Source: The Hacker News

At the Comittee of Inquiry hearing yesterday (26 Sep) on the recent SingHealth cyber attack incident, witnesses said they were apprehensive about raising false alarms of the security incidents.

SingHealth’s cluster information security officer Wee Jia Huo testified that he understood “an incident must be confirmed before being reported” to the leader of the cyber-security governance department.

“Even a few failed attempts to log in would not be conclusive, as it could be a user who had forgotten his password trying to guess or remember his password,” Mr Wee said.

“If there were multiple persistent attempts to log in to the same server over a period of a few days, this would still not be conclusive, but it should, minimally, be investigated.”

Mr Wee also told COI that he relied solely on another cyber-security team headed by Ernest Tan for information.

“At all times, I will seek guidance from Ernest (and his team) because they are the subject matter experts. We do not escalate incidents if they are not confirmed and may be false positives,” Mr Wee said.

Data theft went unnoticed for 6 days

The cyber attack on SingHealth took place from June 27 to July 4, but it was only 6 days later on 10 Jul that IHiS deputy director Henry Arianto found out that 1.5 million medical data had been stolen.

Earlier, he had told others that the unusual database queries of July 4 “had returned zero results”. This was based on information from one of his team member, he said. He later decided to “double-check” the queries and found that they did indeed return results, which meant that the perpetrators must have seen and stolen the medical data. Alarm bell was then sounded and the Cyber Security Agency was informed.

He also told the committee that he receives but does not review the audit logs daily or regularly. One of his staff would just check the logs “randomly”.

Failed log-ins should have been monitored in the first place, he said.

The hearings continue.

Subscribe
Notify of
0 Comments
Inline Feedbacks
View all comments
You May Also Like

It might be time for Singapore Post to reassess their delivery and manpower system

One Singaporean, Andy Lau, had a bit of an awkward encounter with…

禁外国买家入住柔佛森林城

根据《彭博社》报导,马国不再允许外国人在柔佛新马发展经济特区—伊斯坎达特区的碧桂园森林城置产。 马国首相敦马斩钉截铁表示,该发展城镇资产将不会卖给外国人,也不会发签证给外国人来居住。 “我们反对是因为这个发展区块是建给外国人,而不是大马人,很多本国人都还没能力买组屋。” 不过,在今午的发布会上,他未有揭露具体如何执行禁止外国人在森林城置产的政策。 这个发展特区距离我国仅两公里,占地面积约有20平方公里,由碧桂园太平洋景公司发展,总投资规模约为一千亿美元。完成后的森林城预计可容纳70万人口。 森林城放眼吸引来自中国、印尼、泰国乃至杜拜的投资者或买家来置产。而马国过去曾推出第二家园计划,希望能吸引富有外国人持长期居留证在马居留。 事实上,自马国政权更迭以来,该计划即面对不确定因素。敦马在选举前曾多方抨击有关计划乃是中资计划,是前首相纳吉典当马国权益给中国的行为。 另一方面,森林城当局则回应彭博社,将进一步要求马国首相澄清上述论述。 在不久前,碧桂园创办人杨国强还曾亲自拜会敦马,并表示该集团将加大在马国投资规模,日后将着重加强现代农业和只能机器制造业的投资力度。

Use of “double negative” in CPF Board’s formal statements condemned by English experts

CPF Board has come out to strongly deny that the government had…