photo: businesstimes.com.sg

Last Friday (20 Jul), when it was reported that cyber hackers have broken into the computer systems of SingHealth and stolen the personal particulars of 1.5 million patients, including IC numbers, Singapore Cyber Security Czar BG (NS) David Koh told everyone that the stolen information are only “basic demographic data”.

“We are watching to see if anything appears on the Internet both in the open and in some of the less well-known websites,” he said.

“But considering the type of data that’s been exfiltrated (i.e, unauthorized transfer of data), it is – from our professional experience – unlikely that these will appear, because there is no strong commercial value to these types of data.”

In other words, he is telling the 1.5 million patients not to worry about the theft of their personal data, which includes their name, IC number, address, gender, race and date of birth. They are deemed to be of “no strong commercial value” by the Czar, who was amongst the youngest to be promoted to the rank of Brigadier General at 41 when he was in the SAF.

MAS takes action despite Cyber Security Czar says stolen data has “no strong commercial value”

Yesterday (24 Jul), the Monetary Authority of Singapore (MAS) released a public notice, saying that it has issued a circular to all financial institutions, directing them to tighten their customer verification processes, following the recent cyber attack at SingHealth.

For access to online financial services, banks in Singapore have already put in place the two-factor authentication (e.g. PIN and One-Time-Password) at login to identify customers. Banks are also required to implement an additional layer of control to authorise high-risk transactions like opening of beneficial accounts, registration of third party payee details and revision of funds transfer limits, MAS said.

“However, to address any risk that the information stolen from SingHealth may be used by fraudsters to impersonate customers and perform unauthorised financial transactions, MAS has directed financial institutions to tighten their customer verification processes,” it added.

“Specifically, with immediate effect, all financial institutions should not rely solely on the types of information stolen (name, NRIC number, address, gender, race, and date of birth) for customer verification. Additional information must be used for verification before undertaking transactions for the customer.”

“This may include, for instance, One-Time Password, PIN, biometrics, last transaction date or amount, etc,” it said.

MAS’ own Chief Cyber Security Officer takes a serious view on personal data being stolen

MAS has also directed all financial institutions to conduct a risk assessment of the impact of the SingHealth incident on their existing control measures for financial services offered to customers, including transaction and inquiry functions.

“Financial institutions are to take immediate steps to mitigate any risks that might arise from the misuse of the compromised information. MAS will engage financial institutions on their risk assessments and mitigation steps,” MAS said.

Contrary to Cyber Security Czar BG (NS) Koh’s nonchalant attitude towards the stolen data at SingHealth, Tan Yeow Seng, MAS’ Chief Cyber Security Officer said, “MAS will work closely with the financial institutions to ensure that robust cyber defences are in place so that customers can carry out online financial transactions with confidence.”

“But customers must also play their part. They must safeguard their passwords and practise good cyber hygiene. If they suspect any fraudulent transactions in their accounts, they should notify their banks immediately,” Mr Tan added.

Subscribe
Notify of
0 Comments
Inline Feedbacks
View all comments
You May Also Like

12 Indonesians arrested for immigration offences and peddling of duty-unpaid cigarettes

Immigration & Checkpoints Authority (ICA) arrested twelve male Indonesians, aged between 18…

93万户组屋将获 60元至100元水电费回扣

约93万户组屋即将在本月获得60元至100元的水电费回扣,以抵消他们部分的水电费。 水电费回扣,属于消费税补助券之一,每个三月发放一次,以此协助家庭抵消部分水电费,降低开支。 文告表示,将根据不同房型,获得不同价格的回扣,如一房式或两房式单位将获得100元水电费补助、三房式则会有90元补助,四房式则是80元,五房式则有70元,三代同堂或其他大型组屋则享有60元回扣。 若其房地产超过一个将无法享有水电费回扣。 日前,新加坡能源公司宣布,家庭电价将上调至3.5巴仙,即每千瓦0.81元。 举例而言,住在一房式的家庭,每月平均账单可增加1.02元,而五房式也可能会出现上涨3.20元的电费,形成最新电价自2014年以来,达到最高水平。 此外,城市煤气周一也宣布,今年第一季度,家庭天然气价格将调整至4.22巴仙,即每千瓦0.76元。 政府也推出水电费回扣(U-Save)协助民众抵消水电费。据报道,政府为水电费回扣拨出的总开支,今年预计达3亿元。 文告也指出,水电费回扣相当重要,至少能够帮助一房式或二房式单位的居民抵消平均三至四个月的水电费;而三房式和四房式的居民则可以抵消一至两个月的水电费。

Netizens outraged after pet owners reportedly put their dog to sleep to avoid risking their newborn baby from being bitten

A recent story involving a husband and wife allegedly euthanising their pet…

柔州务大臣登新马海域边界执勤船只

柔佛州务大臣奥斯曼沙比安,于昨日登上马国浮标船MV PEDOMAN慰问船员。 奥斯曼在脸书分享,他聆听船长解说新马争议性边界事项,也感谢船员的付出和牺牲,“捍卫海域”。 《联合早报》报导指柔大臣此举“具一定挑衅意味”,可能影响新马解决领海纠纷的努力。 不过,根据马国官媒马新社报导,马国海事局驳斥本周三一则网络报导,指马国船只目前位处新加坡海域。 马海事局企业通讯主任优斯南指出,由于需要重新补给,原本停泊在原有海域的北极星号(Polaris)航标船已开往位于柔佛丹绒巴勒斯的海事局港口。 马坚称Pedoman仍在柔港口界限内 北极星号的停泊岗位,则由航标船Pedoman 填补,但该国海事局仍坚称,船只的方位仍处在柔佛港口界限内。 优斯南称,Pedoman肩负监督柔佛港口界限内海上交通和安全的责任。 马国在去年10月25日颁佈修改柔佛新山港口海域界限宪报,我国则指柔佛港口海域界限侵犯大士一带领海范围,而马国船只也多次侵入大士水域,违反国际法,与此同时在12月6日宣布扩大大士一带港口海域界限。 而在本月8日,马国外交部长到访我国,与外长维文商讨,双方同意设立海事工作团队,研究和商讨海域问题的法律和运作事宜,并缓解局势,为进一步的谈判建立基础。有关海事团队的研究报告会在两个月内提呈给部长。…