fbpx

We Were Hit by a Ransomware Attack on National Day. Here Is What Happened. (Part 1)

Yesterday was National Day. For most Singaporeans, it means fireworks, red and white, and a rare public holiday. For me, it marks something else: exactly one year since the worst day in Aptsys’s history.

On 9 August 2025, while the rest of Singapore was celebrating, we were hit by a ransomware attack.

I am writing this for three reasons. To thank my team, who carried us through it. To thank the customers who stayed with us, understood, and encouraged us when they had every right to be angry. And to write it down — because some things deserve to be remembered, not buried.


What Happened on That Day

It was a Saturday morning. National Day. I had just finished breakfast when the call came in from support — the system was down.

This kind of call happens occasionally. Systems have hiccups. My first thought was that we would have it sorted in fifteen minutes. I alerted our backend programmer, apologised for the interruption to his holiday, and waited for the update that everything was back to normal.

The update did not come. Instead, he found the ransom note.

The hacker was still in the middle of it. Tables were being deleted one by one. Most were gone, but not all — and sitting among the wreckage was a single new table we had never created. Inside it: a ransom note.

The moment we understood what was happening, we shut down the database server. That stopped the deletion. It also meant that whatever tables were still intact when we pulled the plug had a chance of being recovered.

That is how you find out. Not an alarm. Not a dramatic system shutdown. A ransom note in a database being destroyed in real time, on a Saturday public holiday, while the rest of the country is celebrating.

The team cancelled whatever they had planned for the day and came back to the office. No one was asked. No one hesitated. On National Day, while Singapore celebrated, we were back at our desks trying to understand what had just happened to us.

The first feeling is not anger. It is disbelief. You keep thinking there must be a mistake — a glitch, something fixable, something that will make sense in a few minutes. Then the realisation settles in: you have been targeted. Someone deliberately did this to you.


It Was Not Just Us

As the day went on, we started hearing from the police, from customers, from the news: we were not the only ones. Other businesses had been hit. Public services too. Multiple organisations, all on the same day, all while Singapore was in the middle of its National Day celebrations.

This was not a random opportunistic attack. It was coordinated. Timed. Someone — or some group — had chosen our National Day deliberately, knowing that it was a public holiday, that teams would be off, that response would be slower, that the irony of attacking a country on the day it celebrates itself would not be lost.

That realisation made it feel different. It was not just an attack on Aptsys. It was an attack on us as a nation, on the day we were proudest to be one.

The POS system held up in one important way: because it runs offline, merchants could still process orders and serve their customers at the counter. But anything that required a connection to our servers — updating the menu, pulling reports, syncing data — was gone. Three days of that.

The harder impact was on our kiosk and QR ordering customers. Those systems depend on the backend being live. The moment it went down, their self-ordering stopped working entirely.

Which meant they had to take orders manually.

These were restaurants that had built their operations around not needing to do that. No pen and paper process. Not enough floor staff. Some of them had reduced headcount precisely because the kiosk or QR ordering was handling that load. And now, with no warning on a public holiday, they were suddenly trying to run a lunch service the old way — and they were not equipped for it.

The hotline was ringing constantly. Customers calling in, asking when it would be back, telling us they were struggling, telling us they needed it now. And we could not give them a time. We could not fix it fast enough.

We failed them in those hours. I know that. The system we had promised would be there for them was not. That sits with me more than anything else from that day — not the technical failure, but the people on the other end of the phone who were counting on us.


I Did Not Have Answers

On that first day, my staff came to me with questions. My customers came to me with questions. What happened? How bad is it? When will it be back? What do we do?

I did not have answers. Not a single one I could say with confidence.

That is one of the hardest things I have ever had to sit with — being the person people are looking to, and having nothing to give them. As a founder, as a leader, you carry the expectation that you will know what to do. You are supposed to have a plan. And I was standing there, staring at the ransom note, feeling completely defeated.

That night I could not sleep. Not from stress or busyness, but from fear. A specific kind of fear — the fear of not being in control. The fear of not knowing what was coming next. Someone had reached into everything we had built and deleted it, and I did not know who they were, where they were, or what else they were capable of. That feeling does not switch off when you close your laptop.

I lay awake thinking about my team. About our customers. About how I had no timeline to give anyone, no promise I could make, no way to undo what had been done.


What We Did Next

We reported it to the police immediately. We brought in cybersecurity experts to trace what had happened and contain the damage.

Then came the question I had been dreading: do we pay?

