← Case Files · The Breach Files
SingHealth, 2018: 1.5 million patients, taken on the way to one of them
- People affected
- 1.5 million patients' personal particulars; about 160,000 patients' outpatient dispensed-medicine records
- When it happened
- Initial compromise around August 2017; bulk exfiltration 27 June – 4 July 2018
- Made public
- 20 July 2018
- How they got in
- A compromised front-end workstation, then lateral movement to a privileged account and queries against the electronic medical records database
- Attributed to
- A skilled and well-resourced advanced persistent threat group; the government did not publicly name a state
- What it cost
- S$750,000 fine for the health IT agency and S$250,000 for SingHealth; a public Committee of Inquiry and sixteen recommendations
What was exposed: Names · National registration identity card numbers · Addresses · Genders · Races · Dates of birth · Outpatient dispensed medicines
On 20 July 2018 Singapore announced that the personal records of 1.5 million people, a quarter of the country's population, had been taken from its largest healthcare group. The inquiry that followed established something rarer than the number: the attackers had been looking for one patient in particular, and they found him.
What happened
SingHealth operates a large share of Singapore's public hospitals and outpatient clinics. Its records sit in a system called SCM, the electronic medical records platform administered not by the hospitals themselves but by IHiS, the central IT agency for the country's public healthcare sector.
The intrusion began around August 2017 with the compromise of a front-end workstation, most likely through a phishing email. From there the attackers did what capable intruders do: they stayed quiet and moved sideways. Over the following months they harvested credentials, established footholds on additional machines, and worked towards accounts with enough privilege to query the medical records database directly. By mid-2018 they had reached a server that could do exactly that.
Between 27 June and 4 July 2018 they ran the queries that took the data: demographic records for 1.5 million patients, and outpatient dispensed-medicine records for around 160,000 of them. Diagnoses and clinical notes were not taken. The pattern of queries showed why. The Committee of Inquiry found that the records of Prime Minister Lee Hsien Loong had been specifically and repeatedly targeted.
Who they were actually after
Almost every case file in this archive describes an opportunistic crime. Somebody found a way in, took whatever was reachable, and sold it. The value was in volume, and the victims were interchangeable.
This is the other kind. The 1.5 million records were not the objective; they were what came out of the database alongside the records that were. A prescription history is a medical history by inference, what someone is treated for, how long they have been treated, whether the treatment changed. For a head of government that is intelligence, and the people who go looking for it are not motivated by resale value.
The distinction matters for anyone reading this to decide what to do about their own systems. Defences calibrated against opportunists assume the attacker will move on when the effort exceeds the payoff. An actor pursuing one specific person will not move on, will spend months, and will accept a great deal of noise to get there. The same controls are involved, but the assumption that an attacker gives up is not available.
The weaknesses were ordinary. The inquiry did not find an exotic capability. It found administrative accounts with weak and reused passwords, software left unpatched, a network that permitted movement between segments it should not have, and, most consequentially, staff who noticed unusual database activity and did not escalate it, in some cases for weeks. A sophisticated attacker does not need sophisticated failures. It needs the ordinary ones to still be there, and they usually are.
The findings nobody redacted
What makes this incident unusually valuable is the Committee of Inquiry report published in January 2019. Singapore held public hearings and published findings that name specific technical weaknesses and specific human decisions, including the periods during which anomalies were visible to staff and went unreported.
That candour is almost unheard of. The normal output of a government-linked breach is a short statement, a regulatory finding written at a high level of abstraction, and a set of lessons phrased so generally that nobody can act on them. The SingHealth report instead sets out how the detection actually failed: not because no one saw anything, but because the people who saw things did not have a clear route to raise them, did not recognise the significance, or expected somebody else to have done it.
The report's recommendations followed from that, and they are notable for how much of their weight falls on process rather than product. Enhanced security monitoring, yes, but also clearer incident reporting obligations, defined escalation paths with named responsibilities, and the expectation that an unexplained anomaly is reported as an anomaly rather than resolved privately by whoever noticed it.
The timeline
- August 2017: A front-end workstation is compromised; the attackers begin moving laterally.
- Late 2017 – mid 2018: Credentials are harvested and privileged access is obtained; activity is intermittently visible but not escalated.
