengthen its cybersecurity and cyber defense capabilities and accelerate its strategy to provide end-to-end services to its government clients.

“BCT will complement Accenture’s Defence, National Security and Public Safety capabilities in Australia, extending the reach and scale of our business to transform bold ideas into breakthrough outcomes for our public sector clients,” said Catherine Garner, who leads Accenture’s Health & Public Service practice in Australia and New Zealand. “BCT’s impressive experience and capabilities will enable us to enhance the services we provide to government agencies in Australia — ultimately helping improve the lives of citizens.”

“We are excited to join forces with Accenture to address the pressing challenges facing the Defence and broader public sector landscape,” said Angus Heatley, a Director at BCT Solutions. “Most of the BCT workforce are veterans and have the deep, first-hand defence and national security industry experience, skills and understanding to better equip the men and women of Australia’s Defence force. Together with Accenture, we can further tailor services to our clients’ ever-changing security needs and ensure they are building resilience from the inside out.”

Recently, Accenture launched the Accenture Federal Services (AFS) Cyber Center, a state-of-the-art facility in San Antonio that provides cybersecurity capabilities on an as-a-service basis to help government agencies and the Department of Defense manage, detect and respond to the increasing volume and velocity of cyber threats that target government networks.

The Cyber Center offers a suite of security-as-a-service solutions and leading-edge capabilities in advanced adversary simulation, orchestration & automation, and managed detection and response.  An interdisciplinary team of advanced cyber defense experts deploys advanced technologies — including artificial-intelligence-based cyber intelligence — to help government agencies quickly and cost-effectively identify, emulate and eliminate threats.

The Cyber Center is part of a larger AFS expansion in San Antonio. The company currently employs more than 1,300 people at its two primary San Antonio locations and recently announced plans to invest $5 million and add 500 full-time jobs over the next four years to enhance and expand the operations of its Advanced Technology Center in the city.

Accenture is also extending its commitment to provide student internships and apprenticeships that advance industry-relevant skills and provide on-the-job training opportunities to help train the next generation of U.S. technology talent. AFS recently became the anchor industry partner for San Antonio Cyber P-TECH, which gives students the skills, credentials and industry-specific associate degrees necessary for high-wage, high-demand careers in cybersecurity.

New York Legislature passes New Bill to strengthen Data Breach Policies

The New York State Legislature recently passed a new bill in order to strengthen its data breach policies. The new bill, dubbed as Stop Hacks and Improve Electronic Data Security Act (SHIELD), provides more transparency to consumers while also impose stringent penalties on companies without proper cybersecurity measures.

According to the Attorney General Letitia James, the SHIELD Act will update the state’s breach notification laws, expand the current notification requirements for companies, increase penalties for liable companies, and increase the rights of consumers in the event of a breach. The new bill imposes tough obligations on businesses that handle sensitive data of customers.  The businesses are required to maintain reasonable data security measures in case they’re collecting personal data from the customers.

“Consumers deserve the peace of mind that their private information is secure,” said Attorney General Letitia James. “That’s why my office has been working hard this session to modernize our outdated laws governing data breaches. This bill is an important step forward providing greater protection for consumer’s private information and holding companies accountable for securing that data. I thank the sponsors of this bill, Senator Kevin Thomas and Assemblymember Michael DenDekker for their leadership in ushering this legislation through their respective chambers.”

“It is critical that our laws keep pace with the rapidly changing world of technology,” said State Senator Kevin Thomas.“I am proud to announce the passage of the SHIELD Act today, as it will allow for increased accountability and diligence in regards to consumer privacy. Now more than ever, it is important that businesses protect the private information of the consumers they serve.”

In order to boost cybersecurity and tackle next-generation cyber threats, the Singapore government recently updated the guidelines on data breach notification and accountability. Unveiled by the Personal Data Protection Commission (PDPC), the new guidelines are intended to help companies manage data breaches more effectively.

As per the new procedures, which are expected to be included in the upcoming data protection act, the companies in Singapore should not take more than 30 days to complete an investigation into a suspected data breach. The companies are also required to notify the authorities about the incident before 72 hours after discovering a data breach.

The PDPC stated the businesses are required to notify authorities if a breach affects more than 500 individuals. The data intermediaries also need to report potential data breaches to their parent organization within 24 hours after identifying a security incident.

Also, Vietnam lawmakers approved a new cybersecurity law that controls the Internet content and global tech companies operating in the country. The new cyber law, which came into effect on January 01, 2019, requires Facebook, Google, and other international tech firms to store local users’ data on local servers and set up offices in Vietnam.

