PCF Sparkletots pre-school in Singapore experienced a data security incident involving its student management system vendor, LittleLives. The breach occurred through unauthorized access to a compromised user account at LittleLives, affecting certain student data stored there [1, 2].
The accessed information potentially included student names, identification details, class and centre information, as well as parent or guardian contact details and invoice or payment status data. However, no banking account details, student photos, or developmental records were accessed or leaked, as these are stored separately and not handled by LittleLives [1, 2].
The incident came to light in early June 2026. PCF Sparkletots first notified parents and guardians on June 1 about the potential unauthorized access. By June 2, the pre-school had contained the breach and confirmed no confirmed data misuse had occurred. The Personal Data Protection Commission (PDPC), police, and the Early Childhood Development Agency (ECDA) were informed and began investigations. On June 7, PCF Sparkletots publicly confirmed the source was a compromised LittleLives user account and reiterated no sensitive data was leaked. Investigations remained ongoing [1, 2].
PCF Sparkletots stated, "We take our accountability for data protection seriously and will continue to provide updates should there be any significant developments" [2]. The Cyber Security Agency of Singapore has also engaged with LittleLives to advise on recovery steps [2].
To date, no evidence shows any data was viewed, downloaded, misused, or disclosed externally [1, 2]. PCF Sparkletots continues to work closely with LittleLives and professional cybersecurity services in the ongoing investigation [1, 2].