PCF Sparkletots' student management system vendor LittleLives experienced unauthorized access that may have exposed data on students and parents, the early childhood education provider said [1, 2]. Potentially affected information includes pupil names, identification details, class and centre assignment, parent or guardian contact information, invoice data, and payment status or fee descriptions [1, 2].
PCF Sparkletots said the breach has been contained, and there is currently no confirmation that any data was viewed, downloaded, or misused. A spokesperson said, "At this stage, there is no confirmation that any data has been viewed, downloaded or misused." [2]
The incident was reported to Singapore’s Personal Data Protection Commission (PDPC) and the police. PCF Sparkletots is cooperating closely with LittleLives, the PDPC, the police, and the Early Childhood Development Agency (ECDA) on the investigation [1, 2]. The spokesperson added, "We take our accountability for data protection seriously. We are working closely with LittleLives and relevant parties as part of a thorough investigation, and will strengthen security measures and assess any potential impact." [2]
Parents were alerted by letter on June 1 that their data might be involved and have been advised to watch for suspicious emails, calls, or messages, especially those related to billing or payment information [1, 2]. On June 2, PCF Sparkletots and the PDPC confirmed that the unauthorized access was contained and investigations into the full scope and impact of the breach are ongoing [2]. No details have been announced regarding the responsible party or the exact timeline of the intrusion [2].
Authorities and PCF Sparkletots continue to work on the probe as of today, with no further disclosures reported.