Telecoms networks must be ready to defend against cyberattacks

Communications networks are far more than just commercial assets; they are critical national infrastructure that must be protected

Summarise
    • In cybersecurity, information on a system's architecture is often more valuable than customer data.
    • In cybersecurity, information on a system's architecture is often more valuable than customer data. PHOTO: PIXABAY
    Published Thu, Feb 12, 2026 · 12:00 PM

    DISCLOSURES by the Singapore authorities on Monday (Feb 9) that four major telecom operators were targeted by cyberattackers in 2025 should serve as a wake-up call for the industry in South-east Asia.

    While there were no service disruptions or evidence that customer data was stolen, reports suggest that the attackers did gain access to some critical systems and technical network-related data.

    This was not a random cyber incident, and it was not aimed at stealing the personal data of customers. It was a deliberate attempt to probe and understand Singapore’s communications networks and systems, infrastructure that is critical to the functioning of its economy and society.

    For telecoms operators across the region, it is a reminder that communications networks are far more than just commercial assets. They are critical national infrastructure that are prime targets for cyberattack and which must be protected.

    Telco networks are prime targets

    Telecoms companies function as a network of highways for data and other forms of digital communication. Every digital interaction ultimately flows through telco networks, from financial transactions and business e-mails to personal conversations with friends and family and critically, calls to emergency services.

    Because of this, telcos represent foundational infrastructure that enables the functioning of our economies and societies. If a major telecoms operator were to be seriously compromised, a threat actor could potentially “listen in” to, or even manipulate, the data traffic handled by that network.

    With deep access to an operators’ network infrastructure, attackers could spy on businesses and intercept confidential communication. This type of confidential information could enable market manipulation, blackmail, or lead to the theft and sale of intellectual property.

    In more severe scenarios, attackers could disrupt communications services altogether, causing widespread network outages.

    Critical services would be particularly exposed. Transport, healthcare and emergency services all rely on timely, reliable communications to coordinate their operations.

    Disruption to emergency services could delay or prevent the handling of distress calls, while hampering the government’s ability to communicate with the public could spread confusion and panic. The impact of such outages was seen in Australia last year.

    Understanding the attacker

    The potential impact of a compromised telecoms operator extends far beyond the operator itself, and control of a network would give the attacker unparalleled visibility into how a country operates.

    This is why advanced persistent threat groups, such as the one responsible for the recent attack in Singapore, consistently target telcos.

    In cybersecurity, information on a system’s architecture is often more valuable than customer data. Knowing how a network is built is like knowing what locks, alarms and access points protect a house. It gives the attacker a clear target, enables them to plan future attacks and avoid the need to test multiple approaches.

    For example, if a cyberattacker obtains information about network layouts, system architecture or security controls such as firewalls, they can identify specific weaknesses, significantly increasing the speed and effectiveness of future attacks.

    Keeping the door locked

    Telcos in many countries have experienced serious cyber incidents in recent years, some involving deep breaches of core network systems.

    Such incidents have demonstrated how complex and costly recovery can be when core infrastructure is affected, often requiring extensive system overhauls and long-term remediation. They underline why prevention and resilience are far more effective than responding after the fact.

    Singapore’s decision to publicly attribute the attacks to a specific advanced persistent threat group, UNC3886, reflects the authorities’ ability to trace the source of the attacks and their confidence in the resilience of the nation’s cyberdefences.

    For telecoms operators across the region, this incident presents an opportunity to review their cybersecurity posture, strengthen network resilience and ensure their defences are ready for the evolving threat landscape.

    UNC3886-style attacks are stealthy, long-term and infrastructure-focused. They cannot be prevented by deploying cybersecurity tools alone.

    Effective defence requires balanced investment in skilled cybersecurity personnel who can identify warning signs; a disciplined security process that enables a fast and effective response, and robust technology that minimises weakness and security blind spots are also needed.

    Equally important is strong cooperation between private-sector telcos and relevant government agencies. Greater sharing of cyberthreat intelligence and operational insights can play a critical role in strengthening a country’s overall security posture and protecting what is critical national infrastructure.

    The recent attack on Singapore’s telecoms sector reminds us of what is at stake. For telecoms companies in South-east Asia, the lesson is clear: Protecting their networks is not just an operational or commercial imperative, it is one that sits at the heart of every country’s national resilience.

    The writer is president-director, ITSEC Asia