CSIDB logo
Incident

ShopBack

Incident posture

Attack window
Sep 2020
Location
Singapore
Status
Historical
CIA posture
Available to members
Updated
2025-10-28 00:00

Linked entities

Victim
ShopBack
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Sep 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A Singapore-based e-commerce cashback platform experienced unauthorized access to customer personal data, prompting an investigation by local authorities. The company publicly disclosed the incident involving compromised user information, though specific details regarding the scope or nature of the accessed data were not provided in the initial announcement. Concurrently, a separate breach at another regional hospitality startup was reported, though this incident reportedly did not involve sensitive financial data or passwords based on preliminary assessments. Both incidents drew regulatory attention and public disclosures within a short timeframe.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

In September 2020, Singapore-based e-commerce cashback platform ShopBack disclosed a data breach involving unauthorized access to customer personal data. The incident came to public attention when ShopBack announced the breach, prompting immediate investigations by local authorities. While the exact date of the intrusion remains unspecified in public reports, ShopBack's disclosure occurred around mid-September 2020, with media coverage appearing by September 25. The company confirmed that attackers had compromised customer information but did not specify the number of affected accounts or the precise timeline of unauthorized access. ShopBack initiated incident response procedures upon detection, though the specific method of discovery remains undisclosed. The breach investigation involved coordination with relevant Singaporean regulatory bodies as part of standard breach response protocols for data protection incidents.

The confirmed impact involved exposure of customer personal data, though financial information such as credit card details and passwords reportedly remained uncompromised according to initial assessments. ShopBack issued public notifications about the breach through official channels, advising customers to remain vigilant while emphasizing that core financial systems appeared unaffected. Concurrently with ShopBack's incident, Singapore-based hospitality startup RedDoorz separately reported a database breach during the same September timeframe, though this constituted a distinct event from the ShopBack intrusion. Both incidents drew attention to cybersecurity vulnerabilities in Singapore's digital commerce sector during this period. ShopBack maintained ongoing communication with authorities throughout the investigation process while working to restore normal operations following containment of the breach.

Sources

Sources available to members: 1 source.

CSIDB