Back Lightreading Singapore thwarts targeted attack on telco infrastructure
Four of Singapore's major telecom companies were targeted by a cyberattack last year perpetrated by the cyber espionage group UNC3886.
Four of Singapore's major telecom companies – Singtel, StarHub, M1 and Simba – were targeted by a cyberattack last year perpetrated by the cyber espionage group UNC3886.
"In one instance, they were able to gain access to a few critical systems, but did not get far enough to have been able to disrupt services," said Josephine Teo, Singapore's Minister for Digital Development and Information, at the Operation Cyber Guardian engagement event on Monday.
"There is also no evidence thus far to suggest that the attackers were able to access or steal sensitive customer data from our telcos," she added.
Operation Cyber Guardian is a group of 100 cyber defenders who led Singapore's coordinated response to the cyberattack first disclosed in July 2025. This multi-agency effort included six government agencies: the Cyber Security Agency of Singapore, the Infocomm Media Development Authority (IMDA), the Centre for Strategic Infocomm Technologies (CSIT), the Digital and Intelligence Service of the Singapore Armed Forces, the Internal Security Department, and GovTech.
According to Teo, Operation Cyber Guardian is the largest coordinated cyber response from Singapore to date.
Mandiant, a Google-owned cybersecurity firm, has described UNC3886 as a "China-nexus espionage group" that has targeted prominent organizations in various strategic sectors around the world. This group has primarily attacked defense, technology and telecommunications organizations in the US and Asia.
Last July, Singapore's Coordinating Minister for National Security, K. Shanmugam, identified UNC3886 as the "highly sophisticated threat actor" that is attacking the city's critical infrastructure. However, he did not disclose details of the attack, stating that doing so would not be in Singapore's security interests.
Sophisticated attacks
Singapore is no stranger to state- cyberattacks.
In 2014, an attacker infiltrated the Ministry of Foreign Affairs' IT system and attempted to steal sensitive information. Then, four years later, another group hacked SingHealth’s systems and stole more than 1.5 million records, including those of former Prime Minister Lee Hsien Loong.
However, Teo pointed out that UNC3886 poses a more serious threat than attacks because it targets critical systems that provide essential services to the public.
"Our investigations show that the attacks by UNC3886 were a deliberate, targeted, and well-planned campaign against our telecommunications sector," Teo said.
"At stake was not just sensitive data. The consequences could have been more severe; if the attack went far enough, it could have allowed the attacker to one day cut off telecoms or internet services," she added.
According to the IMDA, UNC3886 deployed advanced tools in their campaign to gain access to Singapore telco systems. For one, the group used a zero-day exploit to bypass the telcos' perimeter firewall and gain access to their networks. They also used advanced tools and techniques, such as rootkits, to maintain persistent access, cover their tracks and evade detection.
"UNC3886 managed to steal a small amount of technical data – likely data that will help them to understand the terrain and what they are dealing with," Teo said.
In a statement released Monday, the IMDA announced that cyber defenders have implemented remediation measures, blocked UNC3886’s access points and increased monitoring capabilities for targeted telecommunications companies.
The IMDA, along with the CSA, is working closely with telecom companies to strengthen cybersecurity defenses, improve detection capabilities, and deploy active monitoring systems. These measures are intended to guard against new attempts by UNC3886 to access their networks.
Furthermore, telecom companies have also implemented interventions, including joint threat hunting, penetration testing, and enhancing capabilities, according to the IMDA.
Meanwhile, the CSA will introduce initiatives to gradually improve capabilities across Singapore's cyber ecosystem. These initiatives will enable more effective and timely responses to cyber threats and strengthen Singapore’s cyber defenses.
"While our collective efforts have contributed to containing the attacks so far, we must be prepared that there may be future attempts to gain access into our telco infrastructure. Telcos are strategic targets for threat actors, including state- ones.
"They play a foundational role in powering the digital economy and transmit vast amounts of information, including sensitive data. If threat actors succeed in attacking our telcos, they have the potential to undermine our national security and our economy," the IMDA said.
Senior Editor, APAC, Light Reading
Gigi Onag is Senior Editor, APAC, Light Reading. She has been a technology journalist for more than 15 years, covering various aspects of enterprise IT across Asia-Pacific.
She started with regional IT publications under CMP Asia (now Informa), including Asia Computer Weekly, Intelligent Enterprise Asia and Network Computing Asia and Teledotcom Asia. This was followed by stints with Computerworld Hong Kong and sister publications FutureIoT and FutureCIO. She had contributed articles to South China Morning Post, TechTarget and PC Market among others.
She interspersed her career as a technology editor with a brief sojourn into public relations before returning to journalism, joining the editorial team of Mix Magazine, a MICE publication and its sister publication Business Traveller Asia Pacific.
Gigi is based in Hong Kong and is keen to delve deeper into the region’s wide wild world of telecoms.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