The new law prohibits Internet users in Vietnam from spreading anti-government information and posting false information that could cause damage to the country. It also prevents the circulation of content that’s fake, slandering, or inciting violence.

Deconstructing Apple Card: A Hacker’s Perspective

Apple Notarization

Contributed by Ryan McKamie and Swapnil Deshmukh, Certus Cybersecurity Solutions LLC

Apple Inc. recently announced the introduction of Apple Card, a product developed in collaboration with Goldman Sachs and Mastercard, which the company is touting as a “a new kind of credit card” featuring “a new level of privacy and security.”  In this article, we unpack the technology behind Apple Card, including its strengths and weaknesses from both a security and privacy perspective.  The security integrated within Apple Card is novel as a case study for information security professionals tasked with protecting sensitive information.  For example, the card lacks certain cardholder data (e.g. Primary Account Number, Expiration Date and CVV2) which is both integral to the function of conventional credit cards and at the same time a weakness.  Another novelty and strength associated with Apple Card is that it leverages the heightened security of host card emulation (HCE) – better known as secure element (SE) – a software architecture that enables identification and protection of digital cards. Through these features, combined with many other security enhancements, Apple Card proves that it is possible to provide higher levels of security and privacy even on resource constrained devices.

Apple Card Initialization Process

In order to understand Apple Card’s overall security posture, we need to walkthrough the end-to-end flow from card manufacturing to initialization and registration with a mobile device.  This provides a foundational understanding of the security controls built into the Apple Card payment flow.

During the manufacturing process, Apple provisions Mastercard’s public key on the physical card chip, which is signed by the chip manufacturer’s public key and then syncs with Mastercard’s tokenization service, enabling Mastercard to validate the authenticity of their public key. Mastercard’s tokenization service is responsible for maintaining a registry of all trusted chip manufacturers and its certificates.  This registry is held in a trust store, which verifies certificates from a trusted Certificate Authority (CA).

Chip-specific information such as the integrated circuit card (ICC) key pair and certificate are also signed by the chip manufacturer and provisioned on the chip.

Once the consumer has received the card, Mastercards’ payment applet takes payment information from the issuing bank and securely stores it the SE. Users are prompted for a nonce, or special random number, to validate the user’s authenticity. For successful initialization of the applet, it must validate a unique device PAN signed with Mastercards’ public key using the tokenization API.

On a frequent basis, Apple card performs secure key exchange/generation using Application Processing Data Unit (APDU) commands, this secure key generation replenishes encrypted tokens and unique derived keys.

In case of a lost or stolen card, an adversary cannot make any transactions and the user can receive a new token and unique derived keys on their provisioned devices without concern about fraudulent transactions.

Mastercard’s token enrollment APIs negotiate end-to-end encryption protocols between the secure element and Mastercard’s tokenization service. We speculate that the protocol leverages 3DES, which is then hex encoded and is concatenated with Device Encryption Key (DEK), derived from device key, and the device’s MAC address. Encryption is performed using RSA and gets signed using the ISO 9796. This ensures the key size for both encryption and signature to be 1024 bits.  This way, the heavy lifting of encryption is handled by backend servers. Along with that, as there is a device key and MAC involved in the key generation ceremony, there are a few key generation attributes tied to the users’ Apple Card.

Secure Communication with Mobile Device and Applications

Apple Card owners will likely need to enroll the card into their iPhone manually by entering the cardholder’s data into the Passbook application (we speculate some form of card identifier will be provided by mail or on the card itself to facilitate this process). The unique card identifier, or temporary DPAN, will then be combined with a owner’s specific key and sent to Goldman Sachs along with their iTunes information such as billing address, full name and phone number over secure encrypted channels. Goldman Sachs would view this information in the clear but Apple asserts that Goldman Sachs will refrain from sharing or selling this data to third parties for marketing or advertising purposes. Using the information submitted from the owner’s iOS device, Goldman Sachs then decides whether to approve before allowing the user to add (or bind) the card to the Passbook app. At Goldman Sachs’ discretion, the bank’s process will include steps for additional validation that the cardholder may need to register the credit card. The account holder may confirm their identity with a one-time code. Once the identity is confirmed, Goldman Sachs will create a DPAN, which is a token-like value based upon the user’s personal account number and the user’s device specific information. The DPAN is returned to the device via a two-way transport layer security (TLS) connection from Goldman Sachs for storage in the iOS device’s SE. The DPAN, stored in the SE, is never stored on Apple Card servers, or backed up to iCloud. In addition, the DPAN is encrypted using the user’s private keys, which Apple does not have access to and so has no ability to decrypt. This clear segregation of keys enables Apple to ensure user privacy is maintained and user spending habits or payment-related information is never shared between the company’s servers.

