EXECUTIVE SUMMARY COMMON CYBER THREATS IN SINGAPORE Examples of Phishing Scams: Prevalent cyber threats observed in Singapore’s cyberspace² in 2016 were defacements, phishing, ransomware, and compromised Command & Control (C&C) Servers, the last being potential launch-pads for other cyber-attacks, such as DDoS. A snapshot of these common cyber threats is as follows: Ransomware: Defacements: C&C Servers & DDoS: Phishing: It is one of the biggest cybersecurity threats to businesses and individuals today. Some reports noted that there may be as many as 550 ransomware-related attacks every day in Singapore. However, many cases may go unreported. Some people may decide to reformat their affected computer, and companies may not want to report it to protect their corporate reputation. CSA received 19 reports of ransomware cases from individuals and SMEs in 2016. Cerber, CryptoLocker and Locky were among the types of ransomware reported. As ransomware attacks grew in 2016, SingCERT issued an advisory in May 2016 to warn the public of such dangers and provided precautionary measures to be adopted. Nearly 1,800 website defacements were detected in Singapore in 2016, with the majority being websites of SMEs from a range of businesses such as interior design and manufacturing. The perpetrators included hacktivists keen to promote a certain ideology, and whose attacks were observed across other countries as well. One in 10 defaced websites was hosted on servers running outdated operating systems, which may have resulted in them being vulnerable to such attacks. More than 60 C&C servers were detected. It is not immediately apparent who might have set them up, what they intended to do with these servers, and if any damage was done. Whenever a new C&C server is detected, SingCERT will inform the respective Web hosting providers to rectify the issue. Potentially, C&C servers could be used to control botnets – a network of compromised computers ¬– that in turn could be mobilised for DDoS attacks. The thousands of IoT devices marshalled for DDoS attacks in the USA in October 2016 may hint of similar threats to come. DDoS ransom threats were also observed in Singapore’s cyberspace, believed to be carried out by cyber criminal groups. More than 2,500 phishing URLs were detected in 2016, with the Banking & Finance sector appearing to be the most spoofed (31 per cent of all observed phishing URLs). Among online services, PayPal was spoofed most often in phishing campaigns. CSA also observed that filehosting service providers were popular targets as hackers could easily harvest user credentials from there. Some Government institutions were also spoofed, as attackers sought personal data such as passport numbers that could be traded in underground markets. “Singapore cyberspace” refers to websites ending with the .SG domain or mention Singapore in its URL, IP addresses used in Singapore or Internet Service Providers (ISP) that are located in Singapore. 2 6 Phishing Site Phishing E-mail KEEPING OUR CYBERSPACE SAFE AND TRUSTWORTHY TOGETHER A conducive environment for monitoring, early detection, and quick response to cyber threats and attacks also requires effort in these areas: Raising Cyber Awareness Developing Cybersecurity Professionals Regional and International Exchanges Our outreach programmes and roadshows aim to promote cyber-savviness among businesses and individuals. SingCERT has issued advisories to educate the public on cyber issues such as ransomware, DDoS attacks and compromised remote servers. Singapore is also growing its cybersecurity ecosystem, which includes boosting the talent pool. The Cyber Security Associates and Technologists (CSAT) programme, a joint initiative by CSA and the Infocomm Media Development Authority (IMDA), was launched in 2016 to train and upskill new and existing ICT and engineering professionals for cybersecurity roles. Singapore has been actively involved in the past year in various international platforms on cybersecurity, from multilateral discussions on cyber norms to bilateral co-operation and regional capacity-building programmes. 7

Select target paragraph3