CSIDB logo
Incident

Singtel

Incident posture

Attack window
Jul 2025
Location
Singapore
Status
Unknown
CIA posture
Available to members
Updated
2026-09-01 11:25

Linked entities

Victim
Singtel
Threat actors
1 actor
Sources
3 sources

Timeline

Occurred
Jul 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A China-nexus cyber espionage group known as UNC3886 targeted four major Singapore telecommunications companies, including Singtel, in a deliberate and well-planned campaign. The attackers used advanced tools, including a zero-day exploit to bypass perimeter firewalls, along with rootkits to maintain persistent access and evade detection. While they managed to penetrate some critical systems and exfiltrate a small amount of network-related technical data, they did not disrupt telecom services or access personal customer information. Singapore's Cyber Security Agency, alongside five other government agencies under Operation Cyber Guardian, led the largest coordinated cyber response in the country to contain the threat, remediate affected systems, and block the group's access points.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

0 techniques

Description

In mid-2025, Singapore's Cyber Security Agency (CSA) confirmed it was responding to cyberattacks attributed to a highly sophisticated threat actor targeting high-value strategic assets, though officials declined at the time to disclose which specific sectors or infrastructure were affected. The Coordinating Minister for National Security, K. Shanmugam, identified the group as UNC3886, a "highly sophisticated threat actor," stating that revealing further details would not be in Singapore's security interests. This initial public acknowledgment marked the beginning of what would become Singapore's largest coordinated cyber response to date, eventually formalized under the name Operation Cyber Guardian. The operation brought together approximately 100 cyber defenders from six government agencies, including the Cyber Security Agency of Singapore, the Infocomm Media Development Authority (IMDA), the Centre for Strategic Infocomm Technologies (CSIT), the Digital and Intelligence Service of the Singapore Armed Forces, the Internal Security Department, and GovTech. Their investigation would later reveal the full scope of the campaign as a deliberate, targeted, and well-planned operation against Singapore's telecommunications sector, primarily seeking persistent access to critical systems that provide essential services to the public.

On February 9, 2026, Singapore's government publicly revealed that UNC3886 had targeted the country's four major telecom companies, namely Singtel, StarHub, M1, and Simba Telecom, in attacks that occurred the previous year. The disclosure was made by Minister for Digital Development and Information Josephine Teo at the Operation Cyber Guardian engagement event and through a parallel CSA statement. According to these official accounts, the hackers were able to penetrate and gain access to certain parts of the telecom systems, including, in one instance, a few critical systems. However, the attackers were halted before they could disrupt services, and there was no evidence to suggest they accessed or stole sensitive customer data. The CSA stated that the threat actors exfiltrated a small amount of technical data, believed to be primarily network-related information gathered to advance their operational objectives. Minister Teo noted that if the attack had progressed further, it could have eventually allowed the attackers to cut off telecoms or internet services, underscoring the strategic significance of the telecommunications sector as a target for state-sponsored actors.

The nature of the campaign demonstrated significant technical sophistication. According to the IMDA, UNC3886 deployed advanced tools and techniques to gain access to the telco systems. The group used a zero-day exploit to bypass the perimeter firewall of the targeted telecommunications companies, providing an initial foothold into their networks. Once inside, the attackers used rootkits and other advanced tools to maintain persistent access, cover their tracks, and evade detection. This level of tradecraft is consistent with Mandiant's characterization of UNC3886 as a "China-nexus espionage group" that has primarily targeted defense, technology, and telecommunications organizations in the United States and Asia. The People's Republic of China has routinely denied allegations of cyber espionage, asserting that it opposes all forms of cyberattacks and is itself a victim of such threats; the Chinese Embassy in Singapore did not respond to a request for comment regarding the February 2026 disclosures.

The response to the incident was extensive and multi-layered. Following the detection of the intrusion, the six government agencies under Operation Cyber Guardian worked closely with the affected telecom companies to implement remediation measures, block the access points used by UNC3886, and increase monitoring capabilities across the targeted infrastructure. The IMDA and CSA coordinated with the telcos to strengthen cybersecurity defenses, improve detection capabilities, and deploy active monitoring systems designed to guard against new attempts by UNC3886 to access their networks. The telecom companies themselves carried out additional interventions, including joint threat hunting, penetration testing, and the enhancement of internal security capabilities. The four affected telcos, Singtel, StarHub, M1, and Simba Telecom, also issued a joint statement noting that all telecommunications companies face a range of cyber threats, from Distributed Denial-of-Service attacks and malware to phishing campaigns and more sophisticated advanced persistent threats. They stated that they employ defense-in-depth mechanisms to protect their networks, conduct prompt remediation when issues are detected, and work closely with government agencies and industry experts to improve security and resilience.

The incident carries historical context within Singapore's broader experience with state-sponsored cyberattacks. In 2014, an attacker infiltrated the Ministry of Foreign Affairs' IT system and attempted to steal sensitive information. Four years later, a separate group hacked SingHealth's systems and stole more than 1.5 million records, including those of former Prime Minister Lee Hsien Loong. Minister Teo noted at the engagement event that UNC3886 poses a more serious threat than these previous attacks because it targets critical systems that provide essential services to the public rather than focusing primarily on data theft. The telecommunications sector was identified as a strategic target because it plays a foundational role in powering the digital economy and transmitting vast amounts of information, including sensitive data. Looking forward, the CSA announced it would introduce initiatives to gradually improve capabilities across Singapore's cyber ecosystem, enabling more effective and timely responses to cyber threats and strengthening national cyber defenses. While the collective efforts of Operation Cyber Guardian contributed to containing the attacks, the government acknowledged that further attempts to access Singapore's telco infrastructure may occur in the future.

Sources

Sources available to members: 3 sources.

CSIDB