Singapore's Ministry of Health and Ministry of Communications and Information announced on 20 July 2018 that attackers had taken the personal particulars of about 1.5 million people who had attended SingHealth specialist outpatient clinics and polyclinics between 1 May 2015 and 4 July 2018 — names, national registration identity card numbers, addresses, dates of birth, race and gender. For roughly 160,000 of those patients, the records of outpatient dispensed medicines went as well. The ministries said the intruders had specifically and repeatedly gone after one patient in particular: Prime Minister Lee Hsien Loong, whose records were sought by his identity card number. Diagnoses, clinical notes and test results were not taken, and nothing in the records was altered. It remains the worst data breach in Singapore's history.

The attack, its discovery and its disclosure were three separate events, and the distance between them is most of the story. The Committee of Inquiry later placed the initial compromise at around 23 August 2017, when a front-end workstation running an unpatched version of Outlook was infected. The attacker then went quiet, moving laterally through the network between December 2017 and June 2018 until it held local administrator credentials on Citrix servers at Singapore General Hospital that could reach the patient database. The attacker reached the database itself through a coding vulnerability in the clinical application on 26 June 2018; bulk queries ran from 27 June and stopped on 4 July, when a database administrator saw the unusual activity and severed the connection. The Cyber Security Agency was formally notified on 10 July. The public was told ten days after that.

A four-member Committee of Inquiry chaired by the former chief district judge Richard Magnus was convened on 24 July 2018 and published a 454-page public report on 10 January 2019, carrying sixteen recommendations. Its findings were not exotic. Staff at Integrated Health Information Systems, the agency that ran the health cluster's technology, lacked the training to recognise what they were looking at; patching was slow; and the people who did notice did not push it upwards. The inquiry described an employee urging colleagues in a group chat on 6 July to escalate, and a colleague resisting on the grounds that involving management would mean pressure and work. Lee wrote on Facebook that the attackers might have been "hunting for some dark state secret", and that there was nothing alarming in his medication data.

The response was immediate. Internet surfing separation — staff computers cut off from the open internet — was imposed at SingHealth on 19 July and at the National Healthcare Group and National University Health System on 23 July; the government paused the launch of new public-sector ICT systems on 20 July and lifted that pause on 3 August, while the Cyber Security Agency told the eleven critical information infrastructure sectors to cut connections to unsecured external networks. In January 2019 the Personal Data Protection Commission fined IHiS S$750,000 and SingHealth S$250,000. The government said it had identified the attacker as a state-linked advanced persistent threat and would not name it. Symantec linked the intrusion to a group it called Whitefly in March 2019 — a researcher's assessment, not an official attribution. Nobody has ever been charged.

Also that month · Twelve names, no defendants

The indictment that could not be served

On 13 July 2018, three days before President Trump met President Putin in Helsinki, Deputy Attorney General Rod Rosenstein announced that a federal grand jury in Washington had indicted twelve officers of Russia's military intelligence directorate, the GRU, over the intrusions surrounding the 2016 United States election. What made the document remarkable was its specificity. It named two units — 26165, cast as the hacking arm, and 74455, which pushed the stolen material out — and described spearphishing aimed at more than three hundred people connected to the Clinton campaign, the Democratic National Committee and the Democratic Congressional Campaign Committee, the X-Agent implant left on DNC machines, the DCLeaks site and the Guccifer 2.0 persona, and an intrusion into the Illinois State Board of Elections. It also described the money: bitcoin the officers mined themselves, laundered through transactions the indictment valued at more than $95,000, spent on the servers and domain registrations that carried the operation. Russia denied it. In 2026 none of the twelve has appeared in an American courtroom.

Also that month · Fifty minutes

Seven thousand machines over a weekend

Over the weekend of 14 July 2018, LabCorp — one of the largest clinical laboratory networks in the United States — detected suspicious activity on its network and began pulling systems offline. The company's own account is careful and narrow: test processing and access to results were temporarily affected, operations returned to normal within days, and its investigation found no evidence of theft or misuse of data. The scale came from reporting rather than from the company. CSO Online, citing people familiar with the investigation, described attackers brute-forcing exposed remote desktop services from around midnight on 13 July, the first encryption beginning on the evening of 14 July, and containment reached in roughly fifty minutes — by which point some 7,000 systems and 1,900 servers, about 350 of them production servers, had been encrypted. LabCorp declined at the time to name the malware; its later published account describes a new variant of SamSam. In November 2018 a New Jersey grand jury indicted two Iranian nationals over the SamSam campaign, alleging more than two hundred victim organisations, roughly $6 million collected and over $30 million in losses. Neither has stood trial.

India desk · July 2018

A law of consent, and a dare on Twitter

On 27 July 2018 the expert committee chaired by Justice B. N. Srikrishna handed the Law and IT Minister, Ravi Shankar Prasad, a report titled A Free and Fair Digital Economy: Protecting Privacy, Empowering Indians, together with a draft Personal Data Protection Bill, 2018 — India's first comprehensive attempt at a privacy statute. The draft borrowed the vocabulary of trust rather than control: individuals were data principals, the organisations holding their data were data fiduciaries, and consent had to be free, informed, specific, clear and capable of being withdrawn, with the burden of proof on the fiduciary. It proposed a Data Protection Authority with quasi-judicial powers and, in the provision foreign industry objected to loudest, required a serving copy of all personal data to be held on a server in India, with data notified as critical processed only in India.

