# ASPIRE 2A 与科技研究局 Exanet 网络安全事件：调查报告是否公开及所采取的数据恢复措施

- 日期: 2026-09-08
- 收录: 2026-09-26
- 相关方: Mr Gerald Giam Yean Song · Dr Tan See Leng
- 来源: https://sprs.parl.gov.sg/search/#/sprs3topic?reportid=written-answer-24497
- sgai: https://sgai.md/zh/debates/written-answer-24497/
- 许可：sgai 自产内容（摘要、译文、分析）CC BY 4.0，署名并链接 sgai.md 即可；逐字原文（国会记录、演讲、字幕、政策原文）© 原权利人，仅供引用。条款：https://github.com/meltflake/sgai/blob/main/DATA-LICENSE.md

## 为什么重要

国家超算 ASPIRE 2A 与科技研究局 Exanet 两起事件未发现数据外泄证据，但调查报告不会公开

## 摘要

工人党议员严燕松（Mr Gerald Giam Yean Song）书面询问贸工部长（能源与工业）：新加坡国家超级计算中心（NSCC）ASPIRE 2A 与科技研究局（A*STAR）Exanet 网络近期的网络安全事件，完整调查报告是否公开；采取了哪些恢复、验证和加固措施；是否有数据外泄。陈诗龙博士（Dr Tan See Leng）书面答复：两起事件（2026 年 5 月 22 日、7 月 24 日）发生后，受影响系统被迅速隔离调查，外部鉴证专家查明根本原因，未发现数据受损或外泄证据；报告不会公开，以免为恶意行为者提供有用信息。系统经重建、扫描和检查后才恢复使用，并收紧访问控制、加强终端防护；NSCC 与 A*STAR 已加快红队演练等既有计划，经验已推广至整个科研基础设施。

## 要点

- NSCC 的 ASPIRE 2A 系统（2026 年 5 月 22 日）与 A*STAR 的 Exanet 网络（2026 年 7 月 24 日）发生事件后，受影响系统被迅速隔离并立即展开调查。
- 外部鉴证专家受聘查明每起事件的根本原因；详细调查未发现两起事件有数据受损或外泄的证据。
- 详细调查报告不会公开，理由是可能为恶意行为者提供有用信息。
- 受影响系统和设备经重建、扫描攻击残留、检查并获准后才恢复服务，同时立即收紧访问控制的执行并加强终端防护。
- NSCC 与 A*STAR 加快事件前已启动的网络安全计划，包括通过更复杂的红队演练加强威胁模拟，经验教训已应用于整个科研基础设施。

## 全文

53 号，严燕松先生询问贸工部长（能源与工业）：(a) 近期影响新加坡国家超级计算中心 ASPIRE 2A 系统和科技研究局 Exanet 网络的网络安全事件，完整调查报告是否会公开发布；(b) 采取了哪些具体的恢复、验证和加固措施；以及 (c) 是否有任何数据被外泄，如果有，哪些数据受到损害。

陈诗龙博士：2026 年 5 月 22 日新加坡国家超级计算中心（NSCC）ASPIRE 2A 系统及 2026 年 7 月 24 日科技研究局（A*STAR）Exanet 网络发生网络安全事件后，受影响的系统被迅速隔离，并立即展开调查，以确定事件的性质、范围和影响。

当局也聘请了外部鉴证专家调查并确定每起事件的根本原因。详细调查未发现两起事件中有任何数据受损或外泄的证据。详细调查报告不会公开发布，因为这样做可能为恶意行为者提供有用的信息。

受影响的 ASPIRE 2A 系统和 Exanet 网络中的计算设备都已重建、扫描是否有任何攻击残留、经过检查并获准使用后才恢复服务。当局也立即实施了额外的安全措施，包括更严格地执行访问控制和加强终端防护，以强化防范未经授权访问的保障。

NSCC 和 A*STAR 定期检讨其网络安全规程，确保这些规程保持稳健和与时俱进，并已加快推进事件发生前就已启动的网络安全计划，例如通过更复杂的红队演练加强网络安全威胁模拟。从这些事件中汲取的教训也已应用于我们的整个科研基础设施。

## Hansard (original, English)

© Parliament of Singapore — reproduced for reference only.

53 Mr Gerald Giam Yean Song asked the Minister for Trade and Industry (Energy and Industry) (a) whether full investigation reports on the recent cybersecurity incidents affecting National Supercomputing Centre Singapore's ASPIRE 2A and A*STAR's Exanet network will be publicly released; (b) what specific recovery, validation and hardening measures were taken; and (c) whether any data was exfiltrated and, if so, what data was compromised.

Dr Tan See Leng : Following the cybersecurity incidents affecting the National Supercomputing Centre Singapore's (NSCC's) ASPIRE 2A system on 22 May 2026 and Agency for Science, Technology and Research's (A*STAR's) Exanet network on 24 July 2026, the affected systems were promptly isolated, and investigations were immediately conducted to establish the nature, extent and impact of the incidents.

External forensic specialists were also engaged to investigate and establish the root cause in each case. Detailed investigations found no evidence of data compromise or exfiltration in either incident. The detailed investigation reports will not be publicly released, as doing so could provide information useful to malicious actors.

The affected ASPIRE 2A system and computing devices in the Exanet network were rebuilt, scanned for any residual elements of the attack, inspected and cleared for use before being returned to service. Additional security measures, including tighter enforcement of access controls and enhancement of endpoint protection, were immediately implemented to strengthen safeguards against unauthorised access.

NSCC and A*STAR conduct regular reviews of their cybersecurity protocols to ensure these remain robust and current and have accelerated their cybersecurity initiatives which had commenced prior to the incidents, such as enhancing cybersecurity threat simulation through more sophisticated red teaming. Lessons learnt from these incidents have also been applied across our research infrastructure.
