A file containing personal data from 6,541 accountants in Singapore was “inadvertently” sent to multiple organizations in a security incident that was only revealed months after a review was conducted. The incident exposed personal information including names, national identification numbers, dates of birth and employment information.
The incident occurred under the supervision of the Singapore Accountability Commission (SAC), an agency under the Ministry of Finance, which said on Friday that 41 people in 22 organisations had received the file containing the personal data.
The details were sent in multiple emails between June 12 and October 22 this year to the 22 organisations, which included 21 Accredited Training Organisations and one vendor. The email was sent to inform them of “administrative matters”, the SAC said.

The email was sent to new Accredited Training Organizations to inform them of various administrative issues such as the logos to be used. There are more than 300 such organizations in the country.
The individuals concerned were past and present candidates in the Singapore Chartered Accountants (SCA) programme, as well as staff of the organisations and other executives involved in the management of the qualification scheme before 17 May 2019.
The SAC said it discovered the incident on November 7 after implementing a “new data protection filter” as part of the recommendations of the Public Data Security Audit Committee. Four days later, on November 11, the Committee contacted the 22 organizations that received the file “to request that they delete the data” as well as to confirm whether the file had been passed on to other parties.
To date, all 22 companies have said they have deleted the file, including any transmitted data. The SAC, however, did not disclose whether or how many other parties had received or accessed the data.
He said that all affected individuals were informed, on November 22, of the “involuntary disclosure.” He added that he had notified the Personal Data Protection Commission about the incident.
“SAC takes this Incident seriously and deeply regrets this mistake. SAC will establish a team to review the incident and make any necessary recommendations,” he said, adding that this team will consist of members of the SAC board of directors as well as the Office of Smart Nations and Digital Government and the Department of Public Service.
The Singapore government said in July that its agencies would roll out several new “technical measures” for existing and new systems, such as automatic detection of emails containing sensitive data and stronger file encryption . These were part of the “interim” recommendations deemed necessary after a review of the public sector’s cybersecurity infrastructure and policies , which was carried out after a series of data breaches involving government entities.
A committee set up to assess how the government will secure citizens' data has highlighted the need to strengthen the security amid growing threats. It added that government systems were increasingly complex and there was a growing demand to use data to facilitate digital services for the public.
However, the Singaporean government argued that the public sector should be excluded from the country's Privacy Act due to "fundamental differences" in how organizations , which required a "different approach" to protecting personal data compared to the private sector.
