Simba, Singapore’s fourth mobile network operator, said personal data belonging to 23,549 customers was exposed in a cyber incident discovered on 24 September, including full names, identity card numbers, dates of birth, mobile numbers and email addresses. The company stressed that no credit card or bank account records were involved and that it had seen no evidence of malicious misuse so far, but the breach still hands criminals enough detail to fuel phishing and account-takeover attempts across the city-state’s digital services.

What Simba has confirmed

In a statement released on 25 September and updated as reporters pressed for detail, Simba said engineers contained the flaw quickly after internal monitoring flagged abnormal access. The telco did not specify whether mobile subscribers, fibre broadband users or both were affected, leaving households that bundle services uncertain about their exposure. Simba reported roughly 1.5 million active mobile lines and 62,000 fibre connections as of 31 July, meaning the leak touches a small fraction of its base but a large absolute number of NRIC-linked records.

Simba said it is emailing affected customers and expects notifications to finish within a week. It also said it is reviewing security controls on core infrastructure and cooperating with regulators. The Personal Data Protection Commission told The Straits Times it is aware of the case and investigating, the standard path for serious breaches under Singapore’s privacy law.

Why NRIC data matters in Singapore

Unlike markets that rely primarily on phone numbers, many Singapore government and commercial portals treat the national registration identity card number as a durable identifier. Leaked NRICs cannot be rotated the way a compromised password can, which raises the stakes when they sit beside mobile numbers and email addresses in a single table. Security teams routinely warn that such combinations supercharge bogus calls pretending to be from banks, Singpass reset desks or parcel couriers.

Simba competes against Singtel, StarHub and M1 in a saturated market where budget plans have drawn price-sensitive users. A trust hit can push churn even when networks stay online, particularly if customers believe the operator was slow to disclose or failed to segment sensitive fields.

Regulatory and industry context

Singapore has tightened cyber rules for critical information infrastructure and fined larger telcos for past lapses, but Simba’s relative size does not exempt it from breach-notification duties. The commission can compel forensic reports and order remediation steps if investigators find governance failures. Industry groups have urged all carriers to adopt tokenised identifiers in internal databases, yet legacy billing stacks still store NRICs in plain text in parts of the sector.

The breach arrives as Singapore pitches itself as a trusted data hub for artificial intelligence and cross-border payments, making domestic incidents a reputational counterweight to those ambitions. Officials have not linked this case to any wider campaign against telecom assets, and Simba has not described the intrusion as nation-state activity.

What customers should watch

Until Simba completes its email roll-out, subscribers should treat unsolicited messages referencing account upgrades with extra skepticism and enable two-factor authentication anywhere it is offered. Businesses that verify customers with SMS one-time passwords should expect criminals to pair leaked mobile numbers with NRIC fragments in social-engineering scripts. Further updates are likely once the privacy commission finishes its review and Simba clarifies which product lines were hit.