IT Brief Asia - Technology news for CIOs & IT decision-makers
Asia
Why telecommunications subscriber records need zero standing privilege

Why telecommunications subscriber records need zero standing privilege

Fri, 2nd Oct 2026 (Today)
Takanori Nishiyama
TAKANORI NISHIYAMA Senior Vice President, APAC & Japan Country Manager Keeper Security

Identity card numbers and birth dates cannot be reset like passwords once they are exposed. Singapore residents hold both for life, and cybercriminals who've stolen this information can keep exploiting it for years to come. Paired with contact details, the leaked records make impersonation calls and messages more convincing to targets. 

Singapore's Personal Data Protection Commission has asked private organisations to stop using identity numbers for authentication by the end of this year. 

Telecommunications subscriber registries hold verified identity data at scale, which makes them high-value targets. While Simba has not disclosed how the breach occurred, the incident illustrates a critical risk: broad internal access rights mean that one compromised account can expose an entire customer database. The 2026 Verizon Data Breach Investigations Report found credential abuse was the initial access vector in 25% of Asia-Pacific breaches, second only to vulnerability exploitation at 42%. Credential compromise remains a persistent threat, which is why controlling who has access to subscriber data matters as much as protecting the data itself.

Organisations must isolate subscriber data systems, restrict database access and move to a zero standing privilege model for administrative access. Just-in-time access limits privileges to approved tasks and removes them once the work is complete. Every session that touches customer identity data should be authenticated, authorised and auditable. Continuous identity threat detection, paired with privileged access management, can flag and end suspicious sessions involving bulk queries or exports.

While subscribers cannot change their identity card numbers after a breach, organisations can still monitor, control and secure who has access to that important data. Removing standing access to subscriber records is the most practical step telecommunications providers can take now to prevent breaches of this nature down the road.