書面答覆 · 2026-09-08 · 屆國會 15
ASPIRE 2A 與科技研究局 Exanet 網路安全事件:調查報告是否公開及所採取的資料恢復措施
工人黨議員嚴燕松(Mr Gerald Giam Yean Song)書面詢問貿工部長(能源與工業):新加坡國家超級計算中心(NSCC)ASPIRE 2A 與科技研究局(A*STAR)Exanet 網路近期的網路安全事件,完整調查報告是否公開;採取了哪些恢復、驗證和加固措施;是否有資料外洩。陳詩龍博士(Dr Tan See Leng)書面答覆:兩起事件(2026 年 5 月 22 日、7 月 24 日)發生後,受影響系統被迅速隔離調查,外部鑑證專家查明根本原因,未發現數據受損或外洩證據;報告不會公開,以免為惡意行為者提供有用資訊。系統經重建、掃描和檢查後才恢復使用,並收緊訪問控制、加強終端防護;NSCC 與 A*STAR 已加快紅隊演練等既有計劃,經驗已推廣至整個科研基礎設施。
為什麼重要
國家超算 ASPIRE 2A 與科技研究局 Exanet 兩起事件未發現數據外洩證據,但調查報告不會公開
關鍵要點
- • NSCC 的 ASPIRE 2A 系統(2026 年 5 月 22 日)與 A*STAR 的 Exanet 網路(2026 年 7 月 24 日)發生事件後,受影響系統被迅速隔離並立即展開調查。
- • 外部鑑證專家受聘查明每起事件的根本原因;詳細調查未發現兩起事件有資料受損或外洩的證據。
- • 詳細調查報告不會公開,理由是可能為惡意行為者提供有用資訊。
- • 受影響系統和裝置經重建、掃描攻擊殘留、檢查並獲准後才恢復服務,同時立即收緊訪問控制的執行並加強終端防護。
- • NSCC 與 A*STAR 加快事件前已啟動的網路安全計劃,包括通過更復雜的紅隊演練加強威脅模擬,經驗教訓已應用於整個科研基礎設施。
政府表示兩起事件均已處置,未發現數據受損或外洩,並已加強安全措施、加快既有網路安全計劃。政府拒絕公開詳細調查報告,理由是這可能為惡意行為者提供有用資訊。
提問議員嚴燕松(工人黨)要求公開完整調查報告,並追問具體的恢復、驗證和加固措施以及是否有資料外洩、哪些資料受損。
國家超算與科研網路已被當作需重點防護的 AI 算力基礎設施;政府在事件披露上採取結論公開、細節保密的做法,議會對透明度的要求與安全考量之間的張力可能持續。
“詳細調查未發現兩起事件中有任何資料受損或外洩的證據。”
參與人員 (2)
完整譯文(中文)
Hansard 原始記錄 · 2026-09-26
53 號,嚴燕松先生詢問貿工部長(能源與工業):(a) 近期影響新加坡國家超級計算中心 ASPIRE 2A 系統和科技研究局 Exanet 網路的網路安全事件,完整調查報告是否會公開發布;(b) 採取了哪些具體的恢復、驗證和加固措施;以及 (c) 是否有任何資料被外洩,如果有,哪些資料受到損害。
陳詩龍博士:2026 年 5 月 22 日新加坡國家超級計算中心(NSCC)ASPIRE 2A 系統及 2026 年 7 月 24 日科技研究局(A*STAR)Exanet 網路發生網路安全事件後,受影響的系統被迅速隔離,並立即展開調查,以確定事件的性質、範圍和影響。
當局也聘請了外部鑑證專家調查並確定每起事件的根本原因。詳細調查未發現兩起事件中有任何資料受損或外洩的證據。詳細調查報告不會公開發布,因為這樣做可能為惡意行為者提供有用的資訊。
受影響的 ASPIRE 2A 系統和 Exanet 網路中的計算裝置都已重建、掃描是否有任何攻擊殘留、經過檢查並獲准使用後才恢復服務。當局也立即實施了額外的安全措施,包括更嚴格地執行訪問控制和加強終端防護,以強化防範未經授權訪問的保障。
NSCC 和 A*STAR 定期檢討其網路安全規程,確保這些規程保持穩健和與時俱進,並已加快推進事件發生前就已啟動的網路安全計劃,例如通過更復雜的紅隊演練加強網路安全威脅模擬。從這些事件中汲取的教訓也已應用於我們的整個科研基礎設施。
英文原文
SPRS Hansard 原始記錄 · 抓取日期:2026-09-26
53 Mr Gerald Giam Yean Song asked the Minister for Trade and Industry (Energy and Industry) (a) whether full investigation reports on the recent cybersecurity incidents affecting National Supercomputing Centre Singapore's ASPIRE 2A and A*STAR's Exanet network will be publicly released; (b) what specific recovery, validation and hardening measures were taken; and (c) whether any data was exfiltrated and, if so, what data was compromised.
Dr Tan See Leng : Following the cybersecurity incidents affecting the National Supercomputing Centre Singapore's (NSCC's) ASPIRE 2A system on 22 May 2026 and Agency for Science, Technology and Research's (A*STAR's) Exanet network on 24 July 2026, the affected systems were promptly isolated, and investigations were immediately conducted to establish the nature, extent and impact of the incidents.
External forensic specialists were also engaged to investigate and establish the root cause in each case. Detailed investigations found no evidence of data compromise or exfiltration in either incident. The detailed investigation reports will not be publicly released, as doing so could provide information useful to malicious actors.
The affected ASPIRE 2A system and computing devices in the Exanet network were rebuilt, scanned for any residual elements of the attack, inspected and cleared for use before being returned to service. Additional security measures, including tighter enforcement of access controls and enhancement of endpoint protection, were immediately implemented to strengthen safeguards against unauthorised access.
NSCC and A*STAR conduct regular reviews of their cybersecurity protocols to ensure these remain robust and current and have accelerated their cybersecurity initiatives which had commenced prior to the incidents, such as enhancing cybersecurity threat simulation through more sophisticated red teaming. Lessons learnt from these incidents have also been applied across our research infrastructure.