Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,033 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

1case from 1 jurisdiction
€11,664Total of monetary amounts
€11,664Largest single case: Ezynetic Pte. Ltd.
€11,664Median per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q4 20230–
Q1 20240–
Q2 20240–
Q3 20240–
Q4 20240–
Q1 20250–
Q2 20250–
Q3 20251€11,664
Q4 20250–
Q1 20260–
Q2 20260–
Q3 20260–
Q4 20260–

1 case

3 Jul 2025 Ezynetic Pte. Ltd.Ezynetic: 17,500 SGD after ransomware at IT service provider for moneylenders SingaporeData processors €11,664

The SaaS provider operates a system for licensed moneylenders that is linked to the Moneylenders Credit Bureau and into which its clients enter data on loan applicants and borrowers; in June 2024 an attacker used a vulnerable web application to take over the SQL server's system administrator account, which was protected only by an easily guessed password, deleted databases and exfiltrated data on 190,589 individuals including credit report data, which was offered for sale on the dark web. The Personal Data Protection Commission (PDPC, Singapore's data protection authority) found a breach of the Protection Obligation (inadequate access control, no vulnerability assessments or penetration tests) and, given the company's role as a provider processing client data entrusted to it, considered a fine of 17,500 SGD appropriate; it rejected the request for a waiver or reduction. In addition, the company must obtain the Cyber Trust mark certification of the Cyber Security Agency of Singapore (CSA) for its new network within nine months.

What organisations can take from it

Privileged default accounts such as a database server administrator must be disabled or secured with strong passwords and additional controls, and systems must be tested regularly for vulnerabilities.

Relevance to training and awareness

Strong passwords and protection of privileged administrator accounts

Authority / court
Personal Data Protection Commission (PDPC)
Area of law
Data protection · Data processors
Legal basis
Section 24(a) PDPA 2012 (Protection Obligation); Section 48J PDPA (Financial Penalty); Section 48I PDPA (Directions)
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Repeat case
no
Mitigating circumstances
Cooperation, admission under the Expedited Decision Procedure and first breach of the PDPA.
Published
3 Jul 2025

Original amount 17,500 SGD, converted at the ECB reference rate of 3 Jul 2025.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

Ready for training that actually lands?

Try the combination for free: automated administration for you, learning formats that fit your team, with no minimum or credit card.

Start 14-day free trial