Cyber Incident Victim: Simba Telecom
Date:
Feb 2026
Location:
Singapore
Summary
UNC3886, a sophisticated cyber‑espionage group, compromised the networks of Simba Telecom and three other major Singaporean telcos, gaining long‑term access to backbone infrastructure and technical data through zero‑day exploits, rootkits, and advanced persistence techniques. The intrusion gave the attackers upstream visibility into authentication flows, service‑provider networks, and data traversing the telco’s systems, effectively turning the telco into a collection point for intelligence gathering.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
In February 2026 Singapore disclosed that the cyber‑espionage group UNC3886 had penetrated the networks of the four major telcos serving the country: Singtel, StarHub, M1, and Simba Telecom. The attackers employed zero‑day exploits, rootkits, and advanced persistence techniques to gain long‑term access to the telcos’ backbone infrastructure and technical/network data. This access was described as upstream, persistent, and structurally embedded within the shared dependencies that enterprises rely on for connectivity. By compromising the telcos, the threat actors positioned themselves at a point where they could observe and influence traffic without needing to breach downstream enterprise environments directly. The intrusion gave the adversary the capability to monitor authentication flows, siphon data traversing the network, and maintain presence over extended periods.

Simba Telecom, as part of Singapore’s national telecommunications infrastructure, supports government, enterprise, and individual users, making its compromise a significant collection point for the adversary. The breach meant that any organization relying on Simba’s services for voice, data, or connectivity could have its communications exposed through the upstream telco layer. The disclosure by Singaporean authorities marked the official acknowledgment of the incident and highlighted the permanence of the access gained by UNC3886. The article notes that the access was characterized as permanent and embedded, indicating that the intrusion persisted despite detection efforts. Consequently, organizations that depend on Simba Telecom and the other affected telcos faced an upstream risk that could not be mitigated by internal defenses alone.
