Skip to content
misconfigurationResolved

RedDoorz data breach

A misconfigured cloud database exposed the records of about 5.9 million RedDoorz hotel-booking customers, making it Singapore's largest data breach at the time and drawing a record-context PDPC fine against operator Commeasure.

Victim
RedDoorz (Commeasure Pte Ltd)
Loss
$54.5K
records
5.9M
users
5.9M

In September 2020, Singapore-headquartered hospitality start-up RedDoorz suffered a breach that exposed roughly 5.9 million customer records β€” at the time the largest data breach since Singapore's Personal Data Protection Act (PDPA) came into force in 2014. The breach stemmed not from a sophisticated attack but from a cloud-credential left embedded in an old mobile app.

What happened

RedDoorz, operated by Commeasure Pte Ltd, runs a budget-hotel booking platform across Southeast Asia. On 19 September 2020, an American cybersecurity firm alerted the company that one of its databases had been accessed without authorisation. Commeasure notified the Personal Data Protection Commission (PDPC) on 25 September.

Investigators traced the exposure to an access key embedded in an outdated, unused Android APK still publicly available. The key granted access to a database hosted on Amazon Web Services, allowing an attacker to query and exfiltrate the full customer dataset. The PDPC found that Commeasure had no process to manage or remove credentials in legacy code and had not detected the exposure itself.

Impact

  • About 5.9 million customer records were exposed, including names, contact numbers, email addresses, dates of birth, encrypted passwords and booking information.
  • Masked credit-card numbers were present but the full card numbers and CVVs were not compromised, limiting direct financial fraud.
  • Only around 9,000 affected customers were Singaporeans, but the breach fell under the PDPA because Commeasure is Singapore-based.

Penalty

On 15 November 2021, the PDPC fined Commeasure S$74,000 (about US$54,000). Although this was the largest breach by volume to date, the fine was comparatively modest β€” the Commission explicitly cited the financial hardship the COVID-19 pandemic had inflicted on the hospitality sector as a mitigating factor in setting the penalty.

Why it matters

The RedDoorz case became a textbook example of cloud-misconfiguration and secrets-management failure. The root cause β€” a hard-coded credential shipped in a mobile app and never rotated or revoked β€” is among the most common and preventable cloud-security mistakes. The PDPC's decision underscored that organisations are responsible for the full lifecycle of access credentials, including those buried in deprecated code, and that protective-obligation breaches can be enforced even when most affected individuals are overseas. It remains a frequently cited Singapore enforcement precedent for startups scaling on cloud infrastructure faster than their security practices.

Financial impact

Reported costs in USD

Total reported loss
54.5K
USD Β· $54,456
  • Fines & settlements$54.5K

Timeline

  1. Commeasure is alerted by a U.S. cybersecurity firm that a database holding customer data has been compromised.

  2. Commeasure notifies Singapore's Personal Data Protection Commission of the breach.

  3. Investigation finds an embedded access key in an old, unused Android APK exposed an AWS-hosted database of 5.9 million records.

  4. The PDPC fines Commeasure S$74,000 for failing to put in place reasonable security arrangements.

  5. The penalty and breach details are made public, then the largest data breach since Singapore's PDPA took effect.

Sources

  1. marketing-interactive.comhttps://www.marketing-interactive.com/personal-data-protection-commission-fines-reddoorz-sgs-site-operator-over-data-breach
  2. theregister.comhttps://www.theregister.com/2021/11/18/redoorz_fined_for_massive_data_leak/
  3. theindependent.sghttps://theindependent.sg/spores-largest-data-breach-affects-5-9-million-reddoorz-hotel-booking-site-customers/
  4. secureblink.comhttps://www.secureblink.com/cyber-security-news/reddoorz-incurred-a-fine-of-dollar54456-by-pdpc-of-singapore-following-a-data-breach-exposing-5.9-million-customers

Related incidents

Supply chainContained

SolarWinds SUNBURST supply-chain compromise (Cozy Bear)

Russian SVR operators trojanized SolarWinds Orion build infrastructure, distributing a backdoored update to 18,000 customers including the U.S. Treasury, Commerce, DHS, State, and Energy departments. The defining state cyberespionage operation of the decade.

Victim
SolarWinds (Orion customers β€” ~18,000 organisations including 9 U.S. federal agencies and Microsoft, FireEye, Mimecast)
Loss
$100.00B
Data breachResolved

GamingMonk data breach (2020)

In December 2020, India's "largest esports community" GamingMonk (since acquired by and redirected to MPL Esports), suffered a data breach. The incident exposed 655k unique email addresses along with names, usernames, phone numbers, dates of birth and bcrypt password hashes.

Victim
GamingMonk
Records
654.5K
Data breachResolved

Chowbus data breach (2020)

In October 2020, the Asian food delivery app Chowbus suffered a data breach which led to over 800,000 records being emailed to customers. The email contained a link to a CSV file with customer data including physical addresses, names, phone numbers and over 444,000 unique email addresses.

Victim
Chowbus
Records
444.2K