Singapore shifts cyber strategy after UNC3886 attacks, deploys AI security tools新加坡在 UNC3886 遭受攻击后调整网络战略,部署人工智能安全工具
One AI-powered tool that has been rolled out conducts automated penetration testing on about 2,000 government systems. Read more at straitstimes.com.
Gwenda Fong took over as chief executive of the Cyber Security Agency of Singapore and Commissioner of Cybersecurity on July 1.
ST PHOTO: JASON KUAH
Published Sep 27, 2026, 05:00 AM
Updated Sep 27, 2026, 05:00 AM
SINGAPORE - The local authorities have developed and deployed in-house artificial intelligence tools to better secure some 2,000 government systems under expanded cyber security efforts .
This proactive posture - shifting from perimeter defense to active threat hunting - comes in the wake of an attack on the country’s four major telcos by state-sponsored cyberespionage group UNC3886.
The attack was first made public in July 2025. It could have disrupted telecommunications and internet services had the attackers penetrated further, and threatened national security.
In her first interview since taking over as chief executive of the Cyber Security Agency of Singapore (CSA) in July 2026, Gwenda Fong told The Straits Times that one of the key learning points from the incident is that defences need to go beyond keeping attackers out.
This is because advanced persistent threat actors (APTs) like UNC3886 pursue specific targets.
“APTs are driven by state-backed objectives and you are their target,” said Fong, adding that focusing on threat prevention will not be enough.
Instead, one must now assume that attackers are already inside an operator’s network, and focus on hunting them down before they wreak further havoc.
“You also have to assume that the most well-resourced and qualified attackers will find a way in at some point,” added Fong, in the ST interview on Sept 3.
Once inside, however, attackers still have to move through the network in search of sensitive systems and data, giving defenders opportunities to detect them through unusual activity.
“You need to monitor the internal traffic. You need to detect anomalous traffic behaviour. You need to constantly do threat hunting,” said Fong.
Developed by the Government Technology Agency of Singapore (GovTech), the new AI tools can take on some of this work.
One AI-powered tool conducts automated penetration testing on about 2,000 government systems, some of which contain citizen data and transactions. Automated penetration testing uses software to simulate cyber attacks and identify vulnerabilities that hackers can exploit.
The second AI tool scans the source code of government applications and systems for security weaknesses, allowing agencies to plug the gaps before hackers exploit them.
CSA and GovTech did not reveal which agencies have deployed the AI tools. There are also plans to expand their use in other critical information infrastructure sectors (CII).
The 11 CII sectors in Singapore are government , aviation, healthcare, land transport, maritime, media, security and emergency services, water, banking and finance, energy, and info-communications.
“This work is still at the evaluation stage and involves considering operational requirements, effectiveness and sector-specific needs,” said CSA and GovTech, declining to provide details.
Post-UNC3886, CSA has also started regularly scanning all the Internet-facing systems of CII operators to identify potential entry points for attackers such as unpatched software or weak configurations, so CII operators can fix them before they are exploited.
“It is akin to walking along the common corridor of your HDB flat to see whether your doors and windows are open. We don’t do any active probing, it’s just an external scan to what are the open points of entry,” said Fong.
The moves build on previously-announced efforts to strengthen Singapore’s cyber defences, including rolling out proprietary threat detection tools developed by a technical agency under the Ministry of Defence to all CII operators, and sharing classified threat intelligence with them.
CSA is also looking to tighten the security of supply chains tied to CII operators , as an attack on a vendor could compromise the data or disrupt services down the chain.
“There is a huge swathe of businesses that fall outside the sectors regulated under the Cybersecurity Act, but they are still part of the wider ecosystem we need to secure,” said Fong.
She said that CSA is looking to require some CII operators’ vendors and suppliers to obtain the Cyber Essentials or Cyber Trust mark certifications, potentially as early as 2027.
Launched in March 2022, the two certifications are currently voluntary. Cyber Essentials sets out the baseline cyber security measures for organisations, while the Cyber Trust mark provides five tiers of certification based on the risk profile of organisations and their size .
“It’s not satisfactory just to have it purely voluntary because uptake is extremely slow,” said Fong.
As of August 2026, only 874 Cyber Essentials and 346 Cyber Trust mark certifications were issued.
Fong said these moves come as cyber security evolves from a largely technical concern into a strategic discipline with implications for national security, the digital economy and public trust.
She attributed the shift to three developments: the use of cyber operations as an instrument of strategic competition, the growing influence of geopolitics over access to technologies such as advanced chips and frontier AI models, and society’s increasing reliance on digital infrastructure.
Suspected APT activity in Singapore quadrupled between 2021 and 2024, according to CSA’s Singapore Cyber Landscape 2024 report. Fong expects the upward trend to continue as attackers gain access to AI tools.
At the same time, disruptions to digital systems now have wider consequences because they underpin almost every aspect of work and daily life, she said.
“These have fundamentally changed the nature of cyber security,” said Fong. “It is a much more strategic discipline, and it is fundamentally about protecting trust in our digital infrastructure.”