- 27 June – 4 July 2018: Bulk queries extract 1.5 million patient records and around 160,000 medicine records.
- 4 July 2018: Unusual activity is confirmed by IHiS administrators and the queries are stopped.
- 10 July 2018: The incident is escalated to senior management and national agencies.
- 20 July 2018: The breach is announced publicly, including that the Prime Minister was specifically targeted.
- January 2019: The Committee of Inquiry publishes its report with sixteen recommendations; the data protection regulator fines IHiS S$750,000 and SingHealth S$250,000.
What it changed
Singapore's response went further than most jurisdictions would consider proportionate. Public healthcare systems were placed under internet surfing separation, removing general web access from work computers that handle patient data, on the reasoning that the initial compromise came through ordinary browsing and email, and that severing that path is worth the inconvenience it causes.
It is a genuinely contested trade-off, and worth understanding rather than admiring or dismissing. Isolating clinical workstations from the internet removes an enormous share of the attack surface, and it also makes clinicians' work slower and pushes some of it onto personal devices that nobody is monitoring. Singapore judged the trade worth making for a national health system after a state-grade intrusion. That judgement does not transfer automatically to a dental practice, and the report does not pretend it does.
The fines mattered less than the allocation of them. The larger penalty went to IHiS, the IT agency, not to SingHealth, the healthcare provider, an explicit finding that responsibility for securing the data sat with the organisation actually operating the systems. Where care providers outsource their infrastructure to a central agency or a vendor, that allocation is the precedent worth knowing about.
If you were a SingHealth patient
The exposed set is demographic and durable: name, identity card number, address, race, gender and date of birth, plus dispensed medicines for a subset. None of it can be changed. An NRIC number in particular is a lifelong identifier, which is why the years after this breach saw sustained official effort to discourage organisations from treating it as proof of identity rather than merely as a reference number.
The realistic risk is impersonation rather than fraud on an account. A caller who already knows your identity card number, your address and your date of birth passes the informal test most people apply to decide whether somebody is genuine, and for the smaller group whose medication records were taken, a caller who can also reference a real prescription is more convincing still. No clinic, insurer or government agency resolves anything by asking you to confirm a one-time code. Hang up and dial a number you already had.
Questions people ask
What was actually taken?
Demographic records for about 1.5 million people who had visited SingHealth outpatient clinics over a seven-year period: name, national identity card number, address, gender, race and date of birth. For roughly 160,000 of those patients, records of dispensed outpatient medicines were also taken. Diagnoses, doctors' notes and test results were not, the attackers queried a specific database in a specific way, and what they took reflects that.
Was the Prime Minister specifically targeted?
Yes. The Committee of Inquiry found that the records of Prime Minister Lee Hsien Loong were repeatedly and specifically targeted, along with those of a number of other individuals. That finding is what separates this case from an ordinary healthcare breach: the bulk data was not the objective but the by-product of reaching one person's prescription history.
How did the attackers get in?
Through a front-end workstation, most likely via a phishing email carrying malware. From that foothold they moved laterally through the network over a period of months, obtained credentials for privileged accounts, and eventually reached a server from which they could query the electronic medical records database directly. It is the standard shape of a targeted intrusion: the entry point is mundane, and the work happens afterwards.
Why were the failings made public in such detail?
Singapore convened a Committee of Inquiry with public hearings, and its report names specific technical weaknesses and specific human decisions, including administrative accounts with weak passwords, unpatched software, and staff who saw anomalies and did not escalate them. Very few countries publish that level of detail about a government-linked breach. The report is more useful to defenders than almost any vendor incident write-up, precisely because it does not protect anyone.
Sources
- Public Report of the Committee of Inquiry into the cyber attack on SingHealth's patient database, January 2019
- Personal Data Protection Commission of Singapore, decisions concerning SingHealth and Integrated Health Information Systems, January 2019
- Ministry of Health and Ministry of Communications and Information statements, July 2018
- Cyber Security Agency of Singapore, post-incident measures for the public healthcare sector
Read next
Case files are written from the public record: regulatory findings, court filings, company disclosures and contemporaneous reporting, cited above. Figures are the ones the organisation or its regulator finally settled on, which is often not the number first reported, where that differs, the page says so. Disputed accounts are marked as disputed rather than resolved in either direction.