
The Singapore Land Authority announced that it was impacted by a major cybersecurity breach stemming from a security incident at its vendor, IBM.
The Singapore Land Authority oversees Singapore’s land resources, including land records, geospatial data, and property services. IBM supports the agency as a technology vendor, providing managed IT services and maintaining parts of its IT infrastructure.
In a data security incident notice published on its website, the Singapore Land Authority said IBM had recently notified it of unauthorised access to an IBM-managed cloud environment. As the agency’s technology vendor, IBM supports and maintains the Singapore Titles Automated Registration System (STARS) and eLodgment System (ELS), while also managing their development and systems integration testing environments.
The agency immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.
Preliminary investigations found that unauthorised access involved a development and testing dataset created in 1998. Although it was meant to contain only mock and anonymised data, SLA said it also included the names, NRIC numbers, and former property addresses of about 70,000 individuals. The agency is investigating how the data was not anonymised.
“The affected environment managed by the vendor is distinct and separate from SLA’s operational systems. There is no connection or compromise to the live systems used for operations of STARS, ELS or any other SLA systems. Property ownership and lodgment records in STARS and ELS remain secure and unaffected,” SLA said.
IBM has revoked access to the affected development and testing environment to prevent further unauthorised access. As a precaution, the Singapore Land Authority has identified the individuals whose information was included in the compromised dataset and has started notifying them.
The agency is working with IBM, the Government Technology Agency of Singapore, and the Cyber Security Agency of Singapore to investigate the incident, determine its scope, and implement appropriate remedial measures. It has also notified law enforcement authorities and the Personal Data Protection Commission about the incident.
“As investigations are on-going, we advise members of the public to remain vigilant against phishing emails, phishing websites, text messages, or telephone calls, from parties claiming to represent Government agencies or other organisationS,” SLA added.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543