The Morning
73,466 patient records are locked on the clinic's system.
A specialist eye clinic in Singapore, with a full day of appointments booked. You make four decisions and see the cost of each one after you choose.
Based on a real case: the ransomware attack on a Singapore eye clinic in August 2021. Read the news report
You're the owner. What do you do?
What the locked system held
Every patient file is locked, including the backup.
The patient count and the types of data are as reported. The layout is written for the simulation.
Every field on that list existed because somebody needed treating.
4 decisions
You make the owner's calls, in order.
Written for the simulation. The public record doesn't describe this clinic's controls.
Decision 01 / 04 · In transit · 07:34
Your receptionist calls. The front desk screen is showing a ransom demand. The first patient is due in 68 minutes.
What do you tell her to do?
What it cost · Decision 01 · 07:34
Stop the spread, keep the evidence
Pull the network cable and turn off Wi-Fi to stop it spreading. Then photograph the screen before anyone switches it off: it holds the demand, the deadline and the contact address. Call your IT vendor once it's cut off. Formatting decrypts nothing and wipes the evidence.
Paying doesn't end it: 80% of organisations that paid were attacked again.
Decision 02 / 04 · Reception · 09:15
Sixteen patients are booked today and one is already waiting. You don't know yet what was taken.
What do you do about today's patients?
What it cost · Decision 02 · 09:15
Assess the breach first, then report it quickly
The law asks you to assess the breach quickly before you announce anything. Once you decide it's notifiable, you have three days to tell the Commission. Tell patients as soon as practicable.
In this case, patients were told 19 days after the attack.
Decision 03 / 04 · Your office · 11:20
The vendor can't say how they got in, and your backup was encrypted too. Everything you say from now on will be on record.
Who do you call next?
What it cost · Decision 03 · 11:20
Call your lawyer first
A peer, a journalist and the attackers all keep a record of what you tell them. The lawyer's job is to get the order and the wording right. If you have cyber insurance, its breach line can usually provide one.
You still have to report to the authorities. This clinic told five.
Decision 04 / 04 · Draft notification · 16:30
The breach notification asks for your "security measures at the time of the breach." You had antivirus, passwords and an IT vendor. You had no written policy, training or response plan.
What goes in that section?
What it cost · Decision 04 · 16:30
Report the gaps honestly and never back-date a policy
Security is judged on what existed on the day of the attack. A policy written afterwards carries the date it was written, and passing it off as older would be a false statement.
All three figures are sourced. See the end.
After the attack
What would have changed this
Are you a business owner?
Find out how you can protect your personal data from cyber threats.
Protect yourselfprivacy.com.sg/databreach/personal-data-of-more-than-73000-patients-affected-in-cyberattack-on-eye-clinic
Corroborated by a second outlet reporting the same incident, including the Ministry of Health notification and the Notification of Data Breaches Regulations 2021 framing: cshub.com
Both retrieved 30 August 2026.
pdpc.gov.sg, Guide on Managing and Notifying Data Breaches under the PDPA
cybereason.com/press/cybereason-ransomware-true-cost-to-business-study
Three questions
Now check your own business.
Your answers stay on this page. Nothing is sent or saved.