-
A threat actor posted on a cybercrime forum claiming to have records of thousands of Singapore visa applicants.
-
This alleged data leak could expose passport details, names, birth dates, nationalities and other sensitive data that could fuel identity fraud, phishing, and all kinds of scams.
-
BitSight has listed the incident, but no statement from any Singapore authority confirming any such breach.
A cybercrime forum user advertised a database allegedly holding over 700,000 Singapore visa applicant records. The seller claims the records date from 2025 and describes the data as “Recent / Fresh.” The post also includes a downloadable database and sample records.
There is, however, a major reason to treat the claim with caution. Some visible samples carry an “OLD DATA” label. The post also does not name the Singapore government agency, visa provider, or system that supposedly lost the data. So the size of the database, the source, and whether it’s fresh or old data is still unclear.
On September 1, 2026, BitSight added the incident to its public data breach tracker. The site described it as a Singapore visa applicant database breach exposing over 700,000 records. That gives the claim more visibility, but it does not prove that Singapore’s visa system suffered a confirmed breach.
What the Alleged Database Contains
The forum listing claims the database holds many details tied to visa applications. The alleged fields include applicant names, nationalities, dates of birth and gender. The post also claims to contain passport numbers and other passport-related details.
Other fields reportedly include visa type, visa duration, application numbers and serial numbers. The seller also lists submission and collection details, delivery information, and record creation and modification times.
If genuine, this would be sensitive information. A criminal could use several of these details to make a scam look real. A fake message could mention a person’s name, nationality, passport information or visa status. That could make a victim more likely to trust the sender.
Still, the seller’s field list does not prove that every record contains all of these details.
Singapore Visa Process Involves Multiple Channels and Lots of Data Collections
The Immigration and Checkpoints Authority (ICA) handles Singapore’s visa processing. Its website provides visa application services and information for foreign visitors.
ICA’s privacy statement says the agency collects and uses personal data from people who use its services. It defines personal data as information that can identify a person, either on its own or when combined with other information available to ICA.
Singapore’s immigration process can also involve third parties. The Ministry of Home Affairs said in January 2026 that people may use third parties to prepare immigration applications, including applications for visas, permanent residence and citizenship.
This matters when trying to trace the alleged database. A database held by an outside visa service would point to a different incident from a breach of an ICA system. The forum post does not identify the organization that supposedly held the records.
The fact that the alleged fields resemble information used in visa applications also does not prove where the database came from.
The “Fresh” Data Claim Raises Questions
The threat actor calls the database recent and fresh. Yet some samples reportedly carry the words “OLD DATA.” That creates an obvious question: how old is the information?
The database could combine records from different periods. The seller could also be recycling an older dataset and presenting it as new. Another possibility is that only some sample records are old. But there isn’t enough evidence to answer that question.
The 700,000 count, therefore, remains just a mere claim. It should not be reported as the confirmed number of people affected.
BitSight has Recorded the Claim
BitSight’s data breach tracker provides the main independent public reference found for the incident.
Its September 1 listing says a recent breach involving more than 700,000 Singapore visa applicant records had been disclosed. BitSight says its underground breach data comes from deep-web, dark-web, social and open-source intelligence sources.
The company also says it uses automated analysis to classify and remove duplicate datasets. It says posts are validated where possible by checking reputation signals within underground communities.
That adds useful context to the report. However, the public listing does not identify an affected Singapore agency or company. It also does not establish that the records came from a live ICA system.
So BitSight’s listing confirms that the claim appeared in underground sources and entered its breach tracking system. It does not independently confirm the database’s origin or the full record count.
No Official Confirmation Found
A review of current Singapore government sources found no public confirmation of this alleged incident from ICA or the Ministry of Home Affairs as of September 2, 2026.
ICA’s public website remains active and continues to provide visa services and application information. The agency also warns people about scammers who impersonate ICA officers. That warning matters because exposed visa information could help criminals make impersonation scams more convincing.
Singapore has seen some data breaches involving government databases before. Hackers stole personal info belonging to around 1.5 million patients from Singapore’s public healthcare system in 2018.
The authorities confirmed the incident and called it deliberate and targeted. The current visa claim has not reached that level of official confirmation.
A November 2025 dark web claim alleged the sale of 10 million Singapore citizen records for $10,000. Authorities found no evidence of a government database breach, while the dataset’s small size and suspected fake entries raised doubts about the claim.
Risks the Latest Leak Could Pose for Visa Applicants
If the database proves genuine, the information could support targeted scams and identity fraud. Passport numbers are sensitive because criminals can combine them with other personal details. Visa details may serve as a way to justify scammers’ calls.
For instance, an attacker may disguise themselves as an immigration agent and claim that the visa should be renewed. They could ask the victim for money, documents, or their bank OTPs. ICA warns that no government representative will ever call or text people asking for such information. It also tells people to verify suspicious messages.
That advice remains useful even if the current database claim turns out to be false. Applicants should not assume a message is genuine because it contains accurate personal details. Criminals can obtain such details from older leaks, public sources and other databases.
What Remains Unknown
A lot of important details concerning this incident remain unclear. First, there’s no sample to prove whether the database is genuine. Second, the original source has not been identified. Third, the number of unique people in the dataset remains unknown.
It is also unclear whether the records came from ICA, an authorized visa agent, an overseas mission, or another service provider. The age of the data remains another concern. The seller’s “2025” and “Recent / Fresh” claims do not sit neatly with sample records marked “OLD DATA.”
Those gaps prevent a firm conclusion about the incident. For now, the most accurate description is an alleged leak of more than 700,000 Singapore visa-related records advertised on a cybercrime forum and subsequently listed by BitSight.
The available evidence does not support calling it a confirmed breach of Singapore’s immigration system. Until Singapore authorities, the alleged data owner, or another reliable investigation verifies the records, the database’s authenticity, origin, scope, and freshness remain unconfirmed.