VPN vulnerability linked to ransomware attack in Singapore

Ransomware attack on a computer
(Image credit: Kaspersky)

A VPN vulnerability has been identified as the key behind a ransomware attack against the Law Society of Singapore.

The attack occurred on January 27, 2021 and endangered the personal data of over 16,000 members, using a bug in the VPN service to gain access credentials if left unpatched.

The investigation carried on by the Singapore's Personal Data Protection Commission (PDPC) also found the Society guilty of using an easy-to-guess password as well as failing to conduct the periodic security reviews required by law. The organization has now 60 days to finalize an internal audit and fix any security gaps. 

Breach of data protection obligations

Despite many members' personal information including full names, residential addresses and date of birth were leaked, PDPC's Deputy Commissioner Zee Kin Yeong concluded that: "There was no evidence of any exfiltration or misuse of the personal data of the members and the (Law Society) took prompt remedial actions in response to the incident," Channel News Asia reported.

The company's antivirus software detected the attack on the same day, in fact. It quickly removed the threat actor account used to inject the malware, while restoring the servers on previously data backups.

As the VPN provider Fortinet disclosed, developers informed their clients about the VPN's vulnerability on May 24, 2019. However, there were no updates to fix the bug available before the incident took place.   

For this reason, Mr Yeong absolved the Law Society from any responsibility on the matter.

The troubles for the organizations representing all Singapore's lawyers didn't end there, though.

The PDPC found, in fact, the Society to be in breach of Section 24 of the country's Personal Data Protection Act for failing to fulfil some of its data protection obligations.

Section 24 of Singapore Personal Data Protection Act covering organizations' obligation to protect personal data.

(Image credit: Singapore Statues Online)

Specifically, it was guilty to use weak password— "Welcome2020lawsoc"— for the hacked account. Even worse, this was in use for more than 90 days when the law required this to be changed every three months as a minimum requirement. The Law Society was also found guilty of not carrying out a security review in the three years preceding the attack.

Despite the gravity of the security flaws, these were not directly linked with the ransomware attack. The Law Society is now finalizing an internal audit to strengthen its security posture.

"In the past two years since the incident, we have already taken a number of proactive steps to enhance our cybersecurity infrastructure," said the Society in an official statement.

"Those include implementing multi-factor authentication for all VPN access and strengthening our in-house IT team to deal with cybersecurity matters."

Chiara Castro
News Editor (Tech Software)

Chiara is a multimedia journalist committed to covering stories to help promote the rights and denounce the abuses of the digital side of life – wherever cybersecurity, markets, and politics tangle up. She writes news, interviews, and analysis on data privacy, online censorship, digital rights, cybercrime, and security software, with a special focus on VPNs, for TechRadar and TechRadar Pro. Got a story, tip-off, or something tech-interesting to say? Reach out to chiara.castro@futurenet.com

Read more
An illustration of a silhouetted thief in motion running while carrying a stolen fingerprint
The 5 worst cyberattacks of 2024
Illustration of a thief escaping with a white fingerprint
5 massive privacy scandals that rocked the world – and made millions of victims
Panels at RightsCon 2025 during a press briefing about the latest Access Now report of internet shutdowns
2024 was the worst year on record for internet freedoms – again
A VPN running on a mobile device
US age verification laws put your privacy at risk – and "VPNs are not a solution”
VPN
7 VPN predictions to look out for in 2025
vpn
Nominet says it was hit by cyberattack following recent Ivanti VPN security issue
Latest in VPN Privacy & Security
Digital hand set location on map with two pins. AI technology in GPs, innovation delivery, map location, future transport logistic, route path concept. GPs point. New office location, change address
What does your IP address reveal about you?
A stethoscope next to a laptop on a pink background
How to check if your VPN is working
Teenager playing on a gaming PC with two monitors
Is using a VPN while gaming cheating? 5 myths you shouldn't believe about gaming with a VPN
Neon blue email symbols on a black background
Why am I suddenly getting so many spam emails?
A computer file surrounded by red laser beams
Cover your tracks: the risk of sending unencrypted files
Using an Amazon Fire Stick on a Smart TV
How to use a VPN with Fire Stick
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)