Back to News
technology

Singapore says China-backed hackers targeted its four largest phone companies

Zack Whittaker
Loading...
3 min read
0 likes
⚡ Quantum Brief
Singapore’s government confirmed a China-backed cyber-espionage group, UNC3886, targeted its four largest telecom firms—Singtel, StarHub, M1, and Simba Telecom—in a prolonged attack without disrupting services or stealing personal data. The hackers, linked to China by Google’s Mandiant, exploited zero-day flaws in routers and firewalls, using rootkits for long-term system persistence, though access to critical infrastructure remained limited. UNC3886, known for targeting U.S. and Asia-Pacific defense and tech sectors, aligns with China’s broader cyber-espionage strategy, including prepositioning for potential Taiwan conflict scenarios, per Reuters. Singapore’s telcos stated they mitigate frequent DDoS and malware attacks via "defense-in-depth" strategies, emphasizing rapid remediation despite the sophisticated breach attempt. Unlike past global attacks by China’s Salt Typhoon group, Singapore reported minimal damage, suggesting stronger resilience in its critical telecom infrastructure.
AI Audio Summary
0:00 / 0:00
Click to play
vishal-bansal-SC5sXeyjloE-unsplash.jpg
Quantum News · Media Library

Singapore’s government has blamed a known Chinese cyber-espionage group for targeting four of its top telecommunication companies as part of a months-long attack. In a statement Monday, Singapore confirmed for the first time that the hackers, known as UNC3886, targeted the country’s telecoms infrastructure, including its largest companies: Singtel, StarHub, M1, and Simba Telecom. The government previously said that it was responding to an unspecified attack on its critical infrastructure. While the intruders were able to breach and access some systems, they did not disrupt services or access personal information, said K. Shanmugam, the country’s coordinating minister for national security. Google-owned cybersecurity unit Mandiant previously linked UNC3886 as an espionage group likely working on behalf of China. The Chinese government is known to conduct regular cyber-espionage operations, as well as prepositioning for disruptive attacks ahead of an anticipated invasion of Taiwan, which Beijing has routinely denied, per Reuters. UNC3886 is known for exploiting zero-day vulnerabilities in routers, firewalls, and virtualized environments, where cybersecurity tools that are designed to spot malware cannot typically reach. The hacking group has targeted the defense, technology, and telecom industries across the U.S. and the Asia-Pacific region. In the case of the attack on Singapore’s top telcos, Shanmugam said the hackers used advanced tools, like rootkits, to gain long-term persistence to their systems. “In one instance, they were able to gain limited access to critical systems but did not get far enough to have been able to disrupt services,” according to the government’s statement. Per Reuters, the telcos said in a joint statement that the companies regularly face distributed denial-of-service and other malware attacks. “We adopt defence-in-depth mechanisms to protect our networks and conduct prompt remediation when any issues are detected,” the statement read. The attacks on Singapore’s telcos follow similar but distinctly different attacks on hundreds of telecoms companies around the world in recent years, including in the United States. Multiple governments have linked these attacks to a China-backed group dubbed Salt Typhoon. Singapore said the attack carried out by UNC3886 has “not resulted in the same extent of damage as cyberattacks elsewhere,” referring to the Salt Typhoon hacks. Topics China, cyberattack, Government & Policy, Mandiant, salt typhoon, Security, Singapore, telecoms infrastructure Zack Whittaker Security Editor Zack Whittaker is the security editor at TechCrunch. He also authors the weekly cybersecurity newsletter, this week in security. He can be reached via encrypted message at zackwhittaker.1337 on Signal. You can also contact him by email, or to verify outreach, at zack.whittaker@techcrunch.com.

View Bio October 13-15 San Francisco, CA Tickets are live at the lowest rates of the year. Save up to $680 on your pass now.Meet investors. Discover your next portfolio company. Hear from 250+ tech leaders, dive into 200+ sessions, and explore 300+ startups building what’s next. Don’t miss these one-time savings. REGISTER NOW Most Popular YouTube TV introduces cheaper bundles, including a $65/month sports package Sarah Perez From Svedka to Anthropic, brands make bold plays with AI in Super Bowl ads Lauren Forristal Senator, who has repeatedly warned about secret US government surveillance, sounds new alarm over ‘CIA activities’ Zack Whittaker The backlash over OpenAI’s decision to retire GPT-4o shows how dangerous AI companions can be Amanda Silberling OpenAI launches new agentic coding model only minutes after Anthropic drops its own Lucas Ropek Anthropic releases Opus 4.6 with new ‘agent teams’ Lucas Ropek Sam Altman got exceptionally testy over Claude Super Bowl ads Julie Bort

Read Original

Tags

aerospace-defense
telecommunications

Source Information

Source: TechCrunch

Discussion

0 professional contributions

Sign in to join this professional discussion.

Be the first to add a constructive contribution.