EXECUTIVE SUMMARY CYBER LANDSCAPE 2016 THE NATIONAL CYBER SECURITY COMMAND Actors Targeting Singapore Cybercrime Cyber threats can be carried out by a host of different cyberattackers, or threat actors as they are commonly known. The cyber community has long struggled with the challenge of definitively attributing the specific source of a cyber-attack or crime, as attackers can use a range of tools to cover or distort their tracks. Threat actors targeting Singapore run the gamut from scriptkiddies to Advanced Persistent Threats (APTs). Their behaviour, intentions, and capabilities are always evolving and require close watch. Globally, APTs are a growing concern as they are often undetectable in networks for long periods. APTs may refer to both the nature of the attack (persistent and sophisticated), and the attackers (well-organised and usually state-sponsored). APT groups generally target government institutions and large organisations for the purpose of espionage and other illegal acts. Under Singapore’s Cybersecurity Strategy launched in 2016, one key priority is to build a safer cyberspace for Singaporeans and businesses. The area of cybercrime comes under the responsibility of the Singapore Police Force (SPF). access patient data. However, the attacks did not disrupt Singapore’s healthcare system as the incidents were contained and no other systems were compromised. Technology (ICT) environment as it would enhance the security of the Government’s network from attacks originating from the Internet. The Government sector also continued to be targeted, facing attacks from website defacements to phishing. The Internet Surfing Separation (ISS) policy announced in June 2016 will go a significant way towards securing the Government’s Infocommunications Besides attacks targeting these critical sectors, NCSC also saw individuals and small and medium enterprises (SMEs) being victims of website defacements, business e-mail scams, phishing, and ransomware. In Singapore, 43 per cent of cybersecurity incidents reported by individuals and SMEs to the Singapore Computer Emergency Response Team (SingCERT)¹ were phishing attacks. One of the most common cyber threats SMEs reported to SingCERT was business e-mail scams. CRITICAL CYBER CONCERNS Globally, in 2016, IoT devices like Wi-Fi routers and webcams were hijacked to launch cyber-attacks, specifically DDoS attacks. This resulted in many websites and services being inaccessible. Ransomware was another significant type of cyber-attack that hit industries and individuals, locking them out of their systems. Singapore is certainly not immune to these cyber threats, which can be expected to evolve and emerge in bigger, bolder and faster ways. CSA is keeping a close watch on the cyber landscape and, in this publication, will provide an analysis of the cyber threats that Singapore faced between January and December 2016. The cyber-attacks and threats covered in this publication are just the tip of the iceberg. The absolute number of incidents will be hard to determine – despite best efforts, not all cases are reported or can be detected – but CSA’s observations could provide a baseline towards a further understanding of Singapore’s cyber threat landscape. In turn, that may illuminate more ways to better defend ourselves against similar or new threats. The Government will take the lead, and partner the industry, academia, public and people sectors, and international counterparts, to enhance cybersecurity for the nation, so that Singaporeans and Singapore can reap the long term benefits of having a safe and trustworthy cyberspace. At the frontline to monitor and respond to cyber threats in Singapore is CSA’s National Cyber Security Command (NCSC). It comprises the National Cyber Threat Monitoring Centre (NCTMC), National Cyber Incident Response Centre (NCIRC), and the National Cyber Threat Analysis Centre (NCTAC). The centres work closely together and with stakeholders to respond to cyber threats, research, and make sense of the cyber landscape to protect Singapore’s Critical Information Infrastructure (CII), and to enable a safer cyberspace for businesses and individuals. In 2016, NCSC saw cyber-attacks of varying nature and impact across many sectors, including the Government, Banking & Finance, and Healthcare sectors. For instance, the Healthcare sector was struck by ransomware attacks that left some individual healthcare practitioners unable to CMCA Cases The SPF noted an increase in the proportion of cybercrimes to overall crime cases from 7.9 per cent in 2014 to 13.7 per cent in 2016, underscoring the growing attractiveness of digital platforms for criminals. Cases reported under the Computer Misuse and Cybersecurity Act (CMCA) more than doubled year-on-year to 2016, with ransomware, and the compromise of online and banking accounts, constituting the top five categories in 2016. SingCERT is the focal point in Singapore for the public to report cybersecurity incidents and issues, and liaises with CERTs in other countries to better manage the borderless nature of cyber threats. Businesses and individuals could report incidents to SingCERT by dialling its hotline – (+65) 6323 5052 or e-mail to singcert@csa.gov.sg 1 4 5

Select target paragraph3