
Singapore’s Mustafa group, known for its bustling shopping mall in Little India, has fallen victim to a significant data breach, sparking a probe by the country’s data protection agency. The leak, reportedly revealed on April 25, involves extensive personal information of customers and employees.
A cyber attacker operating on the notorious hacker forum BreachForums claimed responsibility for the breach, alleging the theft of 180GB of sensitive data from the Mustafa group. According to local media sources, this data includes full names, Identity Card numbers, and home addresses. The Straits Times reported that the forum has recently been shut down, and the leaked files have since been removed.
The Personal Data Protection Commission (PDPC) confirmed its investigation into the incident and contacted Mustafa for further details. In response, a Mustafa spokesperson stated that the group has enlisted external cybersecurity experts and auditors to review their IT systems comprehensively.
Ethical-Empire.com, a cybersecurity-focused website, identified the attacker as “GHOSTR,” who managed to breach Mustafa’s poorly secured server network between March 20 and 31. The breach affected Mustafa’s retail and financial operations and other businesses, including restaurants, travel services, and visa applications.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543