EXECUTIVE SUMMARY
CYBER
LANDSCAPE
2016
THE NATIONAL
CYBER SECURITY
COMMAND
Actors Targeting Singapore
Cybercrime
Cyber threats can be carried
out by a host of different cyberattackers, or threat actors as they
are commonly known. The cyber
community has long struggled
with the challenge of definitively
attributing the specific source
of a cyber-attack or crime, as
attackers can use a range of tools
to cover or distort their tracks.
Threat actors targeting Singapore
run the gamut from scriptkiddies to Advanced Persistent
Threats (APTs). Their behaviour,
intentions, and capabilities are
always evolving and require
close watch. Globally, APTs are
a growing concern as they are
often undetectable in networks
for long periods. APTs may refer
to both the nature of the attack
(persistent and sophisticated),
and the attackers (well-organised
and usually state-sponsored).
APT groups generally target
government institutions and large
organisations for the purpose of
espionage and other illegal acts.
Under Singapore’s Cybersecurity
Strategy launched in 2016, one
key priority is to build a safer
cyberspace for Singaporeans
and businesses. The area of
cybercrime comes under the
responsibility of the Singapore
Police Force (SPF).
access patient data. However, the
attacks did not disrupt Singapore’s
healthcare system as the incidents
were contained and no other
systems were compromised.
Technology (ICT) environment
as it would enhance the security
of the Government’s network
from attacks originating from
the Internet.
The Government sector also
continued to be targeted, facing
attacks from website defacements
to phishing. The Internet Surfing
Separation (ISS) policy announced
in June 2016 will go a significant
way towards securing the
Government’s Infocommunications
Besides attacks targeting these
critical sectors, NCSC also saw
individuals and small and medium
enterprises (SMEs) being victims
of website defacements, business
e-mail scams, phishing, and
ransomware. In Singapore,
43 per cent of cybersecurity
incidents reported by individuals
and SMEs to the Singapore
Computer Emergency Response
Team (SingCERT)¹ were phishing
attacks. One of the most
common cyber threats SMEs
reported to SingCERT was
business e-mail scams.
CRITICAL
CYBER
CONCERNS
Globally, in 2016, IoT devices like
Wi-Fi routers and webcams were
hijacked to launch cyber-attacks,
specifically DDoS attacks. This
resulted in many websites and
services being inaccessible.
Ransomware was another
significant type of cyber-attack
that hit industries and individuals,
locking them out of their systems.
Singapore is certainly not immune
to these cyber threats, which can
be expected to evolve and emerge
in bigger, bolder and faster ways.
CSA is keeping a close watch
on the cyber landscape and, in
this publication, will provide an
analysis of the cyber threats that
Singapore faced between January
and December 2016.
The cyber-attacks and threats
covered in this publication are
just the tip of the iceberg. The
absolute number of incidents
will be hard to determine – despite
best efforts, not all cases are
reported or can be detected – but
CSA’s observations could provide
a baseline towards a further
understanding of Singapore’s
cyber threat landscape. In turn,
that may illuminate more ways
to better defend ourselves against
similar or new threats. The
Government will take the lead, and
partner the industry, academia,
public and people sectors, and
international counterparts, to
enhance cybersecurity for the
nation, so that Singaporeans
and Singapore can reap the long
term benefits of having a safe and
trustworthy cyberspace.
At the frontline to monitor
and respond to cyber threats
in Singapore is CSA’s National
Cyber Security Command
(NCSC). It comprises the National
Cyber Threat Monitoring Centre
(NCTMC), National Cyber Incident
Response Centre (NCIRC), and the
National Cyber Threat Analysis
Centre (NCTAC). The centres
work closely together and with
stakeholders to respond to cyber
threats, research, and make sense
of the cyber landscape to protect
Singapore’s Critical Information
Infrastructure (CII), and to enable
a safer cyberspace for businesses
and individuals.
In 2016, NCSC saw cyber-attacks
of varying nature and impact
across many sectors, including
the Government, Banking &
Finance, and Healthcare sectors.
For instance, the Healthcare
sector was struck by ransomware
attacks that left some individual
healthcare practitioners unable to
CMCA Cases
The SPF noted an increase in
the proportion of cybercrimes to
overall crime cases from 7.9 per
cent in 2014 to 13.7 per cent in
2016, underscoring the growing
attractiveness of digital platforms
for criminals. Cases reported
under the Computer Misuse and
Cybersecurity Act (CMCA) more
than doubled year-on-year to
2016, with ransomware, and the
compromise of online and banking
accounts, constituting the top five
categories in 2016.
SingCERT is the focal point in Singapore for the public to report cybersecurity incidents and issues, and liaises with CERTs in other countries
to better manage the borderless nature of cyber threats. Businesses and individuals could report incidents to SingCERT by dialling its hotline –
(+65) 6323 5052 or e-mail to singcert@csa.gov.sg
1
4
5