Cybersecurity incident at contractor building JRL stations and NEWater factory Sign up now: Get ST's newsletters delivered to your inbox SINGAPORE – A cybersecurity incident has been reported at the contractor responsible for building three Jurong Region Line (JRL) MRT stations and the new Changi NEWater Factory 3. Data relating to the two projects was compromised at Shanghai Tunnel Engineering Co (Singapore), a civil engineering and construction company, although it is unclear when this had taken place. In response to queries on April 27, the Land Transport Authority (LTA) said it is aware of the incident, which has since been reported to the police and the relevant authorities. The authority added that the incident has not impacted the ongoing construction of the MRT line, and that it has temporarily suspended the construction company’s access to LTA’s digital systems as a precaution. Meanwhile, national water agency PUB said Shanghai Tunnel Engineering Co (Singapore) has no access to its digital systems. Its investigation showed that no sensitive data pertaining to the Changi NEWater Factory 3 had been stolen, with the compromised data consisting of project tender documents. These documents are publicly available on the government procurement portal GeBIZ, said a PUB spokesman, who stressed that the agency takes a “serious view” of cybersecurity and has reminded the contractor to review its measures. Checks by The Straits Times, including on ransomware portals and hacker forums where stolen data is typically leaked, yielded no results. Shanghai Tunnel Engineering Co (Singapore) told ST on April 28 that it recently identified a cybersecurity incident and took immediate steps to contain the situation. It did not state when the incident happened. The company added that it is working with an external cybersecurity specialist to support its investigation. “We are cooperating fully with the relevant authorities and kindly