2026 Singapore Land Authority — IBM vendor test data; 70K NRICs exposed (Jul)
Data compromised
Names, NRIC (national ID) numbers, and then-current property addresses for about 70,000 individuals in a 1998-origin test dataset; live STARS/ELS operational property records not compromised per SLA
Technical writeup
Verified incident — disclosed July 3, 2026. The Singapore Land Authority (SLA) reported that IBM, its vendor for the Singapore Titles Automated Registration System (STARS) and eLodgment System (ELS), detected unauthorized access to a development and integration testing environment separate from live operational systems. Preliminary investigation found a dataset created in 1998 and updated over time that was intended to hold mock anonymised property records but actually contained names, NRIC numbers, and then property addresses for about 70,000 people. SLA began notifying affected individuals; IBM revoked access to the affected environment. Live STARS/ELS property ownership and lodgment records were not compromised per SLA's statement.
Root cause
Unauthorized access to IBM-managed STARS/eLodgment development and testing dataset that should have been anonymised but contained real NRIC numbers and addresses