IT team lead attached to State Courts installed remote desktop app risking 18,000 files, gets jail一名隶属于州法院的IT团队负责人安装远程桌面应用程序,导致18000个文件面临泄露风险,最终被判入狱。
Janarthanan Tamil Kovan had granted his foreign acquaintance remote access to the government-managed laptop as Janarthanan wanted to use it to take a cyber security examination.

Janarthanan Tamil Kovan had granted his foreign acquaintance remote access to the government-managed laptop as Janarthanan wanted to use it to take a cyber security examination.
A view of the State Courts building in Singapore. (File photo: CNA/Jeremy Long)
This audio is generated by an AI tool.
SINGAPORE: Because his personal laptop was faulty, an IT team leader in charge of the State Courts' cloud system team decided to use his government-managed device containing over 18,000 restricted files to take a cyber security examination.
In doing so, he granted an acquaintance remote access to his laptop, causing unauthorised computer modification and risking protected files which included login credentials and secret keys of the State Courts' network.
Janarthanan Tamil Kovan, 42-year-old Indian national, was sentenced to 28 weeks' jail on Monday (Sep 28).
He pleaded guilty to a charge each of endangering the safety of documents belonging to the State Courts and the Government of Singapore under the Official Secrets Act, and for causing an unauthorised modification of the laptop.
A third charge was taken into consideration.
Janarthanan was employed as a service delivery manager with Lenovo PCCW Solutions in 2017.
In June 2024, he was attached to the State Courts as an external IT vendor.
He was a team leader of the State Courts' cloud system team, which manages various systems and applications of the courts.
Janarthanan was issued with a Lenovo Thinkpad laptop, a government-managed device governed by GovTech's acceptable use policy and Lenovo's own policy.
Both policies prohibit unauthorised access and modifications to the laptop.
The laptop was protected and onboarded onto GovTech's security suite for engineering endpoint devices (SEED), a mobile device management platform enabling access to the judiciary's Government on Commercial Cloud system. This includes access to the backend infrastructure of the State Courts' applications and systems.
On Aug 4, 2025, Janarthanan decided to use the laptop to take an examination administered by ISACA, an international professional association focused on information technology governance, to be certified as a certified information security Manager.
Because his personal laptop had a faulty screen, Janarthanan decided to use his work laptop.
However, when he logged onto ISACA's system, he realised the laptop was unable to clear pre-examination security checks before he could take the exam.
Janarthanan reached out to a person he knew as Hari Balan, whom he had communicated with previously on WhatsApp about IT-related courses. Hari Balan had an IP address in India, court documents stated.
He shared the security checks issue with Hari Balan, and the latter offered his help and asked Janarthanan to download "UltraViewer". This was a remote desktop application that would allow Hari Balan to remotely access and control the laptop.
Janarthanan downloaded and installed UltraViewer and shared with Hari Balan unique credentials required to initiate the remote connection.
A remote connection was thus established for about 10 minutes from 7.45pm that day, Aug 4, between Janarthanan's laptop and another device with an internet protocol address traced to India.
At the time, a total of 18,016 files belonging to the State Courts were stored on Janarthanan's laptop.
All but one of the files were classified as restricted and non-sensitive. The remaining file was classified as restricted and sensitive (high).
The files contained login credentials, secret keys and network architecture details of the State Courts' network.
The files provided details of varying degrees to systems of the State Courts, including the Integrated Case Management System used for daily criminal court work. The names of other systems were redacted from court papers.
While the remote connection was established, five executable files were transferred into Janarthanan's laptop by Hari Balan.
Two were quarantined by Windows Defender and three were successfully executed, tampering with the laptop's firewall rules and anti-virus functionality.
Janarthanan saw the files being transferred and asked Hari Balan about it, who said he was trying to bypass the laptop's security so it could pass the ISACA's security checks.
Minutes later, the SEED team was alerted to the presence of the transferred files on the laptop.
They contacted Janarthanan at about 9.30pm about the running of UltraViewer.
