DarkReading

Boustead Singapore Cyberattack Hits Overseas Unit


An overseas business unit of Boustead Singapore Limited was recently targeted by a cybersecurity incident, according to a filing made by the company on the Singapore Exchange.  

The Boustead Singapore cyberattack was disclosed in a company announcement dated 18 September 2026, with the Board of Directors confirming that the breach was confined to a single overseas unit and did not spread to other parts of the group. 

According to the filing, the affected business unit moved quickly once it became aware of the Boustead Singapore cyberattack, activating its business continuity procedures without delay. External cyber incident response specialists, legal advisers, and restoration providers were brought in to help manage the situation. As part of its containment strategy, the unit shut down and isolated the systems that had been compromised, aiming to prevent any further spread of the intrusion. 

Following these initial steps, the business unit carried out a comprehensive investigation into the cyberattack on Boustead Singapore. The findings were then reported to Singapore’s Personal Data Protection Commission, along with relevant authorities in other jurisdictions where the unit operates, in line with regulatory obligations tied to incidents of this nature. 

Recovery and Business Impact of the Boustead Singapore Cyberattack

Boustead Singapore stated that the business unit’s critical systems and data have since been fully restored using backups. The company noted that this recovery process resulted in no material disruption to the unit’s operations. Importantly, the group emphasized that the cyberattack on Boustead Singapore remained isolated to the one overseas unit, with no other divisions or entities within the group affected. 

As of the date of the announcement, Boustead said there had been no significant or material impact on the wider group’s business operations as a result of the incident. This distinction between the affected unit and the rest of the organization was a key point in the company’s disclosure, suggesting that the broader business continued to function without interruption. 

Independent Review Planned

In response to the Boustead Singapore cyberattack, the group announced plans to commission an independent cybersecurity review. This review is intended to identify areas where the company’s cybersecurity programme can be strengthened, with a particular focus on improving the resilience of its systems going forward. 

The original filing, signed by Company Secretary Tay Chee Wah on behalf of the Board, stated that the Group takes information security seriously and views the review as part of its broader response to the incident. 

Boustead Singapore’s disclosure follows a now-familiar pattern among listed companies facing cybersecurity incidents: swift containment, engagement of external specialists, regulatory notification, and a commitment to post-incident review. The filing did not specify which overseas unit was affected, the nature of the data potentially compromised, or the identity of the threat actors behind the intrusion. 

The announcement was made public through the Singapore Exchange, where Boustead Singapore is listed, ensuring shareholders and other stakeholders were informed of the cyberattack on Boustead Singapore and the company’s ongoing efforts to address it. The company has indicated that further updates may follow as the independent review progresses, though no timeline was provided for when that review might conclude or when its findings would be shared publicly. 



Source link