Singapore shifts cyber strategy after UNC3886 attacks, deploys AI security tools

Singapore shifts cyber strategy after UNC3886 attacks, deploys AI security tools


SINGAPORE – The local authorities have developed and deployed in-house artificial intelligence tools to better secure some 2,000 government systems under expanded cyber security efforts.

This proactive posture – shifting from perimeter defense to active threat hunting – comes in the wake of an attack on the country’s four major telcos by state-sponsored cyberespionage group UNC3886.

The attack was first made public in July 2025. It could have disrupted telecommunications and internet services had the attackers penetrated further, and threatened national security.

In her first interview since taking over as chief executive of the Cyber Security Agency of Singapore (CSA) in July 2026, Gwenda Fong told The Straits Times that one of the key learning points from the incident is that defences need to go beyond keeping attackers out.

This is because advanced persistent threat actors (APTs) like UNC3886 pursue specific targets.

“APTs are driven by state-backed objectives and you are their target,” said Fong, adding that focusing on threat prevention will not be enough.

Instead, one must now assume that attackers are already inside an operator’s network, and focus on hunting them down before they wreak further havoc.

“You also have to assume that the most well-resourced and qualified attackers will find a way in at some point,” added Fong, in the ST interview on Sept 3.

Once inside, however, attackers still have to move through the network in search of sensitive systems and data, giving defenders opportunities to detect them through unusual activity.

“You need to monitor the internal traffic. You need to detect anomalous traffic behaviour. You need to constantly do threat hunting,” said Fong.




Read Full Article At Source

Share. Save. Don't Miss The Buzz: XFacebookRedditLINETelegramWhatsAppGmail

Leave a Reply