The SLA Breach Isn't About Old Data. It's About the Future of Encryption.
- corporatesurvivord
- Jul 4
- 4 min read

On 3 July 2026, the Singapore Land Authority disclosed that personal data belonging to approximately 70,000 individuals had been compromised through a cloud environment managed by its vendor IBM. The data — names, NRIC numbers, and past property addresses — came from a testing dataset created in 1998. It was supposed to contain only mock, anonymised records. It didn't.
SLA was quick to note that its live systems remained unaffected. Technically accurate. But NRIC numbers don't expire. Property ownership history doesn't expire. And the reputational damage didn't wait for an operational system to fail — trust was eroded the moment the breach was disclosed, regardless of when the data was created.
Now layer in quantum computing, and the implications become considerably more serious.
The encryption your organisation is running today has an expiry date
The SLA breach is a third-party risk story. But it is also a preview of a different, slower breach that most organisations haven't priced into their risk register yet.
The attack is called "harvest now, decrypt later." Adversaries — particularly state-sponsored actors — are capturing encrypted network traffic and sensitive data today and archiving it. They don't need to read it now. They are waiting for quantum computing hardware to catch up, at which point today's public-key encryption could become vulnerable and previously captured data could be decrypted.
The breach is invisible when it happens. Like the SLA dataset sitting in IBM's testing environment for years before anyone noticed, the exposure can remain dormant for a long time before it surfaces — by which point, the damage is already done.
This is not hypothetical. In late 2024, researchers demonstrated another step forward in quantum cryptanalysis, highlighting the steady progress in the field even though today's quantum computers remain far from breaking production-scale RSA. By early 2026, subsequent research had reduced the estimated number of physical qubits needed to break RSA-2048 from around 20 million to fewer than one million. The direction of travel is becoming clearer, even if the destination remains uncertain.
While experts disagree on the exact timeline, some researchers now place the earliest plausible window for a cryptographically relevant quantum computer around 2029 to 2032, although considerable uncertainty remains. NIST read the same signals and, in August 2024, finalised its first three post-quantum cryptography standards, urging organisations to begin migration immediately. By publishing those standards, the world's leading cryptographic standards body effectively signalled that today's public-key cryptography cannot be relied upon indefinitely.
Why this is an enterprise governance issue, not just an IT one
The SLA incident illustrates a pattern that applies directly here: the data most exposed by inadequate controls is rarely the data you were thinking about when you designed those controls. In SLA's case, it was a 28-year-old test dataset that slipped through anonymisation. In the quantum context, it is today's encrypted board communications, M&A documents, regulatory filings, intellectual property, and customer data held under PDPA obligations — harvested now, decrypted later.
Post-quantum migration is a governance decision, not an IT ticket. MAS was already running cross-border post-quantum cryptography trials with Banque de France in late 2024. Regulatory expectations around post-quantum cryptography are also likely to become increasingly explicit under Singapore's Technology Risk Management framework. Institutions that wait for formal requirements before acting will almost certainly be playing catch-up. That is always the most expensive way to fix anything. CSA's Quantum Readiness Index and Singtel's hybrid quantum-safe network for enterprises are already available. The groundwork is already being laid.
What to do now
Migration takes years. For large enterprises with complex legacy environments, completing a full cryptographic migration can take a decade or more. If a cryptographically relevant quantum computer arrives around the start of the next decade, organisations beginning in 2026 are already operating within a compressed window.
Inventory first. Map where your long-lived sensitive data sits, what encryption protects it, and how long it needs to remain confidential. CSA's Quantum Readiness Index is the fastest structured starting point. Apply the SLA lesson here: the data most at risk is often what you've stopped thinking about — old test environments, archived records, legacy systems handed to vendors.
Audit your vendors. The SLA breach is a third-party risk failure. Quantum vulnerability in your supply chain follows the same pattern with a much longer fuse. Ask your cloud providers and critical vendors whether they have a post-quantum cryptography roadmap. AWS, Google Cloud and Microsoft Azure have all begun introducing or expanding support for hybrid post-quantum TLS across their platforms. A vendor without a clear roadmap should be treated as a governance risk signal worth escalating.
Layer, don't replace. Start by adding post-quantum algorithms alongside existing encryption rather than ripping out your current stack — which is also the approach taken by Singtel's enterprise quantum-safe offering. Prioritise data with the longest confidentiality horizon first.
For individuals, the lesson is equally relevant. Your NRIC number and property records have surfaced in at least one vendor's testing environment without your knowledge. They may surface elsewhere too. As operating systems, browsers and applications gradually adopt post-quantum cryptography over the coming years, keeping devices updated remains one of the most practical steps you can take. Beyond that, monitor breach notification services for signs that your personal data has been exposed.
Old data is not safe data. And encrypted data is only as safe as the encryption — and the vendors — that protect it.




Comments