00:00:00 since the screen locked
0 patient records told 19 days later

Reconstruction · Singapore, August 2021

Specialist clinic · Two sites

The Morning

73,466 patient records are locked on the clinic's system.

A specialist eye clinic in Singapore, with a full day of appointments booked. You make four decisions and see the cost of each one after you choose.

Based on a real case: the ransomware attack on a Singapore eye clinic in August 2021. Read the news report

You're the owner. What do you do?

What the locked system held

Every patient file is locked, including the backup.

patients connection lost
Field
Contents
Rows
Status
All fields
73,466
No access
Reading 6 fields

The patient count and the types of data are as reported. The layout is written for the simulation.

Every field on that list existed because somebody needed treating.

4 decisions

You make the owner's calls, in order.

07:34In transit
09:15Reception
11:20Your office
16:30Notification
What the clinic had
Antivirus on every machine
A password on each one
An IT vendor on call
What it lacked
A written security policy
Any staff training
A plan for this morning

Written for the simulation. The public record doesn't describe this clinic's controls.

Decision 01 / 04 · In transit · 07:34

Your receptionist calls. The front desk screen is showing a ransom demand. The first patient is due in 68 minutes.

What do you tell her to do?

What it cost · Decision 01 · 07:34

Stop the spread, keep the evidence

Pull the network cable and turn off Wi-Fi to stop it spreading. Then photograph the screen before anyone switches it off: it holds the demand, the deadline and the contact address. Call your IT vendor once it's cut off. Formatting decrypts nothing and wipes the evidence.

Paying doesn't end it: 80% of organisations that paid were attacked again.

Decision 02 / 04 · Reception · 09:15

Sixteen patients are booked today and one is already waiting. You don't know yet what was taken.

What do you do about today's patients?

What it cost · Decision 02 · 09:15

Assess the breach first, then report it quickly

The law asks you to assess the breach quickly before you announce anything. Once you decide it's notifiable, you have three days to tell the Commission. Tell patients as soon as practicable.

In this case, patients were told 19 days after the attack.

Decision 03 / 04 · Your office · 11:20

The vendor can't say how they got in, and your backup was encrypted too. Everything you say from now on will be on record.

Who do you call next?

What it cost · Decision 03 · 11:20

Call your lawyer first

A peer, a journalist and the attackers all keep a record of what you tell them. The lawyer's job is to get the order and the wording right. If you have cyber insurance, its breach line can usually provide one.

You still have to report to the authorities. This clinic told five.

Decision 04 / 04 · Draft notification · 16:30

The breach notification asks for your "security measures at the time of the breach." You had antivirus, passwords and an IT vendor. You had no written policy, training or response plan.

What goes in that section?

What it cost · Decision 04 · 16:30

Report the gaps honestly and never back-date a policy

Security is judged on what existed on the day of the attack. A policy written afterwards carries the date it was written, and passing it off as older would be a false statement.

73,466
Patient records affected
19 days
Before the patients were told
5
Authorities notified

All three figures are sourced. See the end.

After the attack

The clinic reported it to the police and four other authorities. Patients were told on 25 August, 19 days after the attack.
No data was known to have been published. Whether a ransom was paid has never been disclosed.

What would have changed this

01
Disconnect, then photograph
Cut the network to stop the spread. Formatting wipes the evidence and decrypts nothing.
02
Keep a backup off the network
A connected backup gets encrypted too.
03
Know the reporting deadline
Three days to tell the Commission once a breach is notifiable.
04
Write the plan first
Security is judged on what existed on the day.
05
Paying invites another attack
80% of organisations that paid were attacked again.

Are you a business owner?

Find out how you can protect your personal data from cyber threats.

Protect yourself
Patient count, dates, data categories and authorities notified. Contemporaneous reporting of the August 2021 ransomware attack on a specialist ophthalmology practice in Singapore: 73,466 patients affected, attack on 6 August 2021, police report on 13 August, public announcement on 25 August, one of two sites affected. Data affected was names, addresses, identity card numbers, contact details and clinical information. Credit card and bank account details were not held on the affected system.
privacy.com.sg/databreach/personal-data-of-more-than-73000-patients-affected-in-cyberattack-on-eye-clinic
Corroborated by a second outlet reporting the same incident, including the Ministry of Health notification and the Notification of Data Breaches Regulations 2021 framing: cshub.com
Both retrieved 30 August 2026.
The three-day notification rule. Personal Data Protection Act section 26D, read with regulations 3 and 4 of the Personal Data Protection (Notification of Data Breaches) Regulations 2021. An organisation must notify the Commission as soon as practicable and in any case no later than three calendar days after assessing that a breach is notifiable, and must notify affected individuals as soon as practicable. The significant-scale threshold is 500 or more individuals.
pdpc.gov.sg, Guide on Managing and Notifying Data Breaches under the PDPA
The reinfection figures. Cybereason, Ransomware: The True Cost to Business. 80% of organisations that paid a ransom were hit by a second attack, and 68% of those said the second attack came within a month. A later edition of the same study puts the reinfection figure at 78%. The page uses the 2021 edition, which is contemporaneous with this incident.
cybereason.com/press/cybereason-ransomware-true-cost-to-business-study
Not retrieved: Healthcare IT News, DataBreaches.net and The Daily Swig all carry reports of the same incident, and all three returned HTTP 403 to automated retrieval on 30 August 2026. They are listed because they exist, not because they were read. Nothing on this page rests on them.
Not established, and not claimed: whether a ransom was demanded, its amount, and whether it was paid. How the attackers got in. Whether the local backup was encrypted. Whether any regulatory decision followed. Five searches of the Commission's enforcement register on 30 August 2026 returned no decision in this matter, and that register is rendered by JavaScript, so this is a failure to find rather than a finding of no action.
Written for the simulation: the compression of the response into a single morning, which in the record ran nineteen days. All four decisions, the options and the times of day. The receptionist and the phone call. The sixty-eight minutes to the first patient and the sixteen appointments. The clinic's antivirus, passwords, vendor retainer and missing policy, training records and response plan. The wording of the draft notification. The reader plays a composite clinic owner, not any identified person.
Naming, currency and pricing: no individual, clinic or company is named anywhere on this page, deliberately, although the sources linked above do name the practice. Figures are as reported. The plan price is StrongKeep's own published pricing and is not part of the case.

Three questions

Now check your own business.

Your answers stay on this page. Nothing is sent or saved.

01
Would your staff disconnect the network and photograph a locked screen before switching it off?
02
Do you keep a backup that is disconnected from your network?
03
Do you know how quickly you must report a breach?
0 of 3 answered

Where you stand

Run the free scan

Already know what you need? .