Singapore City Development Company Limited (SINGCONS) Listed by thegentlemen Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Singapore City Development Company Limited (SINGCONS) was listed by thegentlemen ransomware group on November 24, 2025, after internal files were exfiltrated in a ransomware attack. Individuals who may have had dealings with SINGCONS should check their accounts and monitor for suspicious activity.
On November 24, 2025, the ransomware group thegentlemen listed Singapore City Development Company Limited (SINGCONS) on its site, stating that internal files had been taken during an attack. The number of individuals whose information may be involved remains unknown, and no further confirmation of the incident has been made public. For people connected to the company through employment, contracts, property transactions or regulatory filings, the listing raises the possibility that personal or operational records could surface without clear details on scope or verification.
Breaking down the breach
The only confirmed public detail is the group’s listing of SINGCONS and the statement that internal files were allegedly exfiltrated. No date of the intrusion, volume of data, or method of access has been disclosed. The organisation has not issued a statement confirming or denying the claim, and independent verification of the files’ contents or the attack’s timeline is not available from public sources.
The group behind it: thegentlemen
Thegentlemen is a ransomware operator that maintains a leak site to list victims and, in some cases, publish material obtained during intrusions. Public reporting on the group shows a pattern of targeting organisations across multiple sectors and regions, typically combining encryption with the threat of data release. In this instance the group claims SINGCONS appears on its listing; that claim has not been corroborated by the company or by independent investigators.
About Singapore City Development Company Limited (SINGCONS)
SINGCONS is a Singapore-headquartered firm active in construction and real-estate development, primarily in Vietnam and neighbouring markets. Its work spans land acquisition, master planning, infrastructure, construction contracting and ongoing property management for residential, commercial and mixed-use projects. Organisations of this type routinely collect and store records relating to land ownership, contractor agreements, employee data, financial transactions and regulatory submissions across multiple jurisdictions.
What data was at risk
The listing refers only to “internal files” without naming specific categories. The exact contents therefore remain unconfirmed. Companies in the construction and real-estate sector commonly hold personal identifiers, contract details, financial information and project documentation; whether any of these categories were present in the exfiltrated material has not been established.
The real-world impact
Until the files are verified or the organisation provides further information, the practical consequences for individuals cannot be quantified. Potential exposure could involve personal details used in identity-related activity or commercial records that affect contractual relationships. For the company, the incident adds to the operational and regulatory workload of assessing what, if anything, was taken and meeting any notification obligations that may apply under Singapore or Vietnamese data-protection rules.
What to do if you're exposed
Individuals who have dealt with SINGCONS can monitor their email accounts and official correspondence for unusual activity. A practical first step is to run a free exposure scan of the email address associated with any past dealings to check whether it appears in known breach data sets. Where accounts show signs of compromise, changing passwords and enabling multi-factor authentication on linked services reduces further risk. Organisations should follow established incident-response procedures and consult legal or regulatory guidance applicable to their jurisdiction.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
3E Accounting Listed by thegentlemen Ransomware GroupStewart Engenharia Listed by thegentlemen Ransomware GroupEver Green Industria e Comercio Ltda Listed by thegentlemen Ransomware Group2GO Group Listed by thegentlemen Ransomware GroupLatest breaches
Publicly posted by thegentlemen — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.