CSIDB logo
Incident

Simba Telecom

Incident posture

Attack window
2025
Location
Singapore
Status
Unknown
CIA posture
Available to members
Updated
2026-09-01 11:32

Linked entities

Victim
Simba Telecom
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A China-nexus cyber espionage group known as UNC3886 targeted Singapore's four major telecom companies, including Simba Telecom, along with Singtel, StarHub, and M1, in attacks the prior year. Singapore's Cyber Security Agency confirmed the threat actors penetrated portions of the telecom systems but were unable to disrupt services or access personal data. A small amount of technical information, believed to be primarily network-related data supporting the group's operational objectives, was exfiltrated during the intrusions. The four affected telcos issued a joint statement acknowledging the broader threat landscape, including Distributed Denial-of-Service attacks, malware, phishing, and advanced persistent threats, and emphasized their use of defense-in-depth security measures and collaboration with government agencies and industry experts to enhance resilience.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

In a cyber espionage campaign disclosed in February 2026, Singapore's Cyber Security Agency (CSA) confirmed that all four of the country's major telecommunications companies — Singtel, StarHub, M1, and Simba Telecom — were targeted by the threat actor tracked as UNC3886 in attacks that took place the previous year. According to the agency, the hackers were able to penetrate and gain access to some parts of the telecom systems, but were not able to disrupt services and did not access personal data belonging to customers. The disclosure, issued on Monday, February 9, 2026, marked the first time the Singaporean government publicly identified the type of infrastructure that UNC3886 had been observed to target.

The intrusion resulted in the exfiltration of a limited amount of technical information from the affected operators. CSA stated that the stolen material was "primarily network-related data" intended to advance the threat actors' operational objectives, rather than customer or personal information. Despite the unauthorized access, the agency confirmed that no service outages or customer-impacting disruptions were caused by the campaign. Google-owned cybersecurity firm Mandiant, which has tracked UNC3886 extensively, has described the group as a "China-nexus espionage group" that has previously targeted defence, technology, and telecommunications organizations in the United States and across Asia.

The cyber espionage activity targeting Singapore's telecommunications sector was first acknowledged by the government in July 2025, when authorities stated they were responding to cyberattacks from UNC3886 that were aimed at high-value strategic assets, without initially specifying the industry or entities affected. The February 2026 statement therefore represented a more detailed attribution, narrowing the target scope to the country's four telco operators and confirming the nature of the compromise. This public disclosure came approximately six to seven months after the underlying intrusions had taken place, based on the government's characterization of the attacks as having occurred "last year."

In a joint response issued after the government's announcement, Singtel, StarHub, M1, and Simba Telecom acknowledged the persistent nature of cyber threats facing the telecommunications industry. The companies collectively described the range of threats they face, including Distributed Denial-of-Service (DDoS) attacks, malware campaigns, phishing attempts, and more sophisticated advanced persistent threats. They stated that they adopt defense-in-depth mechanisms to protect their networks and conduct prompt remediation when any issues are detected, and emphasized that they work closely with government agencies and industry experts to improve security and resilience across the sector.

The Chinese Embassy in Singapore did not respond to a request for comment at the time of the disclosure. Beijing has routinely denied allegations of cyber espionage, maintaining its opposition to all forms of cyberattacks and asserting that China is itself a victim of such threats. The attribution of UNC3886 as a China-nexus group was drawn from Mandiant's independent research and was referenced in the Singaporean government's communication, but the embassy offered no immediate acknowledgment or rebuttal. The reporting on the incident was carried by Reuters and syndicated to other outlets, with bylines attributed to Jun Yuan Yong and editing by John Mair.

The specific technical methods used by UNC3886 to gain access to the four telcos were not detailed in the public statement, and the timeline of individual intrusions — including initial access, dwell time, and detection — was not disclosed by CSA or by the affected companies. It also remains unclear from the available reporting whether the four operators were compromised simultaneously, through a shared supply chain vector, or via independent intrusion paths. The government's communication focused instead on confirming the successful penetration, the limited nature of the data exfiltrated, and the absence of service disruption or personal data exposure. Simba Telecom, alongside its three larger peers, was named as one of the targeted operators in both the government disclosure and the joint industry response, indicating that the threat actor's activity extended across the full breadth of Singapore's telecommunications market.

Sources

Sources available to members: 2 sources.

CSIDB