Cyber Incident Victim: Simba Telecom
Timeline
Summary
Singapore’s cyber defenders thwarted a targeted espionage campaign against several major telecom operators, including Simba Telecom, carried out by the China‑linked group UNC3886. The attackers used a zero‑day exploit to breach perimeter firewalls and deployed rootkits to maintain persistence, gaining limited access to some critical systems but failing to disrupt services or exfiltrate customer data; they only obtained a small amount of technical information. A coordinated response involving multiple government agencies and the firm Mandiant identified the threat, blocked the intrusion points, and enhanced monitoring and defensive measures across the telecommunications sector.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
Four of Singapore's major telecom companies – Singtel, StarHub, M1 and Simba – were targeted by a cyberattack last year perpetrated by the cyber espionage group UNC3886. The attackers managed to gain access to a few critical systems across the telcos but did not progress far enough to disrupt services, as stated by Josephine Teo, Singapore's Minister for Digital Development and Information, at the Operation Cyber Guardian engagement event. There is no evidence thus far that the attackers accessed or stole sensitive customer data from any of the telcos, including Simba. The intrusion was first disclosed in July 2025 and prompted a coordinated response known as Operation Cyber Guardian, which brought together 100 cyber defenders from six government agencies: the Cyber Security Agency of Singapore, the Infocomm Media Development Authority, the Centre for Strategic Infocomm Technologies, the Digital and Intelligence Service of the Singapore Armed Forces, the Internal Security Department, and GovTech. Josephine Teo described Operation Cyber Guardian as the largest coordinated cyber response Singapore has mounted to date. Mandiant, a Google‑owned cybersecurity firm, has characterized UNC3886 as a China‑nexus espionage group that primarily targets defense, technology and telecommunications organizations in the US and Asia. In July 2025, Singapore's Coordinating Minister for National Security, K. Shanmugam, identified UNC3886 as a highly sophisticated threat actor attacking the city's critical infrastructure, though he withheld specific details citing security interests.

According to the Infocomm Media Development Authority, UNC3886 employed advanced tools to breach the telcos' defenses, including a zero‑day exploit that bypassed perimeter firewalls and rootkits that provided persistent access while covering tracks and evading detection. The group succeeded in exfiltrating a small amount of technical data from the telecommunications sector, which Josephine Teo said likely aimed to help the attackers understand the network terrain. In response, the Infocomm Media Development Authority announced that cyber defenders had implemented remediation measures, blocked the attackers' access points, and increased monitoring capabilities for the targeted telcos, including Simba. The Infocomm Media Development Authority, together with the Cyber Security Agency, has been working closely with the telecom companies to strengthen cybersecurity defenses, improve detection, and deploy active monitoring systems to guard against further attempts by UNC3886. Telecom companies have also undertaken joint threat hunting, penetration testing, and capability enhancements as part of their response. Meanwhile, the Cyber Security Agency plans to introduce initiatives to gradually uplift capabilities across Singapore's cyber ecosystem, aiming to enable more effective and timely responses to future threats.
While the collective efforts have contained the attack so far, authorities acknowledge that future attempts to gain access to telco infrastructure remain possible. Telecommunications firms are considered strategic targets for state‑sponsored and other threat actors because they underpin the digital economy and handle large volumes of information, including sensitive data. Should threat actors succeed in compromising telco networks, they could potentially undermine national security and economic stability. The incident underscores the ongoing need for vigilance, coordinated defense, and continuous improvement of protective measures across Singapore's telecommunications sector, including Simba Telecom.