AI/artificial intelligence
Artificial Intelligence
7月1日,方格文接任新加坡网络安全局首席执行官兼网络安全专员。
圣路易斯邮报摄影:JASON KUAH
发布于 2026 年 9 月 27 日上午 5:00
更新于2026年9月27日上午5:00
新加坡——在扩大网络安全工作的基础上,当地政府开发并部署了内部人工智能工具,以更好地保护约 2000 个政府系统。
这种积极主动的姿态——从外围防御转向主动威胁搜寻——是在国家支持的网络间谍组织 UNC3886 对该国四大电信公司发动攻击之后出现的。
该攻击事件于 2025 年 7 月首次公开。如果攻击者进一步渗透,可能会扰乱电信和互联网服务,并威胁国家安全。
在2026年7月接任新加坡网络安全局(CSA)首席执行官以来的首次采访中,方格文达告诉《海峡时报》,此次事件的关键教训之一是,防御措施需要超越阻止攻击者入侵。
这是因为像 UNC3886 这样的高级持续性威胁组织 (APT) 会针对特定目标。
“APT攻击是由国家支持的目标驱动的,而你们就是他们的目标,”方说,并补充说,仅仅关注威胁预防是不够的。
现在,我们必须假设攻击者已经进入运营商的网络,并集中精力在他们造成进一步破坏之前将他们抓捕归案。
“你还必须假设,资源最充足、技术最精湛的攻击者总有一天会找到入侵的途径,”方在9月3日接受《海峡时报》采访时补充道。
然而,一旦进入网络,攻击者仍然需要在网络中移动以寻找敏感系统和数据,这给了防御者通过异常活动发现他们的机会。
“你需要监控内部流量,你需要检测异常流量行为,你需要不断地进行威胁狩猎,”方说道。
由新加坡政府科技局(GovTech)开发的新型人工智能工具可以承担部分此类工作。
一款人工智能工具可对约2000个政府系统进行自动化渗透测试,其中一些系统包含公民数据和交易信息。自动化渗透测试利用软件模拟网络攻击,识别黑客可能利用的漏洞。
第二款人工智能工具会扫描政府应用程序和系统的源代码,查找安全漏洞,使各机构能够在黑客利用漏洞之前将其堵上。
CSA和GovTech并未透露哪些机构已部署了人工智能工具。此外,他们还计划将这些工具的应用扩展到其他关键信息基础设施(CII)领域。
新加坡的 11 个核心行业包括:政府、航空、医疗保健、陆路运输、海事、媒体、安全和应急服务、水务、银行和金融、能源以及信息通信。
CSA 和 GovTech 表示:“这项工作仍处于评估阶段,需要考虑运营要求、有效性和特定行业的需求”,但拒绝提供细节。
在 UNC3886 之后,CSA 也开始定期扫描 CII 运营商所有面向互联网的系统,以识别攻击者的潜在入口点,例如未打补丁的软件或薄弱的配置,以便 CII 运营商可以在这些漏洞被利用之前进行修复。
方先生说:“这就像沿着组屋的公共走廊走一圈,看看门窗是否开着。我们不会进行任何主动探测,只是对外部进行扫描,看看有哪些入口是敞开的。”
这些举措建立在之前宣布的加强新加坡网络防御的努力之上,包括向所有关键信息基础设施运营商推广国防部下属技术机构开发的专有威胁检测工具,并与他们共享机密威胁情报。
CSA 还希望加强与 CII 运营商相关的供应链的安全性,因为对供应商的攻击可能会危及数据或扰乱下游的服务。
方表示:“虽然有大量企业不属于《网络安全法》监管的行业范围,但它们仍然是我们需要保护的更广泛生态系统的一部分。”
她表示,CSA 正在考虑要求一些关键信息基础设施运营商的供应商获得网络安全基础认证或网络安全信任标志认证,最早可能在 2027 年实现。
这两项认证于 2022 年 3 月推出,目前均为自愿性质。“网络安全基础认证”(Cyber Essentials)规定了组织机构网络安全的基本措施,而“网络安全信任认证”(Cyber Trust)则根据组织机构的风险状况和规模提供五个级别的认证。
方先生说:“仅仅依靠自愿参与是不够的,因为参与速度非常慢。”
截至 2026 年 8 月,仅颁发了 874 项网络安全基础认证和 346 项网络安全信任标志认证。
方表示,随着网络安全从主要技术性问题演变为对国家安全、数字经济和公众信任具有重要意义的战略学科,这些举措应运而生。
她将这种转变归因于三个发展:将网络行动用作战略竞争的工具;地缘政治对获取先进芯片和前沿人工智能模型等技术的影响力日益增强;以及社会对数字基础设施的依赖性不断提高。
根据新加坡网络安全局 (CSA) 发布的《2024 年新加坡网络安全形势报告》,2021 年至 2024 年间,新加坡疑似高级持续性威胁 (APT) 活动增加了三倍。Fong 预计,随着攻击者获得人工智能工具的使用权,这一上升趋势还将继续。
她表示,与此同时,数字系统的中断现在会产生更广泛的影响,因为它们几乎支撑着工作和日常生活的方方面面。
方表示:“这些措施从根本上改变了网络安全的性质。它现在是一门更具战略性的学科,其根本在于保护人们对我们数字基础设施的信任。”
人工智能
人工智能