# Release of Investigation Reports into Cybersecurity Incidents Affecting ASPIRE 2A and A*STAR Exanet Network and Data Recovery Measures Taken

- Date: 2026-09-08
- Added: 2026-09-26
- Who: Mr Gerald Giam Yean Song · Dr Tan See Leng
- Source: https://sprs.parl.gov.sg/search/#/sprs3topic?reportid=written-answer-24497
- sgai: https://sgai.md/debates/written-answer-24497/
- License: sgai-authored content (summaries, translations, analysis) is CC BY 4.0 — attribute and link to sgai.md. Verbatim source text (Hansard, speeches, transcripts, policy documents) remains © its original rights holders and is reproduced for reference only. Terms: https://github.com/meltflake/sgai/blob/main/DATA-LICENSE.md

## Why it matters

Investigations into the ASPIRE 2A and Exanet incidents found no evidence of data exfiltration, but the reports will not be released.

## Summary

Workers' Party MP Gerald Giam Yean Song asked the Minister for Trade and Industry (Energy and Industry) whether full investigation reports into the recent cybersecurity incidents affecting the National Supercomputing Centre Singapore's (NSCC) ASPIRE 2A and A*STAR's Exanet network will be released, what recovery, validation and hardening measures were taken, and whether any data was exfiltrated. Dr Tan See Leng replied that after the incidents on 22 May 2026 and 24 July 2026, the affected systems were promptly isolated and investigated, with external forensic specialists engaged to establish root causes; no evidence of data compromise or exfiltration was found. The reports will not be released, as they could provide information useful to malicious actors. Affected systems were rebuilt, scanned, inspected and cleared before returning to service, and access controls and endpoint protection were tightened. NSCC and A*STAR have accelerated existing initiatives such as more sophisticated red teaming, and lessons have been applied across the research infrastructure.

## Key points

- After the incidents affecting NSCC's ASPIRE 2A system (22 May 2026) and A*STAR's Exanet network (24 July 2026), the affected systems were promptly isolated and investigations began immediately.
- External forensic specialists were engaged to establish the root cause in each case; detailed investigations found no evidence of data compromise or exfiltration in either incident.
- The detailed investigation reports will not be publicly released, as they could provide information useful to malicious actors.
- Affected systems and devices were rebuilt, scanned for residual elements of the attack, inspected and cleared before returning to service, with tighter enforcement of access controls and enhanced endpoint protection implemented immediately.
- NSCC and A*STAR have accelerated cybersecurity initiatives begun before the incidents, including more sophisticated red teaming for threat simulation, and lessons learnt have been applied across the research infrastructure.

## Full text

© Parliament of Singapore — reproduced for reference only.

53 Mr Gerald Giam Yean Song asked the Minister for Trade and Industry (Energy and Industry) (a) whether full investigation reports on the recent cybersecurity incidents affecting National Supercomputing Centre Singapore's ASPIRE 2A and A*STAR's Exanet network will be publicly released; (b) what specific recovery, validation and hardening measures were taken; and (c) whether any data was exfiltrated and, if so, what data was compromised.

Dr Tan See Leng : Following the cybersecurity incidents affecting the National Supercomputing Centre Singapore's (NSCC's) ASPIRE 2A system on 22 May 2026 and Agency for Science, Technology and Research's (A*STAR's) Exanet network on 24 July 2026, the affected systems were promptly isolated, and investigations were immediately conducted to establish the nature, extent and impact of the incidents.

External forensic specialists were also engaged to investigate and establish the root cause in each case. Detailed investigations found no evidence of data compromise or exfiltration in either incident. The detailed investigation reports will not be publicly released, as doing so could provide information useful to malicious actors.

The affected ASPIRE 2A system and computing devices in the Exanet network were rebuilt, scanned for any residual elements of the attack, inspected and cleared for use before being returned to service. Additional security measures, including tighter enforcement of access controls and enhancement of endpoint protection, were immediately implemented to strengthen safeguards against unauthorised access.

NSCC and A*STAR conduct regular reviews of their cybersecurity protocols to ensure these remain robust and current and have accelerated their cybersecurity initiatives which had commenced prior to the incidents, such as enhancing cybersecurity threat simulation through more sophisticated red teaming. Lessons learnt from these incidents have also been applied across our research infrastructure.