The next day the chairman of the Telecom Regulatory Authority of India, R. S. Sharma, posted his twelve-digit Aadhaar number on Twitter and challenged anyone to show a concrete example of harm. Within hours strangers had published his mobile numbers, address, date of birth and PAN details, and someone deposited a rupee in his bank account. UIDAI, which had not endorsed the challenge, urged people not to post their numbers publicly and maintained that the Aadhaar database itself remained secure. Sharma maintained he had not lost, and had a point worth conceding: nothing surfaced that day was evidence that the Aadhaar database itself had been breached, and most of it came from elsewhere. That was precisely the problem. An identifier that unlocks everything indexed against it need not leak to be dangerous. The draft handed over the previous morning was rewritten as the Personal Data Protection Bill, 2019, withdrawn in 2022, and passed as the Digital Personal Data Protection Act in August 2023.

AI Tech desk · July 2018

Edge silicon, and the argument about faces

Google used Cloud Next '18, in San Francisco from 24 to 26 July 2018, to push machine learning off the data centre floor: the Edge TPU, announced on 25 July alongside a stack called Cloud IoT Edge, was a small chip for running TensorFlow Lite models on gateways and devices, and reached buyers the following March as the Coral board. The louder argument was about faces. On 13 July Microsoft's president, Brad Smith, called for government regulation of facial recognition, arguing that the rules should not be left to the firms selling the technology; on 26 July the American Civil Liberties Union reported that Amazon's Rekognition, run at its default confidence setting, had falsely matched twenty-eight members of Congress to arrest photographs. Amazon disputed the test, calling that threshold far too low for policing, and stopped selling to police in 2020. On 18 July, at an artificial intelligence conference in Stockholm, more than two thousand researchers had signed a Future of Life Institute pledge neither to build nor to support lethal autonomous weapons; no binding treaty has followed.

Digital Guard desk · July 2018

AT&T buys AlienVault, Washington warns on Emotet

AT&T announced on 10 July 2018 that it would buy AlienVault, the San Mateo firm behind the Unified Security Management platform and Open Threat Exchange; terms were not disclosed, and the business AT&T built around it was spun out in May 2024 as LevelBlue. Ten days later the Department of Homeland Security and the Multi-State Information Sharing and Analysis Center issued alert TA18-201A, calling Emotet among the most costly and destructive malware then circulating: it arrived as counterfeit PayPal receipts, shipping notices and past-due invoices, and cost state and local governments up to a million dollars an incident to clear. An international operation seized its infrastructure in January 2021. Microsoft published its own reading of AV-TEST's March–April figures that same day, conceding that Windows Defender had missed two of 5,680 samples and arguing that single-product tests no longer described what an endpoint platform did. Earlier, on 1 July, the Mac antivirus maker Intego was bought for $16 million by Kape Technologies, a London-listed company that had traded as Crossrider until March and that bought ExpressVPN in 2021.

⏳ Time capsule — July 2018

  • All twelve boys of the Wild Boars football team and their coach were brought out of Thailand's Tham Luang cave by 10 July, eighteen days after they walked in.
  • France beat Croatia 4–2 at the Luzhniki Stadium in Moscow on 15 July to win the World Cup.
  • Scientists using radar data from the European Space Agency's Mars Express orbiter reported on 25 July evidence of a body of liquid water beneath the Martian south polar ice cap.
  • The total lunar eclipse of 27 July was the longest of the twenty-first century, with totality lasting about one hour and forty-three minutes, and Mars at opposition the same night.
Where it stands today — 2026

Named, and never caught

July 2018 produced three attributions and not one defendant in a dock. The twelve GRU officers were named in extraordinary detail and remain in Russia. The two men accused of running SamSam were named four months later and remain in Iran. Singapore's government said it knew which state-linked group had walked out of SingHealth with 1.5 million records, and declined then, and has declined since, to say so publicly. Public attribution matured into an instrument of policy that month; it did not become an instrument of arrest. What did change was defensive, and Singapore's version was blunt: cut the wires. The archive's WannaCry edition of May 2017 had already shown what an unpatched hospital estate costs. SingHealth showed that patching alone had never been the whole answer.

India's thread from this month runs straight into the present. The draft Justice Srikrishna handed over on 27 July became, after a rewrite he publicly disowned — he warned in 2019 that the exemptions granted to government agencies could turn India into an "Orwellian state" — the Digital Personal Data Protection Act of 2023. The strict localisation of the 2018 draft did not survive; the consent architecture largely did, and the reporting culture went the other way entirely, with CERT-In later demanding incident reports within six hours where Singapore had taken sixteen days. The lesson of the Aadhaar dare outlived both bills: identifiers are not secrets, and pretending otherwise is where the impersonation scams this magazine now covers weekly found their raw material.