Janarthanan denied it and claimed that the laptop was unresponsive. He complied with instructions to disconnect the device from the internet and perform a full virus scan.
He was also told that the Government IT Security Incident Response unit would contact him to collect the laptop.
At around the same time, Hari Balan told Janarthanan that the laptop's security and network policy blocked its use for the examination.
Janarthanan then used his personal laptop to take the exam.
He deleted the majority of the files in the downloads folder in his work laptop and cleared its browsing history in order to conceal the offences.
He also deleted the UltraViewer application folder containing logs and the application file before handing the laptop over for investigations.
On Aug 14, 2025, a representative from the Corporate Services Division of the Singapore judiciary lodged a police report about the unauthorised installation of the remote desktop application.
Janarthanan was investigated by the Technology Crime Investigation Branch of the Criminal Investigation Department.
He denied knowledge of UltraViewer prior to the incident and lied that he had been experiencing connectivity issues with the laptop's virtual private network (VPN) that day.
He claimed he was re-installing the VPN application when the laptop stopped responding, and was force-rebooting it when the SEED team called him.
He confessed in a subsequent statement in September 2025.
Janarthanan admitted that his actions endangered the safety of the files, which could have been exfiltrated or stolen when the remote connection was established.
Investigations confirmed, however, that no exfiltration took place. While the files themselves did not contain any sensitive case-specific information, the files contained information that could potentially be used to gain unauthorised access to systems that had sensitive and confidential information, such as case information and judges' notes.
To mitigate Janarthanan's actions, the State Courts' Innovation, Technology and Transformation Division undertook a change of all implicated security keys and took measures such as password changes and key rotations.
The State Courts also conducted a comprehensive review of their systems and traffic logs to ensure that no anomalies, unauthorised access or data exfiltration occurred, the court heard.
They also reviewed the data handling practices for vendors to ensure best-practice compliance.
The Government IT Security Incident Response unit conducted its own investigations and the Digital Forensics Branch of the CID also performed a forensic examination of the laptop.
Deputy Public Prosecutor Matthew Choo sought seven to nine months' jail, saying Janarthanan had been entrusted with a laptop containing sensitive information.
"He ought to have known better, as a team leader of the State Courts' cloud system team, to not allow unauthorised accesses to and make unauthorised modifications to the laptop," said Mr Choo.
"Ironically, he did so to take an examination for information security."
He said the offences endangered sensitive information and could have caused significant disruption to the systems of the State Courts.
Defence lawyers S Balamurugan and A Ravidass of Regal Law sought three to four months' jail instead.
Mr Balamurugan said his client's personal laptop had battery and screen issues that day and he had no other viable option available, so he used the company-issued laptop to sit the exam.
He had installed the remote desktop application solely for the exam and not for any criminal or other improper purpose, said the lawyer.
He added that his client had an unblemished record and had built a long and stable career in the IT industry.
He has two children back in India with his wife and his family is facing financial difficulties, said Mr Balamurugan.
District Judge Lorraine Ho noted however, that the risk of harm was great as there could be a systemic attack causing possible public alarm and fear.
There was also a potential for damage to the reputation of the judiciary's case management system, as there could have been access to court case files.
Judge Ho said the offender had allowed an unknown foreign entity to have unauthorised access to data in his laptop.
For causing the unauthorised modification of computer contents, Janarthanan could have been jailed for up to three years, fined up to S$10,000, or both.
For endangering the safety of documents belonging to the State Courts via a job he had under a government contract, he could have been jailed for up to two years and fined up to S$2,000.
CNA has contacted the State Courts for more information.
