- Briefing Your roundup of Asian tech and startup news that matter
RedDoorz fined $54k for 2020 data breach
“RedDoorz, a Singapore-based hospitality firm, was fined S$74,000 (around US$54,000) in September for failing to prevent the external access and exfiltration of the data,” The Business Times reported, citing the decision published by the Personal Data Protection Commission (PDPC).
Details:
- Millions of RedDoorz’s user records were sold on underground forums in September and October last year. The compromised data included the customers’ names, contact numbers, hashed passwords, and booking information, but the report noted that masked credit card numbers were not accessed.
- After the incident, the company amended its credential policy to prohibit developers from embedding access codes in any code base. RedDoorz also enabled two-factor authentication for all tools and accounts that were used by developers.
Dive deeper:
- In November 2020, Singapore amended its data protection law that allowed the PDPC to increase the financial penalties for companies that infringe the country’s Personal Data Protection Act. However, the change has yet to take effect, and the current cap is still at S$1 million (around US$737,000).
- RedDoorz is not the only tech company that has faced data infringement attacks. Indonesia-based marketplace Tokopedia, Taiwan-based PC maker Acer, and India-based grocery delivery startup BigBasket have also experienced similar incidents in the past two years.
Currency converted from Singapore dollar to US dollar: US$1 = S$1.36.
Editing by Collin Furtado and Lorenzo Kyle Subido
(And yes, we’re serious about ethics and transparency. More information here.)
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.





