The names & workplaces of patients with hereditary cancer were allegedly exposed in an "administrative error" at the National Cancer Centre S'pore.
Their emails were apparently listed in the CC field instead of BCC.
➡️ https://bit.ly/4hdcild
Follow us @mothershipsg
Here's the full detailed account of the incident:
Full Details: NCCS Email Data Breach — September 2026
📅 When & Where
- Sent: Sep 18, 2026, ~7:53 PM
- Disclosed: Sep 19, 2026 via The Straits Times & Mothership
- Sender: National Cancer Centre Singapore (NCCS), Cancer Genetics Service
📧 What Happened
- Email: Invitation to "Living with HBOC" — an invitation-only event scheduled for Oct 31, 2026, for people with Hereditary Breast and Ovarian Syndrome (HBOC)
- Mistake: Recipients were listed in CC instead of BCC, exposing everyone's names + email addresses to each other
- Extra exposure: Those using workplace emails had their employers revealed — domains showed companies, foreign embassies, schools
- Scale: One recipient reported >500 addresses visible — "too numerous to count"
⏱️ Timeline of Response
- ~2.5 hours later: NCCS attempted to recall the email
- Follow-up email sent asking recipients to:
- Delete the original message from inbox + trash
- Not forward/share it
- Not save/use any listed addresses
- NCCS stated: "This was an administrative error that affected e-mail addresses only. We are thoroughly reviewing our internal processes."
⚠️ Why It's Serious
- HBOC status = sensitive health/genetic data — links identifiable people directly to a medical condition
- Recipient concerns: unknown people knowing their genetic status; potential impacts on employment, insurance
🔍 Regulatory Status
- Personal Data Protection Commission (PDPC) confirmed it is aware and investigating
- NCCS & SingHealth contacted for comment — no further statement yet
Source: Mothership | The Straits Times
chelshit playing henderson...lol the hope of winning decreases before game start lol(3-0 loss)
villa currently leading sperms, both fighting for who ish less shiettier