State Courts vendor jailed after unauthorised remote access endangered 18,000 files州法院供应商因未经授权的远程访问危及18000份文件而被判入狱
A 42-year-old external IT vendor for the State Courts was jailed for 28 weeks on Monday (Sept 28) after making an unauthorised modification to a government-managed laptop that allowed a device traced to India to connect remotely, endangering more than 18,000 files.Janarthanan Tamil Kovan, an Indian national, pleaded guilty to one count each of misusing a computer system and an...

A 42-year-old external IT vendor for the State Courts was jailed for 28 weeks on Monday (Sept 28) after making an unauthorised modification to a government-managed laptop that allowed a device traced to India to connect remotely, endangering more than 18,000 files.
Janarthanan Tamil Kovan, an Indian national, pleaded guilty to one count each of misusing a computer system and an offence under the Official Secrets Act.
He had downloaded and installed unauthorised remote-access software on the laptop while trying to use it to take a Certified Information Security Manager examination after his personal laptop developed a faulty screen.
The laptop contained 18,016 State Courts files, including login credentials, secret keys and network architecture details relating to the courts' systems, and was protected by GovTech's Security Suite for Engineering Endpoint Devices (SEED).
When the laptop failed the examination's security checks on Aug 4, 2025, Janarthanan sought help from a man identified as "Hari Balan", who instructed him to download UltraViewer, a remote desktop application that would enable another user to remotely access and control the device.
A connection was established with another device whose IP address was traced to India, during which several files were transferred onto the laptop.
Deputy Public Prosecutor Matthew Choo said the files did not contain sensitive case-specific information but could potentially be used to gain unauthorised access to systems containing confidential information, including case information and judges' notes.
Investigations later found that no data had been exfiltrated during the remote connection.
After GovTech's SEED team detected the files, Janarthanan falsely denied running UltraViewer. He later deleted files from the laptop, cleared its browsing history and removed the UltraViewer application folder before handing the device over to the Government IT Security Incident Response team.
He was arrested in June 2026.
Following the incident, the State Courts' Innovation, Technology and Transformation Division changed all implicated security keys, implemented password changes and key rotations, and reviewed system and traffic logs for anomalies, unauthorised access or data exfiltration.
The Singapore Courts said it took immediate steps to secure its systems and worked with the relevant authorities.
It added that no court documents were lost and no unauthorised access to its documents or systems was detected.
helmy.saat@asiaone.com
一名 42 岁的州法院外部 IT 供应商周一(9 月 28 日)被判入狱 28 周,原因是其未经授权修改了政府管理的笔记本电脑,导致一台可追溯到印度的设备远程连接,危及超过 18,000 个文件。
印度公民 Janarthanan Tamil Kovan 对一项滥用计算机系统罪和一项违反《官方保密法》的罪行供认不讳。
他的个人笔记本电脑屏幕出现故障后,他试图用这台笔记本电脑参加注册信息安全经理考试,结果在笔记本电脑上下载并安装了未经授权的远程访问软件。
该笔记本电脑包含 18,016 个州法院文件,包括登录凭证、密钥和与法院系统相关的网络架构详细信息,并受到 GovTech 的工程终端设备安全套件 (SEED) 的保护。
2025 年 8 月 4 日,当这台笔记本电脑未能通过安全检查时,Janarthanan 向一位自称“Hari Balan”的男子寻求帮助,该男子指示他下载 UltraViewer,这是一款远程桌面应用程序,可以让其他用户远程访问和控制该设备。
通过与另一台设备建立连接,该设备的 IP 地址可追溯到印度,在此过程中,多个文件被传输到笔记本电脑上。
副检察官Matthew Choo表示,这些文件不包含敏感的案件具体信息,但有可能被用来未经授权访问包含机密信息的系统,包括案件信息和法官笔记。
事后调查发现,远程连接期间没有数据被窃取。
在政府科技局的SEED团队检测到这些文件后,贾纳塔南谎称没有运行UltraViewer。之后,他删除了笔记本电脑上的文件,清除了浏览历史记录,并删除了UltraViewer应用程序文件夹,然后将设备交给政府IT安全事件响应小组。
他于2026年6月被捕。
事件发生后,州法院创新、技术和转型部门更换了所有涉事安全密钥,实施了密码更改和密钥轮换,并审查了系统和流量日志,以查找异常情况、未经授权的访问或数据泄露。
新加坡法院表示,已立即采取措施保护其系统安全,并与相关部门合作。
声明还补充说,没有法院文件丢失,也没有发现对其文件或系统的未经授权的访问。
helmy.saat@asiaone.com