Cyber Incident Victim: Eye & Retina Surgeons Singapore
Date:
Aug 2021
Location:
Singapore
Summary
A sophisticated ransomware attack compromised personal and clinical data of over 73,000 patients at a Singaporean eye clinic, exposing names, addresses, national ID numbers, contact details, and medical information without accessing financial data. The breach affected servers and terminals at one branch but did not disrupt clinical operations, with systems subsequently restored securely. Network segregation prevented compromise of cloud-based active medical records. The clinic notified authorities and is collaborating with cybersecurity and health agencies to investigate. While no evidence of data misuse exists, monitoring continues. The incident prompted national health authorities to reinforce cybersecurity vigilance across healthcare institutions, highlighting the effectiveness of segmented networks in limiting attack impact.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On August 6, 2021, Eye & Retina Surgeons Singapore experienced a sophisticated ransomware cyber-attack targeting its Camden Medical branch. The breach compromised servers and multiple computer terminals, resulting in unauthorized access to personal and clinical data of over 73,000 patients. Exposed information included patients’ full names, residential addresses, national identification card numbers, contact details, and clinical records. Financial data such as credit card or bank account details remained unaffected. The clinic confirmed no impact on its other branches or clinical operations, with IT systems subsequently restored securely. Attackers infiltrated administrative networks but failed to access active medical records due to network segregation, as patient care data resided on a separate cloud-based system.

Eye & Retina Surgeons initiated incident response protocols by progressively notifying affected patients starting August 26, 2021. The clinic reported the breach to Singapore’s Personal Data Protection Commission (PDPC) and the Singapore Computer Emergency Response Team (SingCERT). Its IT team collaborated with the Cybersecurity Agency of Singapore (CSA) and the Ministry of Health (MOH) to investigate the attack’s origins and perpetrators. Monitoring revealed no evidence of compromised data being published publicly. MOH confirmed the breached systems operated independently from its networks, including the National Electronic Health Record, and affirmed no prior similar incidents targeting its infrastructure. The ministry announced plans to reinforce cybersecurity advisories to licensed healthcare institutions, emphasizing system hardening and patient data protection. Eye & Retina Surgeons reiterated its commitment to patient confidentiality while maintaining segmented network defenses as a core security measure.
