StarHub
Incident posture
Timeline
Summary
A China-nexus cyber espionage group known as UNC3886 targeted Singapore's four major telecommunications companies, including StarHub, in a deliberate, well-planned campaign. The attackers used a zero-day exploit to bypass perimeter firewalls and deployed advanced tools such as rootkits to maintain persistent access while evading detection. Although they penetrated parts of the telecom systems, they were unable to disrupt services or access personal customer data. A small amount of technical, network-related data was exfiltrated to support the threat actors' operational objectives. Singapore's Operation Cyber Guardian, a multi-agency effort led by 100 cyber defenders, coordinated the response, blocked the attackers' access points, and implemented remediation measures including joint threat hunting and penetration testing.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In mid-2025, Singapore's Coordinating Minister for National Security, K. Shanmugam, identified UNC3886 as a "highly sophisticated threat actor" that was attacking the country's critical infrastructure, though specific details of the campaign were not publicly disclosed at that time because revealing them would not have been in Singapore's security interests. Singapore's Cyber Security Agency (CSA) had earlier indicated in July 2025 that the government was responding to cyberattacks from this group targeting high-value strategic assets. Months later, on February 9, 2026, Singapore's government revealed that the infrastructure targeted in that operation was the country's telecommunications sector. Four of Singapore's major telecom companies—Singtel, StarHub, M1, and Simba Telecom—were confirmed as targets of UNC3886 in attacks that had taken place during 2025. The disclosure was made by Minister for Digital Development and Information Josephine Teo at the Operation Cyber Guardian engagement event and was also communicated through official statements by the CSA and the Infocomm Media Development Authority (IMDA).
UNC3886, described by Google-owned cybersecurity firm Mandiant as a "China-nexus espionage group," has a documented history of targeting defence, technology, and telecommunications organizations in the United States and Asia. According to the CSA, the hackers successfully penetrated and gained access to some parts of the telecom systems of the four affected carriers. Despite this foothold, they were unable to disrupt services and there was no indication that they accessed personal customer data. The attackers did, however, exfiltrate a small volume of technical data, which officials characterised as primarily network-related information intended to advance the threat actors' operational objectives. The IMDA provided further technical detail, noting that UNC3886 deployed advanced tools to achieve and sustain their access. Among the techniques reported, the group used a zero-day exploit to bypass the perimeter firewall of the telcos and gain entry to their networks, and they also used rootkits and other advanced tools to maintain persistent access, cover their tracks, and evade detection. Minister Teo characterised the stolen technical data as information that would help the attackers understand the terrain they were working with.
The consequences had the attack progressed further were potentially significant. Teo stated that the attacks were a "deliberate, targeted, and well-planned campaign" against Singapore's telecommunications sector, and warned that if the operation had advanced far enough, it could have eventually allowed the attackers to cut off telecoms or internet services. This potential impact distinguished UNC3886's campaign from earlier cyber incidents Singapore had faced, such as the 2014 infiltration of the Ministry of Foreign Affairs' IT system and the 2018 SingHealth breach in which more than 1.5 million records, including those of former Prime Minister Lee Hsien Loong, were stolen. According to Teo, the UNC3886 operation represented a more serious threat because it targeted critical systems that provide essential services to the public, with implications for both national security and the broader economy.
The response to the campaign was coordinated under Operation Cyber Guardian, described as the largest coordinated cyber response Singapore had undertaken to date. The operation was led by a group of 100 cyber defenders and involved six government agencies: the Cyber Security Agency of Singapore (CSA), the Infocomm Media Development Authority (IMDA), the Centre for Strategic Infocomm Technologies (CSIT), the Digital and Intelligence Service of the Singapore Armed Forces, the Internal Security Department, and GovTech. Through Operation Cyber Guardian, cyber defenders implemented remediation measures, blocked UNC3886's access points, and increased monitoring capabilities for the targeted telecommunications companies. The IMDA, working alongside the CSA, collaborated directly with the telecom operators to strengthen cybersecurity defences, improve detection capabilities, and deploy active monitoring systems. The affected telcos themselves carried out additional interventions, including joint threat hunting, penetration testing, and other capability enhancements. In a joint statement, the four companies confirmed that all telcos face a range of cyber threats, including Distributed Denial-of-Service attacks, malware, phishing, and more sophisticated advanced persistent threats, and noted that they adopt defence-in-depth mechanisms to protect their networks and conduct prompt remediation when issues are detected. They added that they work with government agencies and industry experts to improve security and resilience.
Although the immediate campaign was contained, Singapore's authorities cautioned that further attempts to access the country's telco infrastructure could occur. The CSA announced it would introduce initiatives aimed at gradually improving capabilities across Singapore's wider cyber ecosystem to support more effective and timely responses to future threats. Beijing has routinely denied allegations of cyber espionage, stating that it opposes all forms of cyberattacks and positions itself as a victim of such threats, and the Chinese Embassy in Singapore did not respond to a request for comment at the time of the February 2026 disclosures.
Sources
Sources available to members: 3 sources.