CSIDB logo
Incident

StarHub

Incident posture

Attack window
Feb 2026
Location
Singapore
Status
Unknown
CIA posture
Available to members
Updated
2026-08-17 09:16

Linked entities

Victim
StarHub
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Undetermined
Disclosed
Feb 2026
Resolved
Pending

Summary

Singapore disclosed that the cyber‑espionage group UNC3886 had infiltrated the networks of the country’s four major telecommunications providers, including StarHub, using zero‑day exploits, rootkits, and advanced persistence mechanisms to achieve long‑term access to backbone infrastructure and technical network data. The compromise gave the attackers upstream visibility into the services relied upon by enterprises and individuals, enabling potential surveillance and data collection without direct intrusion into customer environments.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In February 2026, Singapore authorities disclosed that the cyber‑espionage group UNC3886 had compromised the networks of the four major telecommunications operators serving the country: Singtel, StarHub, M1, and Simba. The disclosure was issued as a public announcement by Singaporean authorities. The intrusion relied on zero‑day exploits, custom rootkits, and advanced persistence mechanisms to establish long‑term presence within the telcos’ backbone infrastructure. The attackers were able to exfiltrate technical and network data from the compromised systems.

The affected telcos constitute a core component of Singapore’s national communications infrastructure, providing connectivity for government agencies, enterprises, and individual users. Because the breach occurred at the level of the telecommunications backbone, the threat actors gained a position upstream of customer environments, enabling them to monitor and collect traffic that traverses the telco networks without needing to penetrate each downstream organization directly. The access was characterized as persistent and structurally embedded within the shared infrastructure that underpins multiple services.

The compromise has been described as creating a permanent collection capability, with the data‑protection implications now rooted in the architecture of the shared dependencies rather than isolated endpoint breaches. Following the disclosure, cyber insurers have begun to explicitly incorporate the risk of enduring advanced persistent threat residency in telecommunications backbone infrastructure into their underwriting assessments. The incident has prompted a broader reassessment of trust in upstream service providers across the sector.

Sources

Sources available to members: 1 source.

CSIDB