Get our pick of top stories and thought-provoking articles in your inbox
Stay updated with notifications for breaking news and our best stories
Join our channel for the top reads for the day on your preferred chat app
Janarthanan Tamil Kovan 允许他的外国熟人远程访问政府管理的笔记本电脑,因为 Janarthanan 想用它参加网络安全考试。
新加坡国家法院大楼一景。(资料照片:CNA/Jeremy Long)
这段音频由人工智能工具生成。
新加坡:由于个人笔记本电脑出现故障,负责国家法院云系统团队的IT团队负责人决定使用其政府管理的设备(其中包含超过18000个受限文件)参加网络安全考试。
这样做,他允许一位熟人远程访问他的笔记本电脑,导致计算机遭到未经授权的修改,并危及受保护的文件,其中包括国家法院网络的登录凭证和密钥。
42岁的印度公民贾纳塔南·泰米尔·科万于周一(9月28日)被判处28周监禁。
他承认犯有违反《官方机密法》危害国家法院和新加坡政府文件安全的罪行,以及擅自修改笔记本电脑的罪行。
第三项指控也被纳入考虑范围。
Janarthanan 于 2017 年受聘于 Lenovo PCCW Solutions,担任服务交付经理。
2024年6月,他作为外部IT供应商被派往州法院。
他是州法院云系统团队的组长,该团队负责管理法院的各种系统和应用程序。
Janarthanan 获配一台联想 Thinkpad 笔记本电脑,这是一款政府管理的设备,受 GovTech 的合理使用政策和联想自身的政策约束。
这两项政策均禁止未经授权访问和修改笔记本电脑。
这台笔记本电脑已受到保护,并接入了 GovTech 的工程终端设备安全套件 (SEED)。SEED 是一个移动设备管理平台,可访问司法部门的“政府商业云”系统。这包括访问州法院应用程序和系统的后端基础设施。
2025 年 8 月 4 日,Janarthanan 决定使用笔记本电脑参加由专注于信息技术治理的国际专业协会 ISACA 组织的考试,以获得注册信息安全经理资格。
由于贾纳塔南的个人笔记本电脑屏幕有故障,他决定使用工作笔记本电脑。
然而,当他登录 ISACA 的系统时,他发现笔记本电脑无法通过考前安全检查,因此他无法参加考试。
贾纳塔南联系了一位名叫哈里·巴兰的人,他之前曾通过WhatsApp与哈里·巴兰讨论过IT相关的课程。法庭文件显示,哈里·巴兰的IP地址位于印度。
他把安全检查的问题告诉了哈里·巴兰,后者主动提出帮忙,并让贾纳塔南下载“UltraViewer”。这是一个远程桌面应用程序,可以让哈里·巴兰远程访问和控制笔记本电脑。
Janarthanan 下载并安装了 UltraViewer,并与 Hari Balan 分享了启动远程连接所需的唯一凭据。
因此,从 8 月 4 日晚上 7 点 45 分开始,Janarthanan 的笔记本电脑与另一台互联网协议地址可追溯到印度的设备之间建立了约 10 分钟的远程连接。
当时,Janarthanan 的笔记本电脑上共存储了 18,016 份属于国家法院的文件。
除一个文件外,其余文件均被归类为受限且非敏感文件。剩余的那个文件被归类为受限且高度敏感文件。
这些文件包含州法院网络的登录凭证、密钥和网络架构详情。
这些文件提供了州法院系统不同程度的详细信息,包括用于日常刑事法庭工作的综合案件管理系统。其他系统的名称已从法庭文件中删除。
在建立远程连接的同时,哈里·巴兰将五个可执行文件传输到了贾纳塔南的笔记本电脑上。
其中两个被 Windows Defender 隔离,三个成功执行,篡改了笔记本电脑的防火墙规则和防病毒功能。
Janarthanan 看到文件正在传输,便询问 Hari Balan,Hari Balan 说他正在尝试绕过笔记本电脑的安全措施,以便通过 ISACA 的安全检查。
