In Singapore’s shadow economy, your private data is being sold without your permission – at one cent apiece

For about one cent – or 1.2 Singapore cents to be exact – I can buy your name, home and email address, mobile number, and shopping history from a broker – all stolen without your knowledge.
And you’re not alone. Tons of customer data can be bought for a dirt cheap price, with 300,000 names going for as little as S$1,000 (about US$800).
This is Singapore’s grey market for data: where private customer information is extracted from customer databases either knowingly or unknowingly, and then sold to shady data brokers.
These brokers, in turn, are approached by people – marketers, ecommerce site owners, or anyone with any agenda and is willing to pay the right price – who are keen on getting a slice of a massive database.
Just recently, Tech in Asia was contacted by one such broker who goes by the name John Lee. In his sales pitch, which landed in our inbox, Lee claimed to have data from Deal.com.sg, Groupon, Zalora, Reebonz, CloutShoppe, and Lazada – some of the most popular daily deals and shopping sites in Singapore.
His assertions are hard to verify, but the amount of records that Lee claimed to possess is staggering if true – 650,000 records from Deal, 440,000 from Reebonz, and 400,000 from Zalora. That’s just for Singapore alone.
That’s not all. To prove his legitimacy, Lee included screenshots of emails from apparently satisfied customers, containing information like how many records they purchased, how many of them contained invalid email addresses, and the conversion rates from sending spam to these email addresses.
Some of these alleged buyers include small-time online shops like ChicKissLove, Hermo, Jennie Shop, Nime Shop, and MichSara.
“Overall our sales revenue increased. We would like to purchase double quantity for second dealing [sic] with you,” wrote one of the buyers, who then requested an order of 900,000 records – about one-sixth the population of Singapore.
Data not compromised, says ecommerce sites
In response to Lee’s claims, a Zalora spokesperson told Tech in Asia that they are aware of data brokers who claim to have Zalora’s customer database. However, she asserts that its databases are “extremely secure and have never been compromised, sold, monetized or made available to any parties” outside of the company.
She adds: “Customer data privacy is of the utmost importance to us and is secured behind several layers of protection, via firewalls and access control mechanisms with detailed audit logs. We have not detected any intrusions into our systems to date.”
A Lazada spokesperson, meanwhile, has said that all its data is encrypted and kept in an isolated environment with isolated security. As such, only a restricted number of employees can access the real data, and all activity is monitored and logged.
“Lazada Singapore will not launch until later this year, so no Lazada Singapore customer databases currently exist. Therefore, if data is being offered for sale, we are confident it is not connected to Lazada Singapore… As a group, Lazada is not aware that any of its legitimate customer data has been misappropriated and sold in any of its markets.”
Privacy laws exist, but are hard to enforce
Meet the shadow broker
As siren servers grow, consumer power may wane
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.





