Cybersecurity 2026

SINGAPORE Trends and Developments Contributed by: Sheena Jacob, Sherman Poon and Andre Choo, CMS

defeated biometric onboarding and authentication in real incidents across multiple jurisdictions. Remote and cross-border channels are especially exposed, as synthetic media can bypass controls across dis - tributed teams and systems, increasing the risk of evasion of anti-money laundering, countering the financing of terrorism, and countering proliferation financing frameworks and controls. Deepfakes also enable misinformation and disinformation that can harm reputation, reduce trust, and move markets. Organisations should therefore monitor for brand abuse and impersonation and respond quickly with verified communications. Mitigation measures include robust document checks and image forensics, metadata analysis, liveness detection across video, image and voice, regular adversarial testing, and protections on devices to block injected media during live verification. High- risk processes can be strengthened with additional verification, multi-factor authentication, separation of duties, role-based access, and dual control to reduce the risk of single-point failure during a scam or imper - sonation attempt. Biometric data should be protect - ed with strong encryption in transit, at rest, and in use, together with certificate pinning, perfect forward secrecy, and secure enclaves to reduce the impact of interception or compromise. Real-time detection should be deployed on endpoints and communica - tions to flag manipulated media, integrate threat intel - ligence into monitoring, and include deepfake sce - narios in incident response plans, with sector-wide information sharing to accelerate detection, take - down, and recovery. Continued threat of cybercrime Cybercrime has further matured into a highly organ - ised, commercially driven ecosystem. Threat actors increasingly operate as co-ordinated groups, offering “cybercrime-as-a-service” models that lower barriers to entry and enable large-scale attacks (see here ). These actors leverage automation, AI, and data ana - lytics to identify vulnerabilities, select high-value tar - gets, and scale operations efficiently. Singapore continues to face a disproportionately high number of cybercrime attacks on its nationals, includ - ing both cyber-dependent crimes and cyber-enabled

crimes (see here ). The growing integration of digital payment systems, e-commerce platforms, and digital identity frameworks has expanded the attack surface for both cyber-dependent and cyber-enabled crimes. Losses are exacerbated not only by direct financial theft but also by downstream costs such as regula - tory investigations, business interruption, reputational harm, and litigation exposure. Singapore continues to experience one of the highest incidences of cybercrime loss globally, amounting to SGD456.4 million in the first half of 2025 (see here ). Law enforcement stepped up their efforts to tackle this, including arresting cybercrime syndicates, tak - ing action against money “mules” and working with other governments in Southeast Asia (see here, here and here ). A notable case to highlight relates to the UNC3886 cyber-espionage group, which has been responsible for several sophisticated attacks against critical infor - mation infrastructure (CII) in Singapore. In July 2025, Singapore officially attributed ongoing cyber-espio - nage and disruption of its CII to UNC3886, marking the first time the country publicly named an advanced persistent threat (APT) attacker (see here ). The attack prompted Singapore’s Cyber Security Agency (CSA) to raise the National Cyber Threat Alert Level and introduce new mandatory reporting requirements for CII owners to immediately report suspected APT inci - dents (see here ). Industrial-scale phishing and social engineering Phishing remained one of the most prevalent attack vectors in 2025, but its nature has evolved signifi - cantly. Generic phishing emails have given way to targeted attacks known as spear phishing (see here ). Spear phishing exploits personal data, organisational structure, and contextual data. AI-generated content allows threat actors to produce convincing emails, messages, and even voice communications that are difficult to distinguish from legitimate correspondence. The result is a higher success rate for phishing attacks and a reduced window for detection and response. In Singapore, the banking and financial services, gov - ernment and e-commerce industries were the most spoofed in 2024. Around 6,100 phishing attempts

299 CHAMBERS.COM

Powered by