For secure payments, the foundational security of Apple’s products rests upon SE, which is a hardware driven, tamper-resistant solution capable of securely hosting payment applets, securely communicating other mobile applications and ensuring confidentiality and key management of sensitive data. The SE embeds into the NFC chip, which is used by Apple Pay at payment terminals. The NFC chip facilitates communication between the terminal and the SE. They key takeaway from the SE integration is a hardware-driven microcontroller that performs all the security checks for sensitive data and is segregated from the rest of the mobile applications. This provides strong cryptographic computational power in a single chip.

Authenticating Users to Access Information 

Only applications created by Apple have access to Apple Card payment information.  When the any mobile application is trying to access payment information such as transaction history or making a cash transaction, a call is made to the Apple Card Servers with DPAN information to obtain a timebound nonce. This number, along with other transaction data, is passed over an applet to the SE to generate a payment signature. When the payment signature comes out of the SE, it’s sent to Apple Card Servers over encrypted channels. The authenticity of this transaction is verified through this payment signature and the random number provided by Apple Pay Servers. After successful verification of the payment signature, the user’s request is initiated. If the user wants to view the transaction details, then temporary payment applet access is provided to the Apple-created mobile applications. For sending or receiving payment, encrypted payment transaction information is sent back to Apple Card Servers, which is encrypted using the user’s private key. In case additional user identification is requested, then that information is also handed over to Goldman Sachs via Apple Card servers using the user’s private key encryption.  The only caveat is that any user enrolled on that device can make a payment on someone else’s behalf provided they can perform touch or face authentication.

Conclusion

As shown in this article, foundational security is embedded across the entire payment flow right from manufacturing to successful payment. Broadly, the security takeaways from Apple Card are threefold: First, from an architecture perspective, Apple thought through all the moving parts and managed to achieve security without compromising user experience. Second, rather than introducing a very fragmented ecosystem for payment, they narrowed the players to only Mastercard and Goldman Sachs, which reduces the number of dependencies and overall business risk. Finally, by integrating hardware-based security controls such as tamper resistance and SE, Apple ensured the foundational security of Apple Card is not software-driven, which may have proved more error prone than hardware controls. The only caveat to this approach is that if a bug is found in the hardware, a fix cannot easily be applied.

The opinions expressed in this article are the personal opinions of the author. The facts and opinions appearing in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Facebook’s request to quash data breach lawsuit dismissed!

Facebook

Facebook has failed to block a lawsuit over a data breach that impacted around 30 million users in 2018. A Federal appeals court in San Francisco recently rejected the social media giant’s request to dismiss the court case, in which petitioners claim that Facebook has proven itself negligent in handling and securing users’ data. the Bloomberg reported.

The U.S. District Judge William Alsup, who’s presiding over the petition, has permitted the case to go forward. “From a policy standpoint, to hold that Facebook has no duty of care here would create perverse incentives for businesses who profit off the use of consumers personal data to turn a blind eye and ignore known security risks,” Alsup said in a statement.

The social media giant announced that its team has discovered a security breach that affected nearly 50 million users globally in September 2018, although the victims’ number later revised to over 30 million.

Facebook stated a security vulnerability existed in its basic ‘View As’ feature which was often used to show how the account looks like to the public. The vulnerability in the code and a combination of three bugs allowed the hackers to penetrate the accounts.

“It looks like when Facebook built the ‘View As’ feature, they did this by making it a modification of how Facebook would work if actually viewed by that other user,” said professional web app hacker and cybersecurity researcher Thomas Shadwell to Forbes. “Which of course means if there’s a mistake they might end up sending the impersonated user’s credentials to the user of the ‘View As’ feature.”

Recently, the Turkish government’s watchdog, Personal Data Protection Authority (KVKK), fined Facebook a total of 1.65 million Lire ($270,976.01) for failing to protect its users’ personal information.

The fine comes after Facebook reported a data breach in December 2018, that exposed 6.8 million users’ private photos to third-party application developers. The social networking giant stated that its internal team discovered a photo API bug that allowed third-party apps to access users’ photos for 12 days between September 13 to September 25, 2018.

