Singapore Discloses Year-Long Telecom Breach by China-Linked Group
A state-sponsored group breached all four of Singapore's major carriers, showing how advanced attackers can persist undetected in critical infrastructure.
Eleven-Month Campaign Against National Infrastructure
Singapore's Cyber Security Agency disclosed on February 9, 2026, that a threat group known as UNC3886 successfully breached all four of the country's major telecommunications operators: Singtel, StarHub, M1, and Simba Telecom. The campaign was deliberate, targeted, and well-planned, according to the agency's official statement.
The attackers used a zero-day exploit to bypass perimeter firewalls and deployed rootkits to maintain persistent, undetected access. In one instance, they gained limited access to critical systems but were contained before they could disrupt services. A small amount of technical network data was exfiltrated, believed to be intended for advancing the threat actors' operational objectives.
Operation CYBER GUARDIAN
Singapore launched its largest coordinated cyber incident response to date, codenamed Operation CYBER GUARDIAN, which spanned more than eleven months. Over 100 cyber defenders from six government agencies worked in partnership with the telecommunications companies to contain the breach and evict the attackers.
Authorities confirmed there is no evidence that customer records or sensitive personal data were accessed. Cyber defenders have since closed off the access points used by UNC3886 and expanded monitoring capabilities within the telecom operators to detect attempts at re-entry.
The UNC3886 Threat Actor
Cybersecurity firm Mandiant previously linked UNC3886 as an espionage group likely working on behalf of China. The group is known for its technical sophistication, including development of custom malware, exploitation of zero-day vulnerabilities, and use of advanced rootkits for stealth and persistence.
While Singapore's government has not officially attributed the attack to any nation-state, multiple cybersecurity researchers describe UNC3886 as a China-nexus advanced persistent threat actor that has been active since at least 2022, targeting telecommunications, government, technology, and defense sectors across Asia, North America, and Europe.
- https://techcrunch.com/2026/02/10/singapore-china-backed-hackers-targeted-largest-phone-companies-salt-typhoon/
- https://www.csa.gov.sg/news-events/press-releases/largest-multi-agency-cyber-operation-mounted-to-counter-threat-posed-by-advanced-persistent-threat--apt--actor-unc3886-to-singapore-s-telecommunications-sector/
- https://thehackernews.com/2026/02/china-linked-unc3886-targets-singapore.html