DataPost ransomware attack exposed data of 146 Income Insurance policyholders
- Organization
- DataPost
- Exploit
- Ransomware
- Industry
- Business Services
DataPost, a Singapore provider of document handling and mailing services, was hit by a ransomware attack in May 2025 that exposed customer records it processed on behalf of Income Insurance.
Income Insurance said it was alerted on 25 May 2025 and immediately halted all printing jobs with the vendor, severed its digital connections to DataPost and tightened its firewall rules. Preliminary work by DataPost found that bonus statements for at least 146 policyholders had been compromised. The documents contained names, postal addresses, policy numbers, policy plan details and 2024 annual bonus figures. The insurer said its own systems remained secure and that it had found no evidence of unauthorised access to its digital platforms.
Both companies made the incident public on 29 May. DataPost said it was still in the early stages of its investigation and that a full assessment would take time to complete, leaving open the possibility that further records or other clients were affected. According to teiss, the monitoring services RedPacket Security and HookPhish first flagged the attack on 27 May and attributed it to a group operating under the name direwolf, which used infostealers and other tooling.
Singapore's Personal Data Protection Commission and the Cyber Security Agency opened enquiries and offered assistance to DataPost. The vendor handles large volumes of printed correspondence for government agencies, telecommunications operators and financial institutions in Singapore and Malaysia, which kept the potential scope of the breach an open question as the investigation continued.