Singapore Discloses Year-Long Telecom Breach by China-Linked Group

A state-sponsored group breached all four of Singapore's major carriers, showing how advanced attackers can persist undetected in critical infrastructure.

Illustration: Singapore Discloses Year-Long Telecom Breach by China-Linked Group
AI-generated illustration · Sylvaris

Eleven-Month Campaign Against National Infrastructure

Singapore's Cyber Security Agency disclosed on February 9, 2026, that a threat group known as UNC3886 successfully breached all four of the country's major telecommunications operators: Singtel, StarHub, M1, and Simba Telecom. The campaign was deliberate, targeted, and well-planned, according to the agency's official statement.

The attackers used a zero-day exploit to bypass perimeter firewalls and deployed rootkits to maintain persistent, undetected access. In one instance, they gained limited access to critical systems but were contained before they could disrupt services. A small amount of technical network data was exfiltrated, believed to be intended for advancing the threat actors' operational objectives.

Operation CYBER GUARDIAN

Singapore launched its largest coordinated cyber incident response to date, codenamed Operation CYBER GUARDIAN, which spanned more than eleven months. Over 100 cyber defenders from six government agencies worked in partnership with the telecommunications companies to contain the breach and evict the attackers.

Authorities confirmed there is no evidence that customer records or sensitive personal data were accessed. Cyber defenders have since closed off the access points used by UNC3886 and expanded monitoring capabilities within the telecom operators to detect attempts at re-entry.

The UNC3886 Threat Actor

Cybersecurity firm Mandiant previously linked UNC3886 as an espionage group likely working on behalf of China. The group is known for its technical sophistication, including development of custom malware, exploitation of zero-day vulnerabilities, and use of advanced rootkits for stealth and persistence.

While Singapore's government has not officially attributed the attack to any nation-state, multiple cybersecurity researchers describe UNC3886 as a China-nexus advanced persistent threat actor that has been active since at least 2022, targeting telecommunications, government, technology, and defense sectors across Asia, North America, and Europe.

sources
more in Security
Upbound breach enabled $13 million in fraudulent Acima leases Stolen customer data was directly weaponized to create fraudulent financial contracts, demonstrating how breach data enables immediate financial crime. Fake job interview delivers malware through Git hooks in take-home coding projects Attackers are weaponizing the technical interview process itself, embedding malicious Git hooks in legitimate-looking coding assignments to compromise developer workstations. South Korea National Diplomatic Academy breach exposes global diplomat data after ten-month intrusion A prolonged breach of diplomatic training infrastructure exposed sensitive personnel data of current and former foreign service officers worldwide, demonstrating the targeting of government educational systems.