That distinction matters. The figure does not mean every additional infection was newly created during the year; better detection can expose systems that previously went unnoticed. But it does show how much compromised infrastructure was visible to Singapore’s defenders—and how attractive the country’s connected devices remain to attackers.
The report links the wider malware problem to the growth of malware-as-a-service, which allows criminals to access malicious capabilities without building every tool themselves. Consumer IoT devices, including poorly configured or unpatched network equipment, provide a large pool of potential botnet devices.
Singapore also reported attacks involving unpatched routers at multiple organisations. In those incidents, attackers created unauthorised administrator accounts and installed tools designed to survive later security updates.
As a response, residential routers sold in Singapore are due to meet Cybersecurity Labelling Scheme Level 2 requirements by the end of 2027. The policy is intended to raise baseline protections for devices that can otherwise become entry points or part of larger botnets.
The report describes artificial intelligence as part of an increasingly complex, AI-enabled threat landscape. AI can help attackers produce convincing messages and synthetic media at greater speed and scale; Singaporean authorities have separately warned about scams involving manipulated media, including deepfakes.
The practical implication is that cybersecurity teams cannot rely only on spotting obvious spelling errors, crude images or poorly written scam messages. Organisations and individuals need controls that verify unusual requests through trusted channels, protect accounts with strong authentication and limit the damage when a device or identity is compromised.
Reported phishing attempts fell by roughly one-fifth, from about 6,100 in 2024 to around 4,800 in 2025.
That decline should be read carefully. Reported cases measure incidents brought to the authorities, not every phishing attempt that occurred. At the same time, AI-generated content can make impersonation and fraud more persuasive, potentially changing the quality of attacks even when the reported volume falls. The supplied evidence does not establish a reliable 2025 ranking of the sectors or foreign institutions most frequently impersonated, so those details cannot be stated with confidence.
Ransomware cases edged up from 159 in 2024 to 165 in 2025. Small and medium-sized enterprises were disproportionately affected, reflecting the difficulty of maintaining mature cyber defences with more limited resources.
For SMEs, the lesson is operational rather than theoretical: regular patching, tested backups, strong access controls and a rehearsed incident-response plan can reduce the consequences of a successful intrusion. The report’s focus on support and recovery reflects the reality that resilience depends on how quickly an organisation can contain an incident and restore essential operations—not only on whether it can prevent every attack.
One of the most significant incidents involved the advanced persistent threat actor UNC3886, which attempted to intrude into all four of Singapore’s major telecommunications operators. Singapore responded with Operation Cyber Guardian, described in the supplied reporting as the country’s largest coordinated cyber-incident response operation. The operation contained the threat without reported disruption to telecommunications services or evidence of customer-data compromise.
The episode illustrates why critical infrastructure is treated differently from ordinary enterprise IT. A compromise affecting telecommunications, energy, finance or healthcare can create consequences beyond one organisation, making coordination between operators and government agencies essential.
Singapore’s critical information infrastructure framework covers 11 sectors:
The Cyber Security Agency of Singapore is requiring critical information infrastructure owners to attain Cyber Trust Mark Level 5 certification by the end of 2027. The broader certification framework has also been enhanced to address cloud security, operational-technology security and AI security—not just conventional IT controls.
This expands the focus from protecting a designated system in isolation to managing the wider network of connected systems and suppliers around it. That is particularly important when attackers use exposed routers, cloud services or operational technology as stepping stones into more valuable environments.
David Koh, the founding chief executive of Singapore’s Cyber Security Agency and Commissioner of Cybersecurity, retired from both roles on 1 July 2026. He was succeeded by Gwenda Fong.
The change came after the report period covered by the 2025/2026 publication, so it is best understood as a leadership transition accompanying Singapore’s next phase of cyber-resilience work—not as a finding about the 2025 threat data itself.
The central message is not simply that Singapore experienced more cyberattacks. It is that the country is confronting a threat ecosystem that is becoming easier to scale and harder to recognise, while its own detection and response capabilities are also becoming more active.
Three conclusions stand out:
The result is a cybersecurity strategy built around visibility, coordinated response and enforceable standards—as well as the everyday security practices needed to keep vulnerable devices and smaller organisations from becoming the next weak link.