几分钟后,SEED 团队发现笔记本电脑上存在已传输的文件。
晚上 9 点 30 分左右,他们联系了 Janarthanan,询问 UltraViewer 的运行情况。
贾纳塔南否认了此事,并声称笔记本电脑没有反应。他按照指示断开了设备的网络连接,并进行了全面的病毒扫描。
他还被告知,政府信息技术安全事件响应部门会联系他来取回笔记本电脑。
大约在同一时间,哈里·巴兰告诉贾纳塔南,笔记本电脑的安全和网络策略阻止了它用于考试。
随后,贾纳塔南使用自己的笔记本电脑参加了考试。
为了掩盖违法行为,他删除了工作笔记本电脑下载文件夹中的大部分文件,并清除了浏览历史记录。
在将笔记本电脑交给调查人员之前,他还删除了包含日志和应用程序文件的 UltraViewer 应用程序文件夹。
2025年8月14日,新加坡司法机构企业服务部门的一名代表就远程桌面应用程序的未经授权安装向警方报案。
Janarthanan 被刑事调查局技术犯罪调查科调查。
他否认在事件发生前知道 UltraViewer,并谎称当天他的笔记本电脑虚拟专用网络 (VPN) 出现了连接问题。
他声称,当时他正在重新安装 VPN 应用程序,笔记本电脑突然停止响应,当他正在强制重启电脑时,SEED 团队给他打了电话。
他在 2025 年 9 月的后续声明中承认了罪行。
Janarthanan 承认他的行为危及了文件的安全,这些文件可能在建立远程连接时被窃取或泄露。
调查证实,并未发生数据泄露。虽然文件本身不包含任何敏感的案件信息,但其中包含的信息可能被用于非法访问存储敏感和机密信息的系统,例如案件信息和法官笔记。
为了减轻 Janarthanan 的行为,国家法院创新、技术和转型部门对所有涉事安全密钥进行了更改,并采取了密码更改和密钥轮换等措施。
法庭获悉,州法院还对其系统和流量日志进行了全面审查,以确保没有发生异常情况、未经授权的访问或数据泄露。
他们还审查了供应商的数据处理规范,以确保符合最佳实践。
政府信息技术安全事件响应部门进行了内部调查,刑事调查局数字取证部门也对笔记本电脑进行了取证检查。
副检察官 Matthew Choo 要求判处 Janarthanan 七至九个月监禁,称 Janarthanan 受托保管一台包含敏感信息的笔记本电脑。
“作为州法院云系统团队的负责人,他应该更清楚,不应该允许未经授权的人访问笔记本电脑并对其进行未经授权的修改,”朱先生说。
“具有讽刺意味的是,他这样做是为了参加信息安全考试。”
他表示,这些违法行为危及敏感信息,并可能对州法院系统造成重大干扰。
辩护律师 S Balamurugan 和 A Ravidass(来自 Regal Law 律师事务所)请求判处三到四个月的监禁。
巴拉穆鲁根先生说,他的客户当天个人笔记本电脑的电池和屏幕都出了问题,他没有其他可行的选择,所以他使用了公司配发的笔记本电脑参加考试。
律师表示,他安装远程桌面应用程序完全是为了考试,并非出于任何犯罪或其他不正当目的。
他还补充说,他的客户没有任何不良记录,并在IT行业建立了长期稳定的职业生涯。
巴拉穆鲁根先生说,他和妻子在印度还有两个孩子,他的家庭正面临经济困难。
地方法官洛林·何指出,造成伤害的风险很大,因为可能会发生系统性攻击,从而引起公众恐慌和恐惧。
此外,由于可能有人能够访问法庭案件档案,司法部门的案件管理系统的声誉也可能受到损害。
何法官表示,该罪犯允许一个身份不明的外国实体未经授权访问其笔记本电脑中的数据。
因擅自修改计算机内容,Janarthanan 可能被判处最高三年监禁、最高 10,000 新元罚款,或两者并罚。
他因利用政府合同下的工作危害国家法院文件的安全,可能被判处最高两年监禁和最高 2000 新元罚款。
CNA已联系州法院以获取更多信息。
订阅我们的邮件,即可获取精选热点新闻和引人深思的文章。
订阅通知,第一时间获取突发新闻和精彩报道。
加入我们的频道,即可在您常用的聊天应用上获取当日热门文章。