
Janarthanan Tamil Kovan, a 42‑year‑old Indian national employed by Lenovo PCCW Solutions, had been assigned to the State Courts as an external IT vendor in June 2024. As team leader of the courts’ cloud‑system team, he oversaw the maintenance of critical court applications.
On 4 August 2025 the vendor was issued a Lenovo ThinkPad, a device governed by GovTech’s acceptable‑use policy and Lenovo’s own rules that forbid unauthorised access or modification. Kovan used the laptop to prepare for an international information‑security exam after his personal device failed, and he granted remote access to a contact named Hari Balan, whose IP lay in India.
The remote session exposed 18,016 court files, 18,015 of which were restricted and non‑sensitive, while the last file was classified as restricted and sensitive (high). The files contained login credentials, secret keys and network architecture that could have enabled a systemic breach of court data, according to the Technology Crime Investigation Branch.
Kovan pleaded guilty on 10 September 2025, admitting that his actions endangered the safety of the files. Deputy Public Prosecutor Matthew Choo requested a sentence of seven to nine months, citing the seriousness of allowing a foreign entity to access government data; District Judge Lorraine Ho instead imposed a 28‑week term, stressing the potential for a large‑scale attack.
The case underscores Singapore’s zero‑tolerance stance on cyber‑security violations, with authorities warning that any breach could spark public alarm and undermine judicial confidence. Officials say the ruling will deter other contractors from compromising state‑sensitive data.