Singapore mobile operator Simba Telecom has confirmed a data breach that exposed the personal details of 23,549 customers. The exposed data includes names, national identity card (NRIC) numbers, dates of birth, mobile numbers and email addresses. In a statement dated 25 September 2026, reported by The Straits Times, CNA and The Business Times, Simba said it found the incident on 24 September and has "swiftly resolved it." The company says no credit card or bank account data is at risk, and it has no indication so far that the data has been misused. Simba has not said how the breach happened or who was behind it. By customer count this is a small incident. The type of data taken is what makes it matter.
What Happened
Every account traces back to one company statement, which the outlets reported on 27 September. According to that statement as quoted by The Straits Times, CNA and The Business Times:
- 24 September 2026: Simba discovered the breach.
- 25 September 2026: Simba published a notice on its newsroom. MissLobang says the notice was on simba.sg. Simba said the issue had been "swiftly resolved" and that it had "taken immediate and appropriate actions to review existing security measures to protect core infrastructure and systems."
- Ongoing: Simba is emailing affected customers in batches and expects to finish "within the next week." It says it is working with "the relevant authorities."
The Business Times, carrying a Straits Times report, says a spokesperson told The Straits Times that the Personal Data Protection Commission (PDPC) is aware of the incident and is investigating. We have not seen a PDPC statement or any other regulator's statement directly.
On sourcing: none of the sources we reviewed is Simba's original notice or a regulator filing. Every detail about the breach comes from the company statement as reported by the press. The outlets agree with each other on every fact they cover.
What Was Taken
- Volume: All sources give the same figure: 23,549 individuals. Headlines round it to "more than 23,500." We found no conflicting counts.
- Data fields: names, NRIC/identity card numbers, dates of birth, mobile numbers and email addresses. Early summaries of this incident left out dates of birth, but every detailed source (The Straits Times, CNA, The Business Times and MissLobang) lists them.
- Not affected, per Simba: credit card and bank account information.
- Unknown: which customers are affected. The Straits Times and The Business Times say it is unclear whether the breach hit mobile customers, broadband customers or both. MissLobang adds that Simba has not said whether current or former subscribers are included.
For scale, The Business Times has reported that Simba had nearly 1.5 million active mobile subscribers as of 31 July, plus 62,000 fibre broadband subscribers. The affected group is therefore a small slice of the customer base, around 1.6% if the comparison is to mobile subscribers alone.
Why It Matters
An NRIC number, date of birth, mobile number and email address together make a strong kit for impersonation. A caller who can recite a victim's NRIC number and birthday sounds convincing. MissLobang and its Chinese-language edition warn about the likely follow-ups: calls claiming to be Simba "handling the breach," fake refund or compensation offers, and scammers posing as bank or government officials. Simba's notice does not mention compensation, so any message offering it should be treated as suspect.
For defenders at other organisations, the key point is that NRIC number plus date of birth is not a secret. Any process that uses those two fields to confirm identity, whether at a call centre, a password reset or a SIM swap request, now has 23,549 more people whose details may be in criminal hands. Telcos are an obvious target for this, because SIM swap fraud lets an attacker intercept one-time passwords (OTPs) sent by SMS.
Context on UNC3886: three lower-tier sources (genova14.org, gufoteca.org and seostupidity.com) describe a separate espionage campaign by the China-linked group UNC3886 against Singapore's four main telcos, Simba included. Singapore's Cyber Security Agency (CSA) responded with a multi-agency effort called Operation Cyber Guardian. These sources do not agree on the timeline. Two say the campaign was disclosed in July 2025 ("last year"), while one describes it as ongoing. Two of them also say authorities found no evidence that customer personal data was taken in that campaign. No source links the September 2026 breach to UNC3886 or to any other threat actor. We mention the campaign only because it shows Simba's infrastructure has been targeted by state-backed attackers before. It is not an attribution.
The Attack Technique
The cause is unknown. Simba has not said whether the breach came from an outside intrusion, a misconfigured system, a third-party vendor or an insider. It has not named a threat actor, and there is no public ransom demand or leak-site listing. Simba's wording, that it "resolved" the issue within about a day and is reviewing measures to protect "core infrastructure and systems," fits a contained exposure better than a long-running intrusion, but that is our reading, not something the company has said. It is also unclear whether the data was actually taken or only exposed. We will update this brief if Simba or the PDPC releases findings.
What Organizations Should Do
- Stop using NRIC number and date of birth as proof of identity. Call centres, account recovery and SIM replacement should require something the customer has, such as an in-app confirmation, a passkey or an in-person check with the physical ID card.
- Tighten SIM swap and number porting controls. Telcos and other operators should add cooling-off periods, check with the existing device before a swap, and flag swaps on numbers linked to recent breaches.
- Move away from SMS OTP for high-value accounts. Banks and fintechs should favour app-based authentication or passkeys, since breached mobile numbers make SMS-based attacks easier.
- Watch for brand impersonation. Organisations that notify customers by email after a breach should publish exactly what the notice looks like and where it comes from. Their own notices should not contain links asking customers to log in or pay.
- Keep an inventory of databases that hold NRIC numbers. Find stores of customer data that are exposed to the internet or reachable by third parties, and cut access to only what is necessary.
- Brief frontline staff. Customer-facing teams should expect social engineering calls that use the leaked data, and should report scams to ScamShield on 1799.
Sources: Simba data breach exposes personal details of 23,500 customers The... | SIMBA Data Breach: 23,549 Customers' NRIC Numbers and Birth Dates E... | China's UNC3886: A Cyber Espionage Threat to Singapore's Telecom Se... | Singapore's Telcos Thwart Major Cyberattack: Operation Cyber Guardi... | Chinese Cyberspies Breach Singapore's Top Telcos: What You Need to... | SIMBA 资料外泄: 23,549 名顾客的身份证号码和出生日期曝光, 现在该怎么做 MissLobang | Personal information of over 23,500 Simba customers leaked in data... | More than 23,500 Simba customers affected in data breach involving...