Singapore shifts cyber strategy after UNC3886 telco attacks, deploys AI security tools
Singapore's Cyber Security Agency has developed and deployed in-house AI tools to secure around 2,000 government systems, shifting from perimeter defence to active threat hunting after state-sponsored group UNC3886 attacked the country's four major telcos.
Singapore’s authorities have developed and deployed in-house artificial intelligence tools to secure around 2,000 government systems, shifting from perimeter defence to active threat hunting after state-sponsored cyberespionage group UNC3886 attacked the country’s four major telcos.
The attack was first made public in July 2025. It could have disrupted telecommunications and internet services had the attackers penetrated further, and threatened national security, The Straits Times reported.
In her first interview since taking over as chief executive of the Cyber Security Agency of Singapore (CSA) in July, Gwenda Fong told the paper one key learning was that defences must go beyond keeping attackers out: operators must assume attackers are already inside the network and hunt them down before they cause further damage.
Developed by the Government Technology Agency (GovTech), one AI tool conducts automated penetration testing on about 2,000 government systems, some of which contain citizen data and transactions, simulating cyberattacks to find vulnerabilities hackers could exploit. A second scans the source code of government applications and systems for security weaknesses so agencies can plug gaps before hackers exploit them. The agencies that have deployed the tools were not revealed, with plans to expand use to other critical information infrastructure sectors.
Post-UNC3886, CSA has also begun regularly scanning all internet-facing systems of critical infrastructure operators to flag entry points such as unpatched software or weak configurations, and is looking to require some operators’ vendors and suppliers to obtain Cyber Essentials or Cyber Trust mark certifications, potentially as early as 2027. Uptake has been slow: only 874 Cyber Essentials and 346 Cyber Trust certifications had been issued as of August.
Suspected advanced persistent threat activity in Singapore quadrupled between 2021 and 2024, according to CSA’s Singapore Cyber Landscape 2024 report.
Sources
More on this topic: all Technology stories

