Singapore Confirms Cyberattack by China-Linked Group Targeting Critical Infrastructure

Singapore is responding to a cyberattack by UNC3886, a China-linked espionage group targeting critical infrastructure. Minister K. Shanmugam confirmed the threat is serious and ongoing, as the CSA leads investigations to protect national services from long-term disruption.

Singapore Confirms Cyberattack by China-Linked Group Targeting Critical Infrastructure
Coordinating Minister for National Security and Minister for Home Affairs K Shanmugam. (Source: Cyber Security Agency of Singapore)

The Singapore government has confirmed it is responding to an ongoing cyberattack from a sophisticated threat actor linked to China. The attack is targeting critical infrastructure across the country.

In a rare public statement, Coordinating Minister for National Security K. Shanmugam identified the group as UNC3886. This group has been described by cybersecurity firm Mandiant, a subsidiary of Google, as a China-based espionage operation focused on long-term surveillance and disruption.

The announcement was made during the 10th anniversary dinner of the Cyber Security Agency of Singapore (CSA), highlighting growing concern over state-sponsored cyber threats and their potential to interfere with essential national services.

Sophisticated Threat Actor

UNC3886 is classified as an Advanced Persistent Threat (APT), a term used for highly skilled and well-funded cyber groups that can infiltrate systems and remain undetected for extended periods.

On July 18, Coordinating Minister for National Security K. Shanmugam delivered a speech addressing the threat posed by UNC3886 and why the government is limiting public disclosure about the incident. He emphasized the seriousness of the group’s actions and its history of targeting sensitive sectors across the United States and Asia, including defense, telecommunications, and technology.

“This is not a random cyber incident,” Shanmugam said. “The intent is clear. It is to conduct espionage and potentially disrupt vital infrastructure that delivers essential services to Singaporeans.”

Watch the full remarks:

Rising Cyber Threats

The minister also pointed out a sharp rise in APT-related threats against Singapore. Between 2021 and 2024, suspected attacks by these groups have increased more than fourfold, suggesting a shift in the overall cyber threat landscape.

At this stage, the government has declined to share further details of the breach, citing national security and the need to protect operational plans.

CSA Takes the Lead

In a separate statement, the Cyber Security Agency of Singapore confirmed that it is leading the investigation into the activities of UNC3886 and providing assistance to affected organizations.

“We have been investigating UNC3886's activities since its presence was detected in parts of our critical infrastructure,” the agency said.

The CSA is currently monitoring all nine of Singapore’s critical information infrastructure sectors. These include energy, water, banking, healthcare, transport, and government services. The agency is also sharing threat intelligence with other authorities to help strengthen national cyber defenses.

“These attacks are often part of long-term campaigns,” CSA said. “To protect ongoing investigations and response efforts, we will not be releasing further details at this time.”

Strategic Implications

The involvement of a state-linked group adds to broader concerns about cyber-espionage becoming a tool of global competition. As nations invest more heavily in digital infrastructure, the risks posed by foreign cyber operations continue to grow.

Shanmugam emphasized that Singapore remains committed to strengthening its cyber resilience, especially as digital systems become central to national security and daily life.

The CSA’s 10th anniversary not only marks a decade of progress in cybersecurity but also serves as a reminder of the increasingly complex threats facing Singapore.

As the investigation moves forward, the government is expected to enhance collaboration with private sector partners and deepen ties with regional and global allies to counter emerging cyber threats.


Get the stories that matter to you.
Subscribe to Cyber News Centre and update your preferences to follow our Daily 4min Cyber Update, Innovative AI Startups, The AI Diplomat series, or the main Cyber News Centre newsletter — featuring in-depth analysis on major cyber incidents, tech breakthroughs, global policy, and AI developments.

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to Cyber News Centre.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.