Eye & Retina Surgeons (ERS) Singapore officially disclosed that it has been a hit by a ransomware attack earlier this month potentially affecting 73,000 medical records of patients...

Continue reading
Eye & Retina Surgeons (ERS), a specialist ophthalmic medical clinic of Singapore, became the victim of a ransomware attack earlier this month potentially affecting 73,000 medical records of its patients. Ministry of Health, Singapore confirmed this breach of security occurred on the 6th of August in their report. However, the affected list of victims in this ransomware attack is yet to be revealed along with the type of data that was compromised in this attack. ERS has already reported this incident to the local police, the Personal Data Protection Commission, and the Computer Emergency Response Team of Singapore. While ERS has been officially directed by the Govt. of Singapore to coordinate with the Federal Cybersecurity Agency in order to implement necessary mitigation actions and strengthen the online security defenses.
_“The government takes a serious view of any cyber-attack, illegal access of data, or action that compromises the integrity, confidentiality, and availability of data and IT systems in Singapore, ”_ states in the official statement.
Moreover, the official statement extended by citing that laws ordering licensed medical institutions are required to enforce _“adequate safeguards”_ to insure critical healthcare details against accidental or unlawful loss, modification or destruction, or unauthorized access, disclosure, copying, use, or modification.
Besides, it goes on emphasizing that _“periodically monitor and evaluate such safeguards in place to ensure that they are effective and being complied with by the persons involved in handling medical records”_.
Additionally: _“Following this incident, MOH will be reminding all its licensed healthcare institutions to remain vigilant, strengthen their cybersecurity posture, and ensure the security and integrity of their IT assets, systems, and patient data.”_
The newly enacted data breach law of Singapore in 2021 highlights that _“notifiable”_ data breaches must be reported to the data protection officer.
In case this may seem vague for any data breach the criteria to be reported has to either cause significant harm to those victims whose information has been leaked out in the wild and/or amount beyond 500 in headcount.
And in any case, Cybersecurity Commissioner must be reported on priority by the impacted organization at least before three calendar days. Penalties could include a fine of up to 10% of an organization’s annual turnover or SGD 1 million ($742,000), whichever is highest.

Hugging Face reveals a July 2026 security incident involving dataset pipeline exploits, credential exposure, lateral movement, and enhanced AI security controls