How one breach spreads across a Singapore MNC’s regional offices
Attackers exploit shared systems and vendor networks to turn one compromise into a regional crisis.
Singapore’s multinational companies (MNCs) are increasingly targeted by cyber attackers, with breaches spreading across regional offices through shared systems, vendors, and service providers, according to ThreatBook.
Attackers are scaling campaigns by reusing proven techniques across markets, allowing a single compromise to affect multiple countries, said Chase Li, co-founder and managing director for international business at ThreatBook.
“An attack proven against a bank in Singapore lands just as well on a Hong Kong bank running the same stack,” he said. “That is why a breach rarely stays in one market: a single compromise inside a multinational reaches its offices across countries, and one trusted node that falls carries the attacker into every business relying on it.”
In ransomware attacks, two tactics remain dominant, including data theft combined with encryption, known as “double extortion”, and targeting organisations with strong business continuity plans where ransom payments are often accounted for.
The report noted that advanced persistent threat (APT) groups targeting Singapore are increasingly using sophisticated methods, including phishing campaigns disguised as recruiters, developers, financiers and legal advisers; stolen identities of Singapore-based IT professionals; and AI-generated deepfake video calls impersonating executives.
The Asia-Pacific region has also become one of the fastest-growing markets for ransomware and data extortion. About 57% of initial ransom demands exceed $1.28m US$1m, whilst 52% of all ransom payments surpass the $1.28m (US$1m) mark.
Data breaches made up the largest share of incidents at 8,856 (39.9%), followed by ransomware at 4,068 (18.3%), phishing at 4,061 (18.3%), and state-affiliated advanced persistent threats (APTs) at 3,966 (17.9%).
According to Kaspersky, Singapore was amongst Southeast Asia's most targeted countries for Remote Desktop Protocol (RDP) and exploit attacks in 2025. The cybersecurity firm said it blocked more than 70,000 exploit attacks targeting businesses in Singapore, out of over 2 million detected across the region.
Separately, ExtraHop found that 42% of organisations in Singapore said attackers exploited encrypted traffic to avoid detection, whilst 38% attributed delayed or overlooked critical alerts to alert fatigue. Around 37% reported that threat actors imitated legitimate business processes, and 33% said attackers abused valid privileged accounts to gain access.
The survey also pointed to AI as an emerging security concern, with 32% of respondents identifying AI agents, agentic infrastructure, and generative AI applications as the biggest cybersecurity risk facing their organisation.
Feng Xue, co-founder and chief executive officer of ThreatBook, said the cyber threat landscape is changing as vulnerabilities are exploited faster and sophisticated attacks become accessible to less-skilled actors.
“The vulnerability lifecycle is compressing,” he said, adding that flaws that previously took weeks to exploit can now be weaponised at a pace beyond human teams.
AI is accelerating phishing attacks, accounting for about 80% of phishing activity tracked by ThreatBook, with click rates exceeding 50%.
E-commerce impersonation is the most common phishing method, followed by fake government notices, bank verification requests and QR-code scams.
State-linked APT groups are also shifting beyond intelligence theft, establishing access to communications networks and critical infrastructure that could be used during geopolitical conflicts.