Time since the screen locked
00:00:00
Patient records affected
0
Told 19 days later
Reconstruction · Singapore, August 2021
Specialist clinic · Two sites
The Morning

73,466 patients' data remained locked in the clinic's system.

A specialist eye clinic in Singapore. The system holding every patient record has been locked since first thing this morning, and there is a full day of appointments booked. Four decisions today. You make each one before you find out what it cost.
You are in the owner's shoes. What do you do?
What was on that one screen

You cannot open a single patient file. Neither can the backup.

patients connection lost
Field
Contents
Rows
Status
All fields
73,466
No access
Reading 6 fields
The patient count and the categories of data are as reported. The order they are listed in, and the wording describing each, are written for the simulation. No source states what was on any individual screen.
None of this was unusual for a clinic to hold. Every field on that list existed because somebody needed treating.
4 decisions
You make the calls the owner made, in the order he made them.
What the clinic had
Antivirus on every machine
A password on each one
An IT vendor on call
What it did not
A written security policy
Any staff training
A plan for this morning
Written for the simulation. The public record says nothing about this clinic's controls, either way.
Decision 01 / 04 · In transit · 07:34

Your receptionist has just unlocked the front desk computer. The screen is black with red text asking for money. The first patient is due in sixty-eight minutes. You are fifteen minutes away.

What do you tell her to do?

Option A
Unplug it now. Cut the connection before it reaches anything else.
Option B
Touch nothing. Photograph the screen and leave it exactly as it is.
Option C
Pay it now, while the demand is still small.
Option D
Call the IT vendor and let him deal with it before you arrive.
That screen is the only thing the attacker ever tells you

Pulling the plug decrypts nothing, and it destroys what an investigator would have worked from. A photograph costs you nothing and it is the only record of the demand, the deadline and the address you were told to reply to.

Paying is not recovery either. In the year of this attack, 80% of organisations that paid were hit again, and 68% of those inside a month. Handing it to the vendor first does not stop the clock that is already running.

Decision 02 / 04 · Reception · 09:15

You are on site. Sixteen patients are booked today and one is already in the waiting room. The ransom note is still on the screen behind the desk.

What do you do about today's patients?

Option A
Tell them now that you have been hacked and their data may be affected.
Option B
Say nothing. Reschedule everyone and call it a technical problem.
Option C
Close the clinic and send everyone home until you understand it.
Option D
Run the day on paper, and start assessing the breach this morning.
You cannot announce what you have not yet assessed

The law does not ask you to declare a breach on the morning you find it. It asks you to assess it quickly, and then not to delay. Under the PDPA that means the Commission within three calendar days of deciding the breach is notifiable, and the affected patients as soon as practicable after that.

Calling it a technical problem is the sentence you have to take back later. In this case the patients were told nineteen days after the attack.

Decision 03 / 04 · Your office · 11:20

The vendor cannot say how they got in. Your local backup sat on the same network and encrypted with everything else. The cloud copy might be intact. The police report is logged.

Who do you call next?

Option A
Another clinic owner who has been through one of these.
Option B
Your lawyer, before you say anything else to anybody.
Option C
Your insurer, to find out what any of this is covered for.
Option D
The attackers, to see how far the price will come down.
Every other call is one you can only make properly after that one

What you say in the next eight hours gets written down somewhere, and you do not choose where. The insurer's file, the regulator's file and a peer's recollection are all records. The lawyer is the only call whose job is to get the order and the wording right.

Reporting to the authorities is a separate obligation and it is not optional. In this case the clinic told the police, the Commission, SingCERT, the Cyber Security Agency and the Ministry of Health.

Decision 04 / 04 · Draft notification · 16:30

The draft notification runs to two pages. One section is headed "Reasonable security measures in place at the time of the breach." You have antivirus, passwords on the workstations and a vendor on retainer. You do not have a policy, training records, or a plan that pre-dates this morning.

What goes in that section?

Option A
List what you have and hope it reads as enough.
Option B
State plainly what you had and what you did not, and take the finding.
Option C
Ask the lawyer to write it as "industry-standard measures".
Option D
Hold the submission back and write the missing policy up today.
Negligence is recoverable. A back-dated record is not.

Writing the policy today and dating it last year changes what is being investigated. The question stops being what you lost and becomes what you signed, and that question has a different range of answers.

Reasonable security is judged on what existed on the day. Nothing written afterwards changes that, and everything written afterwards carries the date it was written.

