Menu
Browse

Cyber Incident Victim: Eye & Retina Surgeons Singapore

Date:

Aug 2021

Location:

Singapore

Summary

A sophisticated ransomware attack compromised personal and clinical data of over 73,000 patients at a Singaporean eye clinic, exposing names, addresses, national ID numbers, contact details, and medical information without accessing financial data. The breach affected servers and terminals at one branch but did not disrupt clinical operations, with systems subsequently restored securely. Network segregation prevented compromise of cloud-based active medical records. The clinic notified authorities and is collaborating with cybersecurity and health agencies to investigate. While no evidence of data misuse exists, monitoring continues. The incident prompted national health authorities to reinforce cybersecurity vigilance across healthcare institutions, highlighting the effectiveness of segmented networks in limiting attack impact.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On August 6, 2021, Eye & Retina Surgeons Singapore experienced a sophisticated ransomware cyber-attack targeting its Camden Medical branch. The breach compromised servers and multiple computer terminals, resulting in unauthorized access to personal and clinical data of over 73,000 patients. Exposed information included patients’ full names, residential addresses, national identification card numbers, contact details, and clinical records. Financial data such as credit card or bank account details remained unaffected. The clinic confirmed no impact on its other branches or clinical operations, with IT systems subsequently restored securely. Attackers infiltrated administrative networks but failed to access active medical records due to network segregation, as patient care data resided on a separate cloud-based system.

Cyber Incident Image

Eye & Retina Surgeons initiated incident response protocols by progressively notifying affected patients starting August 26, 2021. The clinic reported the breach to Singapore’s Personal Data Protection Commission (PDPC) and the Singapore Computer Emergency Response Team (SingCERT). Its IT team collaborated with the Cybersecurity Agency of Singapore (CSA) and the Ministry of Health (MOH) to investigate the attack’s origins and perpetrators. Monitoring revealed no evidence of compromised data being published publicly. MOH confirmed the breached systems operated independently from its networks, including the National Electronic Health Record, and affirmed no prior similar incidents targeting its infrastructure. The ministry announced plans to reinforce cybersecurity advisories to licensed healthcare institutions, emphasizing system hardening and patient data protection. Eye & Retina Surgeons reiterated its commitment to patient confidentiality while maintaining segmented network defenses as a core security measure.

Sources
Sources available to members
1 source