Written reply to PQ on Release of investigation reports into cybersecurity incidents affecting ASPIRE 2A and A*STAR's Exanet network and data recovery measures taken
8 September 2026
Question:
Mr Gerald Giam Yean Song: To ask the Minister for Trade and Industry (Energy and Industry) (a) whether full investigation reports on the recent cybersecurity incidents affecting National Supercomputing Centre Singapore's ASPIRE 2A and A*STAR's Exanet network will be publicly released; (b) what specific recovery, validation and hardening measures were taken; and (c) whether any data was exfiltrated and, if so, what data was compromised.
Written Answer by Minister for Trade and Industry (Energy and Industry) Dr Tan See Leng
1. Following the cybersecurity incidents affecting the National Supercomputing Centre Singapore (NSCC)'s ASPIRE 2A system on 22 May 2026 and A*STAR's Exanet network on 24 July 2026, the affected systems were promptly isolated, and investigations were immediately conducted to establish the nature, extent and impact of the incidents.
2. External forensic specialists were also engaged to investigate and establish the root cause in each case. Detailed investigations found no evidence of data compromise or exfiltration in either incident. The detailed investigation reports will not be publicly released, as doing so could provide information useful to malicious actors.
3. The affected ASPIRE 2A system and computing devices in the Exanet network were rebuilt, scanned for any residual elements of the attack, inspected and cleared for use before being returned to service. Additional security measures, including tighter enforcement of access controls and enhancement of endpoint protection, were immediately implemented to strengthen safeguards against unauthorised access.
4. NSCC and A*STAR conduct regular reviews of their cybersecurity protocols to ensure these remain robust and current, and have accelerated their cybersecurity initiatives which had commenced prior to the incidents, such as enhancing cybersecurity threat simulation through more sophisticated red-teaming. Lessons learnt from these incidents have also been applied across our research infrastructure.
