Singapore launched its largest coordinated cyber defense and incident response effort after a sophisticated intrusion campaign targeted all four major telecommunications operators—M1, SIMBA Telecom, Singtel, and StarHub—according to the Cyber Security Agency of Singapore (CSA) and Minister Josephine Teo. Authorities described the activity as a deliberate, well-planned operation consistent with cyber espionage, prompting a whole-of-government response dubbed Operation Cyber Guardian.
CSA said the attackers achieved unauthorized access to parts of telecom networks and, in at least one case, reached limited portions of critical systems, but reported no service disruptions and no evidence that customer data was accessed or exfiltrated. Singapore attributed the campaign to the China-linked threat actor UNC3886, noting the use of advanced tooling for stealth and persistence; officials also stated that at least one intrusion involved exploitation of a previously unknown software vulnerability, though detailed technical indicators were not publicly released.

See the actors and campaigns active against you right now.
6 events from the most recent confirmed update back to the earliest known activity.
On February 9, 2026, Minister Josephine Teo announced that Singapore had mounted its largest coordinated cyber defense operation in response to the telecom attacks. The government said it would continue joint threat-hunting, penetration testing, and expanded monitoring across the sector to prevent re-entry.
On February 9, 2026, Singapore's Cyber Security Agency publicly attributed the campaign against the country's telecom providers to UNC3886, a China-linked cyberespionage group. Authorities described the operation as deliberate, well-planned, and aimed at maintaining long-term covert access to telecom infrastructure.
By February 2026, Singapore said Operation Cyber Guardian had successfully contained the malicious activity targeting the telecom sector. Officials reported no service disruptions and no evidence that customer information was compromised, though technical data was exfiltrated.
During the campaign, the threat actor obtained unauthorized access to parts of all four major Singapore telecom networks and, in one case, reached limited portions of critical systems. Authorities said the operation used advanced tooling, stealth malware, long-term persistence techniques, and at least one previously unknown software vulnerability.
Following the July 2025 confirmation, Singapore began a nearly year-long multi-agency incident response effort called Operation Cyber Guardian. More than 100 cyber defenders from government, military, intelligence, and telecom operators were mobilized to investigate and contain the intrusion.
In July 2025, Singapore confirmed that a threat actor had been observed attacking critical infrastructure, though authorities withheld detailed public information at the time for national-interest reasons. The activity later proved to involve all four major telecommunications operators.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
4 references tracked. Mallory keeps watching after this page renders.
govinfosecurity.com
Open sourcebankinfosecurity.com
Open sourceteiss.co.uk
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.