Report: Cyber Threats Surge in 2024 as Singapore Strengthens Digital Defenses

September 5, 2025

Over the past ten years, Singapore has positioned itself as a regional leader in cybersecurity policy, innovation, and capacity building.
A general view from Changi Airport as passengers gather and wait due to the global communications outage caused by CrowdStrike, which provides cyber security services to US technology company Microsoft, on July 19, 2024 in Singapore. Photo by Anadolu Images.

Singapore’s cybersecurity authorities reported a sharp rise in cyber threats in 2024, with ransomware, outdated infrastructure vulnerabilities, and state-linked cyberattacks dominating the digital landscape. The findings were published on September 3 in the Singapore Cyber Landscape (SCL) 2024/2025, an annual report that not only reviews the previous year’s cybersecurity situation but also commemorates a decade of progress since the establishment of the Cyber Security Agency of Singapore (CSA) in 2015.

The report paints a picture of a small but digitally advanced nation grappling with the challenges of rapid digitalization while seeking to build a safer, more resilient cyberspace. Over the past ten years, Singapore has positioned itself as a regional leader in cybersecurity policy, innovation, and capacity building — but 2024 served as a reminder of the evolving and persistent threats that continue to test its defenses.

“The cyber threat landscape is becoming increasingly complex. Threat actors are not only more numerous but also more sophisticated, often state-linked and well-funded,” said a CSA spokesperson. “Singapore cannot afford complacency. Our focus must remain on building resilience, fostering public-private collaboration, and staying one step ahead of malicious actors.”

Rise of ransomware and legacy malware exploitation

One of the most concerning findings in the 2024 report was the marked increase in ransomware incidents and the exploitation of unpatched, legacy systems. Many attacks in 2024 were carried out using older malware strains, some of which had been identified and patched years ago.

This suggests a continuing challenge in promoting basic cyber hygiene practices among individuals, businesses, and even certain critical sectors. Despite heightened awareness campaigns, many organizations failed to update their software or implement layered security measures, leaving themselves open to ransomware schemes that encrypted data and demanded payments, often in cryptocurrency.

“Ransomware remains a lucrative business model for cybercriminals because it exploits the weakest links — outdated systems and poor patching practices,” the report noted.

Advanced persistent threats targeting strategic sectors

Beyond ransomware, Singapore faced continued targeting by Advanced Persistent Threat (APT) groups, which conduct stealthy, prolonged operations to compromise high-value networks. One such group highlighted in the report, UNC3886, has been actively focusing on strategic sectors, including Critical Information Infrastructure (CII), which encompasses energy, transport, and financial services.

APT activity in 2024 demonstrated increasing scale, sophistication, and persistence, aligning with global trends of cyber operations linked to geopolitical tensions. Singapore’s position as a major financial hub and technology innovator makes it an attractive target for cyber espionage and disruption campaigns.

CSA’s 10-year milestone

This edition of the SCL is particularly significant as it marks the 10th anniversary of the Cyber Security Agency of Singapore. Since its inception in 2015, CSA has overseen major national initiatives, from setting up sector-specific resilience frameworks to building a talent pipeline in cybersecurity.

To commemorate this milestone, the report includes Founders’ Stories — first-hand accounts from early CSA leaders detailing the agency’s formative years, the lessons learned from early cyber incidents, and how Singapore’s strategy evolved from reactive measures to a proactive, globally connected approach.

Over the past decade, CSA has also strengthened Singapore’s role in international cyber diplomacy, forming strategic alliances and participating in global threat intelligence sharing initiatives to counter transnational cybercrime.

Protecting critical systems and the public

In response to the challenges of 2024, CSA introduced several initiatives aimed at bolstering national cybersecurity. Among them:

  • Enhanced regulatory requirements for CII operators, mandating more frequent risk assessments and the adoption of zero-trust security models.
  • Expanded public education campaigns, encouraging citizens and small businesses to adopt stronger passwords, enable multi-factor authentication, and keep devices updated.
  • Collaboration with international law enforcement and cybersecurity partners to disrupt cross-border ransomware operations.

Support schemes for small and medium-sized enterprises (SMEs), including grants and advisory services to help them implement baseline cybersecurity measures affordably.

Balancing rapid digitalization with security

The report situates these efforts within Singapore’s broader economic transformation, as the nation pushes ahead with smart city initiatives, artificial intelligence integration, and a highly connected digital economy. Each leap in digital innovation, however, comes with a wider attack surface.

CSA warned that while technological advancement is crucial for growth, security must remain a “non-negotiable foundation.” Failure to address vulnerabilities, the agency said, could have cascading effects not only on businesses but also on public trust and national stability.

A recurring theme in the SCL 2024/2025 is the importance of a whole-of-nation approach to cybersecurity. The report highlighted successful collaborations with private companies, community groups, and academic institutions in threat detection, response planning, and research.

“Cybersecurity is no longer just an IT problem — it is a national resilience challenge,” the report stated. “It requires everyone, from the largest enterprise to the individual user, to play their part.”

Outlook: A trusted, resilient, and vibrant cyberspace

Looking ahead to 2025 and beyond, CSA emphasized its goal of fostering a trusted and vibrant cyberspace that supports both economic opportunity and public safety. The agency will continue to invest in talent development, regulatory enhancements, and cross-border cooperation to counter emerging threats, including artificial intelligence-driven attacks and the weaponization of Internet-of-Things (IoT) devices.

“Together with our partners, stakeholders, and Singaporeans, we will continue to work towards a future where everyone can live and work online safely,” CSA said in its statement.

As Singapore enters its second decade of coordinated national cybersecurity efforts, the challenges remain steep — but so too does its ambition to remain one of the most secure and digitally advanced nations in the world.

(Source: CSA)

Politics Today is dedicated to publishing insightful analyses in order to understand the changing nature of contemporary politics. It aims to contribute to the sound and constructive discussion of international affairs.