Quick response may have helped, but how would the new Cybersecurity Code of Practice for critical infrastructure operators impact SIMBA?
SIMBA discovered a data breach incident on 24th September 2026. While there is no indication that any data has been maliciously misused, the Singapore mobile operator is treating this incident seriously and has swiftly resolved it swiftly.
Based on investigations to date, the data that was included in the breach included names, identity card numbers, dates of birth, mobile numbers, and email addresses belonging to 23,549 individual customers who had registered for SIMBA’s services. No credit card or bank account information is at risk.
SIMBA has taken immediate and appropriate actions to review existing security measures to protect core infrastructure and systems, and is working closely with the Personal Data Protection Commission (PDPC) of Singapore in investigating the breach.
The company is also progressively notifying affected customers via email. This process is expected to be completed within the next week.
Last year’s telco industry breach
Last year, it was disclosed that all four of Singapore’s major telcos were the targets of a cyber-attack by UNC3886. There has been no evidence so far that any sensitive customer data was stolen, said authorities.
In one instance, the attackers were able to gain access to a few critical systems but did not get far enough to have been able to disrupt services or to access or steal sensitive customer data from the telcos Singtel, M1, StarHub and Simba.
The discovery of the breach last year triggered Operation Cyber Guardian, the largest coordinated cybersecurity operation in Singapore’s history, involving more than 100 specialists from six government agencies:
- The Cybersecurity Agency of Singapore (CSA)
- The Infocomm and Media Development Authority (IMDA)
- The Centre for Strategic Infocomm Technologies (CSIT)
- The Singapore Armed Forces Digital and Intelligence Service
- The Internal Security Department
- GovTech
Any regulatory penalty?
Last year’s breach had prompted a significant tightening of cybersecurity rules for critical infrastructure operators in Singapore. The Cybersecurity Code of Practice, which includes new rules mandating homegrown intrusion detection tools and board-level accountability, was introduced in response to the breach.
These new measures are part of a broader effort to protect Singapore’s critical infrastructure from sophisticated cyber threats, including state-sponsored espionage groups. The updated rules are expected to take effect in stages through 2027, with a focus on enhancing the ability of boards to understand and manage their organizations’ cyber recovery posture.
SIMBA may face regulatory scrutiny under PDPA and the new Cybersecurity Code of Practice, including penalties such as fines. But that remains to be seen, as any penalty may be moderated due to its prompt action and the absence of malicious exploitation of data.
