The Singapore Land Authority (SLA) announced on July 3, 2026, that personal data of about 70,000 individuals was compromised in a cybersecurity incident involving IBM, SLA’s vendor for development and testing systems [1, 2, 3]. The affected data included names, NRIC numbers, and historical property addresses linked to the individuals at that time [1, 2, 4].
The compromised data was stored in an IBM-managed cloud environment supporting SLA's Singapore Titles Automated Registration System (STARS) and eLodgment System (ELS) development and integration testing but was separate from SLA's live operational systems [1, 2, 3, 4]. SLA emphasized that the breach did not affect the live STARS or ELS systems, which remain secure and unaffected [1].
The data set, originally created in 1998 and periodically updated, was intended to be anonymised mock data for vendor testing. SLA said investigations found real personal information was included instead, an error being probed further [1]. SLA stated, "Preliminary investigations indicate that there was unauthorised access to a data set created for the sole purpose of vendor development and testing. This information should have been anonymised but was not. Investigations are ongoing to determine how this occurred" [1].
IBM has revoked access to the affected environment to block further unauthorised entry [1, 2]. SLA is coordinating with IBM, the Government Technology Agency of Singapore, and the Cyber Security Agency to investigate fully and implement remedial actions [1]. A police report has been filed and the Personal Data Protection Commission notified [1].
SLA is notifying affected individuals and advising vigilance against phishing attempts related to the breach, cautioning the public about emails or calls claiming to be from government agencies [4]. The agency said, "As investigations are ongoing, we advise members of the public to remain vigilant against phishing emails, phishing websites, text messages or telephone calls from parties claiming to represent government agencies or other organisations" [4].
The breach exposes a long-term lapse in data anonymisation practices. SLA and its partners must verify corrective steps and tighten controls to prevent similar incidents. The investigation will continue until a full understanding of the breach’s cause and scope is established [1].