CSIDB logo
Incident

M1

Incident posture

Attack window
Jul 2025
Location
Singapore
Status
Unknown
CIA posture
Available to members
Updated
2026-09-01 11:29

Linked entities

Victim
M1
Threat actors
1 actor
Sources
3 sources

Timeline

Occurred
Jul 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Singapore Cyber Security Agency disclosed that a China-linked cyber espionage group, UNC3886, targeted four of the country's major telecom companies, including M1, Singtel, StarHub, and Simba Telecom, in a deliberate and well-planned campaign against the telecommunications sector. The attackers penetrated parts of the telecom systems using advanced tools such as zero-day exploits to bypass perimeter firewalls and deployed rootkits to maintain persistent access and evade detection. While they were unable to disrupt services or access personal customer data, they exfiltrated a small amount of network-related technical data believed to support their operational objectives. Singapore's coordinated response, known as Operation Cyber Guardian, involved six government agencies working with the affected telcos to block the group's access points, implement remediation measures, and strengthen monitoring. Authorities warned that future intrusion attempts remain possible given the strategic importance of telecom infrastructure.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

In 2025, Singapore's four major telecommunications companies—Singtel, StarHub, M1, and Simba Telecom—were targeted by the cyber espionage group UNC3886 in a deliberate and well-planned campaign against the country's telecommunications sector. The Cyber Security Agency of Singapore disclosed the incident publicly on February 9, 2026, marking the first time the government had identified the specific type of critical infrastructure that the group had attacked. Prior to this disclosure, in July 2025, Coordinating Minister for National Security K. Shanmugam had acknowledged that UNC3886 was a highly sophisticated threat actor targeting Singapore's critical infrastructure, though he did not provide details of the attacks at that time, citing national security concerns. Mandiant, a Google-owned cybersecurity firm, has described UNC3886 as a "China-nexus espionage group" that has primarily targeted defense, technology, and telecommunications organizations in the United States and Asia.

UNC3886 employed advanced tools and techniques to penetrate the telecommunications networks. According to the Infocomm Media Development Authority, the group used a zero-day exploit to bypass the perimeter firewalls of the telcos, granting them initial access to the networks. Once inside, the attackers deployed rootkits and other sophisticated tools to maintain persistent access, cover their tracks, and evade detection. The hackers were able to penetrate and gain access to some parts of the telecom systems. Singapore's Minister for Digital Development and Information, Josephine Teo, stated at the Operation Cyber Guardian engagement event that in one instance the attackers gained access to a few critical systems but did not get far enough to disrupt services. There was also no evidence to suggest that the attackers accessed or stole sensitive customer data. However, UNC3886 did manage to exfiltrate a small amount of technical data, which is believed to be primarily network-related information intended to advance the threat actors' operational objectives. Minister Teo noted that this stolen data likely helped the attackers understand the terrain and what they were dealing with, and warned that if the attack had gone far enough, it could have eventually allowed the attackers to cut off telecommunications or internet services.

The Singapore government mounted its largest coordinated cyber response to date under Operation Cyber Guardian, a multi-agency effort comprising 100 cyber defenders drawn from six government bodies: the Cyber Security Agency of Singapore, the Infocomm Media Development Authority, the Centre for Strategic Infocomm Technologies, the Digital and Intelligence Service of the Singapore Armed Forces, the Internal Security Department, and GovTech. Cyber defenders implemented remediation measures, blocked UNC3886's access points, and increased monitoring capabilities for the targeted telecommunications companies. The IMDA worked closely with the CSA and the telecom companies to strengthen cybersecurity defenses, improve detection capabilities, and deploy active monitoring systems to guard against new attempts by UNC3886 to access their networks. The telecom companies themselves carried out additional interventions, including joint threat hunting, penetration testing, and the enhancement of their security capabilities.

In a joint statement, the four affected telecom companies confirmed that all telecommunications providers face a wide range of cyber threats, including Distributed Denial-of-Service attacks, malware, phishing, and more sophisticated advanced persistent threats. The companies stated that they adopt defense-in-depth mechanisms to protect their networks and conduct prompt remediation when any issues are detected, while also working with government agencies and industry experts to improve security and resilience. The CSA has announced initiatives to gradually improve capabilities across Singapore's cyber ecosystem, enabling more effective and timely responses to cyber threats. Minister Teo cautioned that while collective efforts had contributed to containing the attacks, future attempts to access Singapore's telecommunications infrastructure cannot be ruled out, noting that telcos are strategic targets for state-sponsored actors because they play a foundational role in powering the digital economy and transmitting vast amounts of information. The Chinese Embassy in Singapore did not respond to a request for comment regarding the allegations, as Beijing has routinely denied allegations of cyber espionage and stated that it opposes all forms of cyberattacks.

Sources

Sources available to members: 3 sources.

CSIDB