Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • Supply Chain Updates
  • Global News
  • Contact Us
  • Home
  • Supply Chain Updates
  • Global News
  • Contact Us
No Result
View All Result
No Result
View All Result
Home Supply Chain Updates

Singtel Supply Chain Breach Traced to Unpatched Bug

usscmc by usscmc
February 12, 2021
Singtel Supply Chain Breach Traced to Unpatched Bug
Share on FacebookShare on Twitter

One of APAC’s biggest telecoms companies has admitted that a supply chain attack may have led to the compromise of customer data.

Singtel released a statement on Thursday revealing that it was running Accellion’s legacy file sharing system FTA to share information internally and with external stakeholders.

Cyber-criminals appear to have exploited potentially multiple FTA vulnerabilities in attacks against various customers.

Although Singtel said its core operations “remain unaffected and sound,” it admitted there may be an impact on customers.

“We are currently conducting an impact assessment with the utmost urgency to ascertain the nature and extent of data that has been potentially accessed. Customer information may have been compromised,” it explained.

“Our priority is to work directly with customers and stakeholders whose information may have been compromised to keep them supported and help them manage any risks. We will reach out to them at the earliest opportunity once we identify which files relevant to them were illegally accessed.”

Accellion said in an update at the start of February that it was the target of a “sophisticated cyber-attack” which all FTA customers were informed of on December 23. As of February 1 it said it had “patched all known FTA vulnerabilities exploited by the attackers and has added new monitoring and alerting capabilities to flag anomalies associated with these attack vectors.”

Singtel corroborated this in its own version of events, stating that the supplier had made two patches available to fix the bug, which it applied on December 24 and 27 2020. However, there was a further issue the following month.

“On January 23, Accellion issued another advisory citing a new vulnerability which the December 27 patch was not effective against and we immediately took the system offline. On January 30, Accellion provided another patch for the new vulnerability which triggered an anomaly alert when we tried to apply it,” it continued.

“Accellion informed thereafter that our system could have been breached and this had likely occurred on January 20. We continued to keep the system offline and activated cyber and criminal investigations which has confirmed the January 20 date. Given the complexity of the investigations, it was only confirmed on February 9 that files were taken.”

Other customers known to have been hit by the same attacks are the New Zealand central bank, which issued a statement on January 10 and so is likely to have been caught out by an exploit of the vulnerability patched in December.

Saryu Nayyar, CEO of Gurucul, argued that the incidents highlight the risks associated with running legacy software. FTA is thought to be over 20-years-old.

“Patch cycles in enterprise environments can be complicated, especially for mature organizations with a robust change management system, but the malicious actors do not wait,” she added.

“They know there is usually a limited time between an exploit being released and a defense going in place, so they tend to move quickly. That means cybersecurity needs to move at least as quickly.”

usscmc

usscmc

No Result
View All Result

Recent Posts

  • How Hapag Lloyd captured a major market share in the Container Shipping Industry in USA
  • Why USA’s East Coast is the Favorite Destination for Manufacturing Companies
  • How Trade Relations Between the USA and UK Improved After Keir Starmer Became Prime Minister
  • Tips and Tricks for Procurement Managers to Handle Their Supplier Woes
  • The Crazy Supply Chain of Walmart Spanning Across the Globe

Recent Comments

  • Top 5 Supply Chain Certifications that are in high demand | Top 5 Certifications on Top 5 Globally Recognized Supply Chain Certifications
  • 3 Best Procurement Certifications that are most valuable | Procurement Newz on Top 5 Globally Recognized Supply Chain Certifications

Archives

  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • September 2019

Categories

  • Global News
  • Supply Chain Updates

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org
  • Antispam
  • Contact Us
  • Disclaimer
  • Home
  • Privacy Policy
  • Terms of Use

© 2025 www.usscmc.com

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • Supply Chain Updates
  • Global News
  • Contact Us

© 2025 www.usscmc.com