Full Report
Personal information of more than 23,500 Simba customers has been compromised in a data breach, the telco said in a statement on Sept 25. The data involved included names, identity card numbers, dates of birth, mobile numbers and e-mail addresses belonging to 23,549 people who had registered for Simba’s services. No credit card or bank account information is at risk, said the telco, adding that it had no information that any of the leaked data has been maliciously misused. It is unclear whether the leak affected its mobile or broadband customers, or both. Simba has nearly 1.5 million active mobile subscribers as at July 31, along with 62,000 fibre broadband subscribers, according to a recent report by The Business Times. The data breach was discovered on Sept 24 and Simba “swiftly resolved it”, the telco said.
Analysis Summary
# Incident Report: Simba Data Breach (Sept 2026)
## Executive Summary
Simba (formerly TPG Singapore) suffered a data breach involving the personal information of 23,549 customers. The incident was detected on September 24, 2026, and reportedly resolved within 24 hours. While sensitive PII was compromised, no financial data was affected, and the telco reports no evidence of malicious misuse at this time.
## Incident Details
- **Discovery Date:** September 24, 2026
- **Incident Date:** September 2026 (exact start date undisclosed)
- **Affected Organization:** Simba (Telco)
- **Sector:** Telecommunications
- **Geography:** Singapore
## Timeline of Events
### Initial Access
- **Date/Time:** Undisclosed
- **Vector:** Not publicly disclosed by the organization
- **Details:** The telco has not specified whether the entry point was a system vulnerability, misconfiguration, or credential compromise.
### Lateral Movement
- **Details:** No specific technical details regarding internal movement were provided in the public statement.
### Data Exfiltration/Impact
- **Exfiltrated Data:** PII of 23,549 customers, including full names, identity card numbers (NRIC/FIN), dates of birth, mobile numbers, and email addresses.
- **Excluded Data:** Credit card and bank account information remained secure.
### Detection & Response
- **Discovery:** September 24, 2026.
- **Response Actions:** The issue was "swiftly resolved" by September 25. Simba initiated a security review of core infrastructure, contacted the Personal Data Protection Commission (PDPC), and began notifying affected individuals.
## Attack Methodology
*Note: Due to limited public disclosure, specific MITRE ATT&CK mappings are categorized as "Undisclosed" where information was withheld for security reasons.*
- **Initial Access:** Undisclosed
- **Persistence:** Undisclosed
- **Privilege Escalation:** Undisclosed
- **Defense Evasion:** Undisclosed
- **Credential Access:** Undisclosed
- **Discovery:** Undisclosed
- **Lateral Movement:** Undisclosed
- **Collection:** Automated extraction of customer database records.
- **Exfiltration:** Unauthorized transfer of PII for 23,549 records.
- **Impact:** Data breach resulting in exposure of sensitive customer identity markers.
## Impact Assessment
- **Financial:** No direct loss of customer funds or bank data reported; potential for regulatory fines from the PDPC.
- **Data Breach:** Compromise of 23,549 customer records containing high-value identity data.
- **Operational:** Swift resolution reported with minimal impact on service availability.
- **Reputational:** Public disclosure required for a significant subscriber base (approx. 1.5M mobile users); potential trust erosion.
## Indicators of Compromise
- **Network indicators:** None disclosed to the public.
- **File indicators:** None disclosed to the public.
- **Behavioral indicators:** Unusual access patterns to customer registration databases (implied).
## Response Actions
- **Containment:** Vulnerability patched or access closed by Sept 25.
- **Eradication:** Review of existing security measures to protect core infrastructure.
- **Recovery:** Customer notification via email; cooperation with Singapore authorities (PDPC and ST).
## Lessons Learned
- **Key Takeaways:** Even with a resolution time of under 24 hours, over 23,000 records were successfully exfiltrated, highlighting the need for faster automated detection.
- **Improvement Areas:** Need for clearer transparency regarding whether mobile or broadband systems were the primary target to better inform customer risk assessments.
## Recommendations
- **Identity Protection:** Affected customers should be advised to monitor for phishing attempts using their leaked NRIC and mobile details.
- **Zero Trust Architecture:** Implement stricter micro-segmentation around databases containing NRIC and PII data to prevent bulk exfiltration.
- **Encryption:** Ensure all PII at rest is encrypted so that even if exfiltrated, the data remains unreadable without the specific keys.