Back to the archive
Incident file · 2018
SingHealth
Public health · Singapore · Threat actor: State-linked APT
Data breach
No ransom demanded
- None
- Ransom demanded
- No
- Ransom paid
- 2 days
- Estimated downtime
- US$8m
- Est. revenue lost
What happened
Attackers used an unpatched workstation to reach the outpatient prescription database in a targeted espionage operation.
How it ended
No ransom involved; regulators fired S$1m in fines and mandated an internet-surfing separation programme.
Data affected
1.5 million patients
Would your business survive this incident?
We stress-test detection, response and recovery so a ransom demand is never your only option.