{"id":777033760,"date":"2025-10-28T08:40:45","date_gmt":"2025-10-28T11:40:45","guid":{"rendered":"https:\/\/focusgn.com\/asia-pacific\/?p=777033760"},"modified":"2026-04-21T17:45:02","modified_gmt":"2026-04-21T20:45:02","slug":"marina-bay-sands-fined-over-major-2023-data-breach","status":"publish","type":"post","link":"https:\/\/focusgn.com\/asia-pacific\/marina-bay-sands-fined-over-major-2023-data-breach","title":{"rendered":"Marina Bay Sands fined over major 2023 data breach"},"content":{"rendered":"\n
Singapore\u2019s data protection watchdog ruled that the casino resort failed to take \u201creasonable security measures\u201d.<\/p>\n\n\n\n\n\n\n\n
Singapore.- The integrated resort Marina Bay Sands<\/strong> (MBS) has been fined SGD 315,000 (US$243,000) by the Personal Data Protection Commission<\/strong> (PDPC) for a 2023 data breach <\/strong>that compromised the personal information of more than 665,000 customers. The incident, discovered in October 2023, involved unauthorised access by unknown actors who extracted names, contact details and other personal identifiers from the customer database. <\/p>\n\n\n\n The breach affected members of MBS\u2019s LifeStyle rewards programme, and the stolen data was later found for sale on the dark web. The company said its Sands Rewards Club casino data was not impacted.<\/p>\n\n\n\n According to the PDPC, the breach occurred during a large-scale software migration in March 2023, when a technical identifier was omitted. The error, stemming from a failure to properly configure APIs, left personal data unprotected for six months.<\/p>\n\n\n\n Investigators found that the migration process had been handled by a single employee without any secondary checks, which the regulator described as a \u201cnegligent contravention\u201d of Singapore\u2019s data protection laws. The fine, one of the largest imposed under Singapore\u2019s updated data protection framework, accounted for the scale of the breach and the sensitivity of the information exposed. The PDPC noted MBS\u2019s voluntary admission of liability and prompt remediation efforts, including the immediate reactivation of security measures once the breach was detected.<\/p>\n\n\n