In brief
On 30 June 2026, the Cyber Security Agency (CSA) released its Singapore Cyber Landscape 2025/2026 Report (“Report”). The Report reviews Singapore’s cybersecurity situation for 2025 and 1H2026 against the backdrop of an evolving threat landscape driven by rapid technological advancements, and highlights Singapore’s efforts to build a safer cyberspace.
In more detail
Cybersecurity trends
Singapore’s cybersecurity landscape over the past 18 months was defined by several prominent trends, underpinned by a threat environment of growing complexity, speed, scale, and sophistication.
Some key trends are:
- Intertwined digital dependencies: Global information and communications technology (ICT) supply chains have evolved into deeply interconnected digital ecosystems, becoming amplifiers of systemic cyber risk. These supply chains enable cyber-attacks to cascade across entire industries and generate disproportionate impact.
- AI as a threat, tool and target: Artificial intelligence (AI) brings both tremendous opportunities and significant risks. The emergence of agentic AI (AI systems capable of independent reasoning, multi-step planning, and autonomous execution) represents a significant shift in the cybersecurity landscape. AI is being increasingly weaponised with threat actors now utilising agentic orchestrators to manage the entire attack lifecycle and automating parts of the cyber kill chain, allowing cybercriminals to carry out cyberattacks at a level that was previously only possible by nation state actors.
State of Singapore’s cyberspace
In line with global trends, Singapore’s cyber landscape saw an increase in ransomware attacks, with SMEs being the most affected. Singapore was also the 10th most attacked location globally for network-layer Distributed Denial-of-Service (DDoS) attacks.
Locally, there was also a notable rise in the number of infected systems, driven primarily by an expanded attack surface stemming from the increasing adoption of Malware-as-a-Service (MaaS) operations and the proliferation of consumer-grade Internet-of-Things (IoT) devices that have security weaknesses.
In 2025, Singapore also launched its largest coordinated cyber incident response to date, codenamed Operation Cyber Guardian. The operation was launched in response to a campaign by the advanced persistent threat actor UNC3886 targeting all four major Singapore telecommunications operators. UNC3886 gained access to limited parts of the telecommunications operators’ networks, including peripheral areas of critical systems, but did not disrupt services. A limited set of technical data, largely network-related, was exfiltrated, but the Report states that there was no evidence that sensitive or personal data, such as customer records, were accessed or exfiltrated.
Building a safer cyberspace – national strategies and capabilities
Amidst the evolving cyber threat landscape, CSA introduced several initiatives in 2025 to strengthen the cyber defences of Critical Information Infrastructure (CII) and organisations, and the cybersecurity awareness of individuals.
Some key developments include:
- Key provisions of the Cybersecurity (Amendment) Act 2024 came into force on 31 October 2025. These tackle three critical areas: (1) Expanded Risk Management Scope for CIIs, (2) Expanded Protection of Digital Infrastructure, and (3) Proactive Cybersecurity Measures for Systems of Temporary Cybersecurity Concern.
- CSA launched the revised and expanded Cyber Essentials and Cyber Trust marks in April 2025 to address emerging cyber risks from digital transformation.
- Safeguarding CII systems through the development of an Automated Indicator Sharing Platform for sharing timely and actionable cyber threat indicators.
- Strengthening cybersecurity collaboration with key industry partners such as Google, Amazon Web Services, and Microsoft.
- CSA’s National Quantum-Safe Initiative, a national approach to safeguard Singapore’s digital infrastructure against quantum threats.
CSA plans to review its national cybersecurity strategy and master plan in 2026 in response to AI-enabled threats.
Key takeaways
With the trends highlighted, organisations should note in particular that AI-driven phishing and impersonation attacks make strong identity protections essential. Organisations should therefore prioritise phishing-resistant authentication methods, session monitoring, and anomaly detection. Further, threat actors are now more sophisticated, which means that preparation, rapid detection and robust cybersecurity governance are increasingly necessary.

© 2026 Baker & McKenzie. Wong & Leow. All rights reserved. Baker & McKenzie. Wong & Leow is incorporated with limited liability and is a member firm of Baker & McKenzie International, a global law firm with member law firms around the world. In accordance with the common terminology used in professional service organizations, reference to a "principal" means a person who is a partner, or equivalent, in such a law firm. Similarly, reference to an "office" means an office of any such law firm. This may qualify as "Attorney Advertising" requiring notice in some jurisdictions. Prior results do not guarantee a similar outcome.