The government’s advice was clear — do not pay. Paying funds criminal networks. It does not guarantee your data is returned. And it marks you as a target who will pay again. We followed that advice. We did not pay.

I will not pretend that decision was easy in the moment. When you are staring at encrypted servers and a team of people depending on you, every hour the systems are down feels like a week.


I Prayed for a Miracle

In those first hours, I prayed. I prayed that my backend programmer would call me back and say it was fixed. That somehow, some way, the data would be there, the systems would come back, and this would turn out to be something we could undo in an afternoon.

God did not send the miracle I asked for.

In the days that followed, He felt silent. I was waiting for a sign, a breakthrough, something to tell me it was going to be all right. Nothing came — or so I thought.

In the middle of that chaos, a question formed in my mind: What does it mean to truly trust God when everything you depend on collapses?

During those weeks, the story of King Jehoshaphat in 2 Chronicles 20 came up in Sunday service. It spoke directly to me.

Judah faced an approaching army — vast, threatening, seemingly unstoppable. Jehoshaphat did not rush to fight. He did not pretend to have a strategy. He acknowledged he was helpless, sought God, and kept his eyes on Him. And when Judah eventually went out to face the enemy, they did not march out with swords drawn. They went out singing praises to God. Before the battle was won. Before they could see how it would end.

God acted on their behalf. The enemy was defeated without a single battle fought.

That Sunday, God used that passage to remind me: praise Him. Look up to Him. Not after the problem is resolved — before. Not when you can see the way forward — when you cannot. I had to turn away from the problem and look upward, even when it was extremely difficult to do so.

What I could not see in those first weeks was that God was not silent. He was working. He was with me through every sleepless night, every unanswered question, every moment I had nothing left to give. And He was using the people around me — my staff — according to His will, not mine. As I was falling apart, they were moving. Quietly. Methodically. Without waiting for me to tell them what to do.

That was the miracle. Not data appearing out of nowhere. Not a sudden fix. The miracle was that He was present the whole time, carrying what I could not carry, working through the people He had placed around me — one problem at a time, one step at a time.

And He humbled me. That is the part I did not expect and could not have asked for. The identity I had built as a founder — someone who leads by knowing what to do, by having the answers, by being the one people can rely on — He quietly dismantled it in those weeks. I do not need to have all the answers. I cannot lead by telling everyone what to do. Trusting God is not a one-time decision in a crisis. It is a posture — a way of living that acknowledges your limits and His sovereignty.

He was in control. He delivered — just not the way I expected.


To My Team

What I am most proud of — and what I most want to say — is this: I could not have got through this without the people around me.

While I was in crisis mode, barely sleeping, running on fear and adrenaline, the team was doing the actual work. New servers were set up. Data was recovered piece by piece. Systems were rebuilt from the ground up. By the time full operations were restored, it had taken three days for the POS and two days for the kiosk and QR ordering systems. Three days is still too long. But without them it would have been far worse — or we might not have recovered at all.

I have said this to them privately. I want to say it here, on record: thank you. The way you handled this, under that kind of pressure, on that timeline, is something I will not forget.


To Our Customers

When our systems went down, our merchants could not update their inventory, could not pull reports, could not run their operations normally. They had every reason to be frustrated. Some of them were.

But a number of them reached out to say they understood. That they were rooting for us. That they knew we were doing everything we could. Those messages mattered more than I can explain. When you are in the middle of something like this — feeling helpless, feeling responsible, feeling the weight of every person whose business depends on your platform — a message of encouragement from a customer does something that no technical fix can.

If you were one of those people: thank you. Genuinely.


What I Could Not Shake

Even after the systems came back online, I could not sleep.

Not because I was still in crisis mode. Because I kept thinking: what if it happens again? We had security measures. We thought we were reasonably protected. And it still happened.

That fear — of being hit again, of being helpless against something you cannot see coming, of facing that empty database with that ransom note again — does not go away quickly. Some nights it still does not.

But fear without action is just suffering. And somewhere in those sleepless nights, that fear turned into something else: a resolve to make sure that if they ever came back, we would not be the same target they found the first time.


What Comes Next

This is Part 1 — the story of what happened, how it felt, and the people who carried us through it.

In Part 2, I share exactly what we did after the dust settled: the infrastructure changes, the new protocols, and the shift in thinking that changed how Aptsys is built. Not as a how-to guide, but as an honest account of what one attack forced us to rethink from the ground up.

Read Part 2 here