Monday, August 3, 2026

Policy & Regulation

Singapore attributes cyber-espionage to China-linked group

Singapore’s government has attributed a cyber-espionage campaign against its four largest telecommunications companies to the group UNC3886, which is likely working on behalf of China.

Singapore attributes cyber-espionage to China-linked group

On Monday, the Singapore government confirmed that a known Chinese cyber-espionage group targeted the country’s telecommunications infrastructure. The attack, which focused on Singapore’s four largest telecommunications companies—Singtel, StarHub, M1, and Simba Telecom—was carried out by the hacking group UNC3886. This disclosure marks the first time the government has publicly identified the China-backed hackers as the perpetrators of the months-long campaign against its critical infrastructure.

While the intruders breached and accessed some systems, they did not disrupt services or access personal information, according to K. Shanmugam, Singapore’s coordinating minister for national security. A government statement noted that the hackers gained limited access to critical systems in one instance, but did not progress far enough to disrupt services. To maintain long-term persistence on the compromised systems, the hackers deployed rootkits—malicious software designed to provide unauthorized, persistent access to a computer system. The group is known for exploiting zero-day vulnerabilities, which are software security flaws that are unknown to the vendor and have no existing patch, to bypass standard security tools in routers and firewalls.

In response to the incident, the targeted telecommunications companies issued a joint statement noting that they regularly face malware and distributed denial-of-service attacks. “We adopt defence-in-depth mechanisms to protect our networks and conduct prompt remediation when any issues are detected,” the companies stated.

Cybersecurity unit Mandiant has previously identified UNC3886 as an espionage group likely working on behalf of China. The group has a history of targeting the defense, technology, and telecommunications sectors across the U.S. and the Asia-Pacific region. The Chinese government is reported to conduct regular cyber-espionage operations and preposition for disruptive attacks ahead of an anticipated invasion of Taiwan. While the campaign follows similar cyberattacks on telecom companies in the U.S. and elsewhere attributed to the China-backed group Salt Typhoon, Singapore officials stated that the UNC3886 attack did not result in the same level of damage.

Why it matters

This disclosure highlights the growing vulnerability of critical national infrastructure to state-sponsored cyber-espionage, specifically as geopolitical tensions rise in the Asia-Pacific region.