73,466
Patient records affected
19 days
Before the patients were told
5
Authorities notified
All three figures are sourced. See the panel at the end.
What happened next
A police report was made on 13 August, seven days after the attack. The Commission, SingCERT, the Cyber Security Agency and the Ministry of Health were all notified. The patients were told on 25 August.
The clinic said no data was known to have been released publicly, and that it would keep watching. The second site was not affected. Whether a ransom was demanded, and whether anybody paid it, has never been disclosed.
What would have changed this
01
Photograph it
The ransom screen is the only thing the attacker tells you. Unplugging destroys it and decrypts nothing.
02
Backup off the network
A backup reachable from the machine it backs up encrypts along with it. Only a disconnected copy survives.
03
Know the clock
Three calendar days to the Commission once you decide it is notifiable. The patients as soon as practicable.
04
Write the plan first
Reasonable security is judged on what existed that day. A plan written afterwards is dated afterwards.
05
Paying is not fixing
80% of organisations that paid were hit again, and 68% of those inside a month.
Are you a business owner?
Find out how you can protect your personal data from cyber threats.
Protect yourself
Patient count, dates, data categories and authorities notified. Contemporaneous reporting of the August 2021 ransomware attack on a specialist ophthalmology practice in Singapore: 73,466 patients affected, attack on 6 August 2021, police report on 13 August, public announcement on 25 August, one of two sites affected. Data affected was names, addresses, identity card numbers, contact details and clinical information. Credit card and bank account details were not held on the affected system.
privacy.com.sg/databreach/personal-data-of-more-than-73000-patients-affected-in-cyberattack-on-eye-clinic
Corroborated by a second outlet reporting the same incident, including the Ministry of Health notification and the Notification of Data Breaches Regulations 2021 framing: cshub.com
Both retrieved 30 August 2026.
The three-day notification rule. Personal Data Protection Act section 26D, read with regulations 3 and 4 of the Personal Data Protection (Notification of Data Breaches) Regulations 2021. An organisation must notify the Commission as soon as practicable and in any case no later than three calendar days after assessing that a breach is notifiable, and must notify affected individuals as soon as practicable. The significant-scale threshold is 500 or more individuals.
pdpc.gov.sg, Guide on Managing and Notifying Data Breaches under the PDPA
The reinfection figures. Cybereason, Ransomware: The True Cost to Business. 80% of organisations that paid a ransom were hit by a second attack, and 68% of those said the second attack came within a month. A later edition of the same study puts the reinfection figure at 78%. The page uses the 2021 edition, which is contemporaneous with this incident.
cybereason.com/press/cybereason-ransomware-true-cost-to-business-study
Not retrieved: Healthcare IT News, DataBreaches.net and The Daily Swig all carry reports of the same incident, and all three returned HTTP 403 to automated retrieval on 30 August 2026. They are listed because they exist, not because they were read. Nothing on this page rests on them.
Not established, and not claimed: whether a ransom was demanded, its amount, and whether it was paid. How the attackers got in. Whether the local backup was encrypted. Whether any regulatory decision followed. Five searches of the Commission's enforcement register on 30 August 2026 returned no decision in this matter, and that register is rendered by JavaScript, so this is a failure to find rather than a finding of no action.
Written for the simulation: the compression of the response into a single morning, which in the record ran nineteen days. All four decisions, the options and the times of day. The receptionist and the phone call. The sixty-eight minutes to the first patient and the sixteen appointments. The clinic's antivirus, passwords, vendor retainer and missing policy, training records and response plan. The wording of the draft notification. The reader plays a composite clinic owner, not any identified person.
Naming, currency and pricing: no individual, clinic or company is named anywhere on this page, deliberately, although the sources linked above do name the practice. Figures are as reported. The plan price is StrongKeep's own published pricing and is not part of the case.
Three questions

Now your business.

Answer these honestly. Nothing is sent anywhere and nothing is saved.

01
If a screen in your business locked tomorrow morning, does anybody there know to photograph it before touching it?
02
Do you have a backup that cannot be reached from the machines it backs up?
03
Does anybody in your business know how long you have to notify the regulator after a breach?
0 of 3 answered
Where you stand

Run the free scan
Already know what you need? .
Notes
Review notes
S0. Hero
S1. The reckoning
S1B. Brief
Decision 01
Decision 02
Decision 03
Decision 04
S6. End sequence
S7. Mini-scan and CyberScan bridge
General / anything else
Saved in this browser only