Disclosures by Singapore authorities earlier this year that four major telecom operators were targeted by attackers should resonate across the telecom industry. Although there were no service disruptions and no confirmed theft of customer data, reports indicate that the attackers gained access to critical systems and technical network-related data.

This was not opportunistic cybercrime. It was a calculated attempt to map and understand Singapore’s core communications infrastructure. For telecom operators, that distinction matters. The objective was not the theft of individual customer data, but a deliberate attempt to probe and understand Singapore’s communications infrastructure.

For operators, this attack should be a reminder that telecom networks are not only important commercial assets. They are strategically important national infrastructure and are increasingly becoming targets for threat actors.

GettyImages-1276687348.jpg
– Getty

Why telecom networks attract advanced threat actors

Telecom operators sit at the center of a country’s digital ecosystem. Every digital communication, whether financial transactions, business calls and emails, personal data, and even the workings of government and the emergency services, all pass through a country’s telecoms infrastructure.

If a threat actor achieves deep access into an operator’s network, they could potentially monitor, manipulate, or even disrupt these data traffic flows at scale. The consequences could extend far beyond the operator itself, affecting individuals, businesses, and the functioning of government.

Potential impacts could include: interception of confidential business communications, exposure of intellectual property, financial market manipulation or blackmail, and government service disruption across healthcare, transport, and emergency response.

The strategic value of network intelligence

Advanced persistent threat (APT) groups, like the one responsible for the attack in Singapore, are increasingly targeting telecom operators for this reason. Control of a communications network gives a threat actor unparalleled visibility into how a country’s economy and society function.

In cybersecurity, architectural intelligence is often more strategically valuable than individual customer data. Understanding network layouts, system architecture, and security controls, such as firewalls, enables an attacker to identify structural weaknesses and plan future attacks that evade detection mechanisms.

The first attack may not cause immediate operational disruption; instead, it positions the threat actor for future attacks, making them faster and more effective. The Singapore incident illustrates this pattern clearly and has the hallmark of a long-horizon campaign.

Why prevention is the best response

Operators globally have experienced incidents involving breaches of core network systems in recent years. When core infrastructure is affected, remediation is neither simple nor quick. Recovery can involve extensive system audits, the replacement of compromised components, and even extensive system overhauls and re-architecture.

The financial and operational cost of such recovery can be substantial. More importantly, reputational impact and regulatory scrutiny can persist long after systems are restored. This is why prevention and resilience are more effective than responding once a compromise occurs.

Singapore authorities attributed the latest attack on their telcos to the APT group UNC3886. UNC3886-style attacks are stealthy, long-term, and infrastructure-focused.

For operators in other markets, this attack should be an urgent reminder to review their cybersecurity posture, strengthen network resilience, and ensure their defenses are ready for the evolving threat landscape. Defending against APT activity requires more than deploying the latest cybersecurity tools. It requires balanced investment in people, processes, and technology.

Strengthened cybersecurity posture

First, organizations must strengthen their cybersecurity teams and capabilities. Effective cyber defense requires analysts who deeply understand the network architecture they are protecting, and dedicated threat-hunting teams must proactively hunt for abnormal behavior rather than wait for alerts. Computer Security Incident Response Teams (CSIRTs) must be empowered, trained, and rehearsed to respond decisively under pressure, while strong internal access controls and monitoring should be used to reduce insider risk.

Second, robust processes are critical. Secure change management procedures and strict access controls help prevent security weaknesses from emerging, while clear zero-day response protocols ensure swift, coordinated action when a threat does occur. Threat hunting should follow a structured lifecycle rather than ad-hoc investigations, and infrastructure-specific incident response plans are essential, particularly for telecoms and critical national infrastructure operators.

Finally, the technology must be used to enable the cybersecurity teams and processes. Key areas telcos should invest in their cybersecurity technology include: centralized infrastructure logging, identity-centric security, network detection & response, integrity monitoring, behavioral analytics, and SOAR automation.

In the end, resilience against advanced persistent threats is not achieved through a single investment, but through disciplined execution across these three pillars. Telcos that treat cybersecurity as a strategic capability will be far better positioned to withstand the growing wave of infrastructure-focused attacks.