A ransomware attack crippled Pennsylvania’s Attorney General office, exposing sensitive data including names, Social Security numbers and medical details. Inc Ransom claimed responsibility after exploiting a Citrix vulnerability that disrupted systems for weeks.
Berlin-based Peec AI has raised a $21M Series A to scale its marketing platform for the AI search era. As consumers shift from Google to ChatGPT, Peec helps brands analyse and improve their visibility in AI-generated answers, pioneering the new field of Generative Engine Optimisation (GEO).
Parallel Web Systems, the AI startup from former Twitter CEO Parag Agrawal, has secured $100 million in a Series A round co-led by Kleiner Perkins and Index Ventures. The company is building a new layer of web infrastructure designed for AI agents to search and interact with live, accurate data.
Singapore Confirms Cyberattack by China-Linked Group Targeting Critical Infrastructure
Singapore is responding to a cyberattack by UNC3886, a China-linked espionage group targeting critical infrastructure. Minister K. Shanmugam confirmed the threat is serious and ongoing, as the CSA leads investigations to protect national services from long-term disruption.
The Singapore government has confirmed it is responding to an ongoing cyberattack from a sophisticated threat actor linked to China. The attack is targeting critical infrastructure across the country.
In a rare public statement, Coordinating Minister for National Security K. Shanmugam identified the group as UNC3886. This group has been described by cybersecurity firm Mandiant, a subsidiary of Google, as a China-based espionage operation focused on long-term surveillance and disruption.
The announcement was made during the 10th anniversary dinner of the Cyber Security Agency of Singapore (CSA), highlighting growing concern over state-sponsored cyber threats and their potential to interfere with essential national services.
Sophisticated Threat Actor
UNC3886 is classified as an Advanced Persistent Threat (APT), a term used for highly skilled and well-funded cyber groups that can infiltrate systems and remain undetected for extended periods.
On July 18, Coordinating Minister for National Security K. Shanmugam delivered a speech addressing the threat posed by UNC3886 and why the government is limiting public disclosure about the incident. He emphasized the seriousness of the group’s actions and its history of targeting sensitive sectors across the United States and Asia, including defense, telecommunications, and technology.
“This is not a random cyber incident,” Shanmugam said. “The intent is clear. It is to conduct espionage and potentially disrupt vital infrastructure that delivers essential services to Singaporeans.”
Watch the full remarks:
Rising Cyber Threats
The minister also pointed out a sharp rise in APT-related threats against Singapore. Between 2021 and 2024, suspected attacks by these groups have increased more than fourfold, suggesting a shift in the overall cyber threat landscape.
At this stage, the government has declined to share further details of the breach, citing national security and the need to protect operational plans.
CSA Takes the Lead
In a separate statement, the Cyber Security Agency of Singapore confirmed that it is leading the investigation into the activities of UNC3886 and providing assistance to affected organizations.
“We have been investigating UNC3886's activities since its presence was detected in parts of our critical infrastructure,” the agency said.
The CSA is currently monitoring all nine of Singapore’s critical information infrastructure sectors. These include energy, water, banking, healthcare, transport, and government services. The agency is also sharing threat intelligence with other authorities to help strengthen national cyber defenses.
“These attacks are often part of long-term campaigns,” CSA said. “To protect ongoing investigations and response efforts, we will not be releasing further details at this time.”
Strategic Implications
The involvement of a state-linked group adds to broader concerns about cyber-espionage becoming a tool of global competition. As nations invest more heavily in digital infrastructure, the risks posed by foreign cyber operations continue to grow.
Shanmugam emphasized that Singapore remains committed to strengthening its cyber resilience, especially as digital systems become central to national security and daily life.
The CSA’s 10th anniversary not only marks a decade of progress in cybersecurity but also serves as a reminder of the increasingly complex threats facing Singapore.
As the investigation moves forward, the government is expected to enhance collaboration with private sector partners and deepen ties with regional and global allies to counter emerging cyber threats.
Get the stories that matter to you. Subscribe to Cyber News Centre and update your preferences to follow our Daily 4min Cyber Update, Innovative AI Startups, The AI Diplomat series, or the main Cyber News Centre newsletter — featuring in-depth analysis on major cyber incidents, tech breakthroughs, global policy, and AI developments.
Sign up for Cyber News Centre
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead.
Somalia's government has confirmed a major data breach of its electronic visa system, exposing the sensitive personal information of over 35,000 travellers. The incident has prompted warnings from the US and UK, raising serious concerns over digital infrastructure security.
A wave of cyber attacks disrupted Australia’s defence and industry sectors, as confidential military data and industrial networks were exposed by state backed and criminal groups. ASIO’s director warns these persistent threats now demand urgent, coordinated cyber security action.
The Australian Signals Directorate (ASD) has issued a critical alert regarding the BADCANDY malware, which is actively exploiting a Cisco vulnerability to compromise hundreds of devices across Australia. The non-persistent web shell allows attackers to reinfect unpatched systems repeatedly.
Japan's largest brewer, Asahi Group Holdings, has confirmed a ransomware attack by the Qilin group, resulting in production shutdowns and the theft of 27GB of corporate data.
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead. Sign up for free!