Oral Answer

Probe into Unauthorised Access of Vendor-managed SLA Platform Containing Real Personal Data

Speakers

Summary

This question concerns unauthorized access to a vendor-managed Singapore Land Authority (SLA) test environment containing personal data of about 70,000 individuals, with Mr Low Wu Yang Andre inquiring how the data entered the dataset, when audits occurred, and what contractual actions would follow. Senior Minister of State Murali Pillai explained that the breach involved an IBM-managed development environment created in 1998 for SLA's registration and lodgment systems, while live operational systems remained unaffected. He stated that the dataset was intended to be anonymised, but incomplete anonymisation was missed during regular audits, including a 2025 risk-based audit focused on broader information and communications technology security controls. Senior Minister of State Murali Pillai noted that SLA completed checks across other systems and found no similar issues. He concluded that SLA is currently investigating the matter, after which appropriate contractual actions and audit process considerations will be determined.

Transcript

16 Mr Low Wu Yang Andre asked the Minister for Law regarding unauthorised access to a vendor-managed Singapore Land Authority test environment containing real personal data of about 70,000 individuals (a) how did the data enter and remain in a dataset intended for mock or anonymised data; (b) when was the environment last audited against Government data-security requirements; and (c) what contractual action will be considered after investigations.

The Senior Minister of State for Law (Mr Murali Pillai) (for the Minister for Law): Mr Speaker, Sir, the data security incident involved unauthorised access to a data set in a development and systems-integration testing cloud environment managed by IBM. IBM was the vendor appointed to support and maintain the Singapore Land Authority's (SLA's) Singapore Titles Automated Registration System (STARS) and the eLodgment System (ELS). The affected environment was separate from SLA's live operational systems, which were not affected.

The data set was created in 1998 for major system tests and updated periodically over the subsequent years. Although the data set was intended to contain only mock and anonymised testing data based on property ownership and lodgement records, SLA subsequently uncovered that the data set contained personal information which was not anonymised. STARS and ELS are subject to regular audits, with the most recent audit carried out in 2025.

The appropriate contractual action will be determined after the full facts and respective responsibilities have been established. SLA is investigating the matter.

Mr Speaker: Mr Low.

Mr Low Wu Yang Andre (Non-Constituency Member): Thank you, Speaker. I thank the Senior Minister of State. I have two supplementary questions. First, will SLA also be undertaking audits of any other development or test environments arising from this incident to make sure that no similar issues are occurring elsewhere?

And secondly, it seems like the Senior Minister of State has acknowledged that the audits that were previously undertaken might have had some gaps, and especially, it sounds like the audits were being undertaken on the nature of the technical controls, but not of the actual data, given that the data set has been in existence for almost 20 years and it was only uncovered now. Will SLA reform their audit process going forward, so that the actual data is audited periodically, to make sure that no personal information inside is leaked?

Mr Murali Pillai: Sir, in response to the first question of the hon Member, indeed SLA has completed checks across its other systems and found no similar issues.

Turning to the second question about audit, I would like to clarify that the 2025 audit was determined through a risk-based scoping exercise that was conducted in late 2024. Based on the IT risk landscape known at that time, the audit prioritised broader information and communications technology (ICT) security and resilience controls, such as cloud security management, privileged access and third party management. The incomplete anonymisation was not identified during the audit.

The hon Member makes pertinent points. This is something that we can consider once the investigation is complete.