A 42-year-old IT vendor attached to Singapore’s State Courts has been sentenced to 28 weeks in jail after allowing an acquaintance to remotely access his government-managed laptop, putting more than 18,000 court-related files at risk.
Janarthanan Tamil Kovan, who led the State Courts’ cloud systems team, pleaded guilty to charges involving the endangerment of government documents under the Official Secrets Act and unauthorised modification of a computer. A third charge was taken into consideration for sentencing.
The incident happened on Aug. 4, 2025, when Janarthanan used his work laptop to take a cybersecurity certification examination because his personal laptop had developed a fault. When the government-managed device failed the examination platform’s security checks, he contacted an acquaintance in India for assistance.
The acquaintance instructed him to install UltraViewer, a remote-desktop application, and Janarthanan provided the credentials needed to establish a remote connection. The connection lasted about 10 minutes.
At the time, the laptop contained 18,016 files belonging to the State Courts. All but one were classified as restricted and non-sensitive, while one was classified as restricted and highly sensitive. The files included login credentials, secret keys and network architecture information that could potentially provide access to systems containing confidential court information.
During the remote session, five executable files were transferred to the laptop. Two were quarantined by Windows Defender, while three were executed and altered the device’s firewall and antivirus settings. Security personnel subsequently detected the activity and instructed Janarthanan to disconnect the laptop from the internet and submit it for investigation.
Investigators found no evidence that State Courts files were exfiltrated or stolen. However, authorities said the unauthorised connection created a risk that protected information could have been accessed and potentially used to compromise court systems. The State Courts subsequently changed affected security keys, rotated passwords and conducted reviews of system logs and vendor data-handling practices.
Janarthanan initially denied knowing about the remote-access software and gave investigators an alternative explanation for the laptop activity. He later admitted what had happened in a statement in September 2025.
The prosecution had sought seven to nine months’ imprisonment, arguing that Janarthanan had been entrusted with a device containing sensitive information and was responsible for a cloud systems team. His lawyers sought three to four months, citing his lack of previous convictions and personal circumstances.
District Judge Lorraine Ho said the potential consequences were serious because the incident could have enabled a broader attack and affected confidence in the judiciary’s systems. Janarthanan was ultimately sentenced to 28 weeks’ imprisonment.