Skip to content
Data breachContained

Singapore Land Authority test-environment breach exposes 70,000 people

The Singapore Land Authority said names, NRIC numbers and past property addresses of about 70,000 people were compromised after unauthorized access to an IBM-managed testing environment whose supposedly mock dataset contained real records.

Victim
Singapore Land Authority
users
70.0K

On 3 July 2026, the Singapore Land Authority (SLA) disclosed that personal data of about 70,000 people had been compromised after unauthorized access to a testing environment managed by IBM. The environment supports development and systems integration testing for the Singapore Titles Automated Registration System (STARS) and the eLodgment System (ELS), which are used to submit property transfer and caveat documents.

IBM discovered the incident and reported it to the SLA. Access to the affected testing environment was revoked, and the SLA said it was working with IBM, the Government Technology Agency (GovTech) and the Cyber Security Agency of Singapore to investigate.

What was exposed

The dataset, first created in 1998 and updated periodically, was meant to contain only mock and anonymized records but in fact held real names, NRIC (national identity card) numbers and past property addresses. The SLA stressed that there was no connection to or compromise of the live STARS, ELS or other SLA systems, and that property ownership and lodgment records remained secure. The authority identified the affected individuals and began notifying them.

Why it matters

Local media described it as one of Singapore's most significant public-sector data incidents since the 2018 SingHealth breach. The root cause is a classic one: real personal data copied into a non-production environment, managed by a vendor and protected less strictly than live systems, then forgotten for decades.

Timeline

  1. The test dataset later found to contain real personal data is first created; it is updated periodically afterwards.

  2. SLA discloses that IBM detected and reported unauthorized access to the testing environment for STARS and ELS, affecting about 70,000 people.

Sources

  1. techgoondu.comhttps://www.techgoondu.com/2026/07/03/data-for-70000-people-compromised-in-singapore-after-government-test-system-exposed/
  2. malaymail.comhttps://www.malaymail.com/news/singapore/2026/07/03/singapore-land-authority-data-breach-exposes-70000-records-after-ibm-testing-environment-compromised/226215
  3. freemalaysiatoday.comhttps://www.freemalaysiatoday.com/category/highlight/2026/07/03/personal-info-of-70000-people-in-singapore-exposed-in-data-breach

Related incidents

Data breachResolved

Protemps data breach (2021)

In October 2021, the Singaporean recruitment website Protemps suffered a data breach that exposed almost 50,000 unique email addresses. The impacted data includes names, email and physical addresses, phone numbers, passport numbers and passwords stored as unsalted MD5 hashes, among troves of other…

Victim
Protemps
Records
49.6K