Both failures happen on ordinary project days, not during a cyber attack.
The PDPC has published an advisory drawn from its own investigation findings, and it names two common lapses behind recent breaches. The first is migration. The second is detection. Section 24 of the PDPA already requires reasonable security arrangements for personal data in your possession or under your control. - Migrations break quietly. A mismatch between old and new fields can post statements to the wrong customers.
- Test environments leak. PDPC asks you to keep them offline and to check no credentials or personal data are left behind.
- Run VAPT before go live. Vulnerability assessment and penetration testing belongs before launch and after any change.
- Nobody watches the database. Without alerts on bulk downloads, a breach using stolen credentials can run for months.
Both lapses are cheap to close and expensive to discover later.