DBS and Bank of China Singapore customer data exposed by vendor ransomware
- Organization
- DBS Bank
- Exploit
- Third-Party Data Breach
- Industry
- Financial Services
DBS Bank said in April 2025 that customer statements handled by Toppan Next Tech, a Singapore printing vendor, may have been taken during a ransomware attack on the vendor's systems. DBS said it was informed of the incident late on 5 April and that its own banking systems were not compromised.
The bank put the number of potentially affected customers at roughly 8,200, drawn mainly from DBS Vickers brokerage accounts and, to a lesser extent, Cashline loan accounts. Bank of China's Singapore branch, which also used the vendor to print paper letters, said about 3,000 of its customers were affected, bringing the combined figure to around 11,200.
According to DBS, the documents contained first and last names, postal addresses and details of equities held under DBS Vickers or Cashline loan information. The bank said they did not include login credentials, passwords, national registration identity card numbers, deposit balances or total wealth holdings. Statements covering December 2024 through February 2025 were involved. DBS sends files to the vendor encrypted, and it was not established whether the attacker had been able to decrypt them.
DBS halted all printing work with the vendor, increased monitoring for unusual account activity and began contacting affected customers by email and post. Toppan Next Tech reported the incident to Singapore's Personal Data Protection Commission on 6 April and said it had cut off the attacker's entry point. The Cyber Security Agency of Singapore assisted with containment while the Monetary Authority of Singapore worked with the two banks on risk mitigation.