The company declared that it has fixed the issue, but some third-party apps may have had access to a wider set of photographs which were uploaded/shared on the Facebook Stories. KVKK stated that the data breach affected around 300,000 users in Turkey last year and Facebook did not reacted in time with technical precautions regarding the issue.

AI startup Xanadu raises $32 million to accelerate Photonic Quantum Computing

Startup funding

The photonic quantum computing startup Xanadu recently secured $32 million in a Series A financing round to accelerate its progress toward the release of its photonic-based quantum cloud computing platform. The funding round was led by OMERS Ventures along with the participation from other investors, including Georgian Partners, Radical Ventures, Real Ventures, Silicon Valley Bank, and Tim Draper.

Founded in 2016 by Christian Weedbrook, Xanadu is focussed on providing quantum on demand to enable significant computational improvements. “Confidence in Xanadu’s photonic approach to building a quantum computer is reflected in the strong interest from the highly reputable VC firms we have in this Series A financing,” said Weedbrook in a media statement.

The Toronto-based company stated the new investments will support its milestone – the release of a quantum cloud-computing platform. “Xanadu’s vision of the quantum cloud is truly unique. In addition to solving a different set of important problems across industries, using photonics, we have the potential of having an all-optical quantum data center. As photonics is a natural underlying substrate for many quantum technologies—quantum computing, quantum sensors, and quantum security—our platform can be used throughout the larger quantum technology sector,” Weedbrook added.

“We are thrilled to continue our support of Christian and the Xanadu team,” said Sid Paquette, managing partner at OMERS Ventures. “Once they deploy the world’s most powerful cloud-computing platform, we anticipate creative approaches from developers in harnessing Xanadu’s next-generation processing capability and its potential to accelerate finance, quantum chemistry, material science, and artificial intelligence.”

PDPC fines AIA Singapore for failing to protect policyholders’ data

AIA

The Singapore-based insurance firm AIA Singapore recently fined for S$ 10,000 by the Personal Data Protection Commission (PDPC) for failing to take proper security arrangements in its letter generation process. The penalty comes after AIA Singapore sent 245 letters, which belonged to various policyholders, to wrong addresses, exposing customers’ sensitive information.

According to the official statement, the insurance company generated the letters on December 22, 2017, and December 27, 2017, that comprised four integrated shield plan premium notice reminder letters, 237 integrated shield plan premium notice letters, three change of payor letters and other sensitive information, sent to only two customers between December 28, 2017, and January 02, 2018.

AIA Singapore stated the issue occurred due to a technical glitch in their system while processing the letters online. “At AIA Singapore, we are serious about safeguarding confidential information entrusted to us, and will continually strive to better serve our customers,” AIA said in a statement.

The PDPC stated that AIA Singapore compromised policyholders’ personal data due to wrong mailing and violated the privacy norms as per section 24 of the Personal Data Protection Act 2012. PDPC also concluded that AIA Singapore did not perform any testing before rolling out the letters and did not check to ensure the accuracy of the letters that the system generated automatically.

Recently, the PDPC fined its computer vendor Option Gift $4,000 for disclosing the personal information of 426 NSmen (National Servicemen) last year. The commission recently stated that it discovered in an investigation that Option Gift violated section 24 of the Personal Data Protection Act by exposing the sensitive information.

The compromised data included sensitive information like log-in identifications, e-mail addresses, delivery addresses, and mobile phone numbers of the NSmen from the Singapore Armed Forces (SAF) and Home Team. The issue occurred due to a technical issue in Uniquerewards, online portal maintained by Option Gift, which allows NSmen to redeem credits for service-linked rewards from the Ministry of Defence (MINDEF) and the Ministry of Home Affairs (MHA).

The personal information of the NSmen was leaked when e-mails that are meant to be sent out individually ended up sending it to all the NSmen due to an error in the program script. The PDPC stated that Option Gift had failed to conduct enough testing before deploying the program script.

In order to boost cybersecurity and tackle next-generation cyber threats, the Personal Data Protection Commission of Singapore recently updated the guidelines on data breach notification and accountability. The new guidelines are intended to help companies manage data breaches more effectively.

As per the new procedures, which are expected to be included in the upcoming data protection act, the companies in Singapore should not take more than 30 days to complete an investigation into a suspected data breach. The companies are also required to notify the authorities about the incident before 72 hours after discovering a data breach. The PDPC stated the businesses are required to notify authorities if a breach affects more than 500 individuals. The data intermediaries also need to report potential data breaches to their parent organization within 24 hours after identifying a security incident.