Nearly 80% of Singapore firms report AI cyber threats: ESET
Only 49% of Singapore firms monitor AI tool access and outputs, exposing an oversight gap.
Seventy-nine percent of organisations in Singapore experienced at least one artificial intelligence (AI)-related cyber threat in the past 12 months, according to an ESET report.
Amongst the 400 cybersecurity decision-makers surveyed across Singapore, the Enterprise Cybersecurity Report 2026 revealed that 97% of organisations are using or piloting AI across functions such as customer service, document processing, business analytics, software development, risk management, and threat detection.
However, only 49% have measures to monitor AI tool access and outputs, highlighting a gap in oversight. Around four in ten organisations reported employee misuse of generative AI and data leakage through AI platforms.
AI-generated phishing and impersonation attacks were the most commonly reported AI-related threat (46%), followed by exploitation of AI-powered tools such as prompt injection (41%) and deepfake or voice cloning attacks (39%). Financial services (62%) and technology companies (55%) reported the highest levels of AI-generated phishing and impersonation attacks.
Beyond AI threats, 71% of organisations experienced at least one major cybersecurity incident in the past year, with 25% facing three or more. The most common incidents were cloud environment breaches, insider threats, and data exfiltration. Delayed detection was cited by 55% as a challenge, lack of visibility across environments by 49%, and shortages of skilled cybersecurity professionals by 41%. One in six organisations reported significant financial losses.
Phishing and social engineering attacks were the leading cause of incidents (36%), followed by lack of visibility across IT environments (34%), limited cybersecurity resources or skills shortages (34%), and user actions or human error (32%). ESET telemetry from H1 2026 also identified phishing as the leading threat observed globally.
Managed Detection and Response (MDR) was the most widely planned cybersecurity capability over the next 12 months, with 43% of organisations planning to adopt it. Cyber insurance is also of interest, but 97% reported challenges in obtaining or maintaining coverage, with stricter security requirements cited by 43%.