Transcription
Tonight I would like to speak about a very serious matter, a particular category of cyber threats. They are known as advanced persistent threats, or APTs.
APTs are highly sophisticated and well-resourced actors. They typically act on state objectives. They steal sensitive information. They disrupt essential services. APT groups have been identified like Sandworm, Typhoons Cluster. They attack critical infrastructure like healthcare, telcos, water, transport, power.
One of the APT groups conducting such attacks is UNC 3886. The UNC label stands for uncategorized or unclassified. It simply means that industry analysts have not formally classified it. But that does not mean that it is any less of a threat. The industry has identified UNC 3886 as a highly sophisticated threat actor. It deploys advanced tools to compromise systems. It is also able to evade detection and maintain persistent access in victim networks. Industry has associated UNC 3886 with cyber attacks against critical areas including defense, telcos, technology organizations in the United States and in Asia.
The intent of this threat actor in attacking Singapore is quite clear. It is going after high-value strategic targets, vital infrastructure that deliver essential services. If it succeeds, it can conduct espionage and it can cause major disruption to Singapore and Singaporeans. UNC 3886 poses a serious threat to us and has the potential to undermine our national security.
Even as we speak, UNC 3886 is attacking our critical infrastructure right now. CSA and relevant agencies are actively dealing with this attack, and they are working with the relevant CIO owners. It is not in our security interest to disclose further details of this attack at this point in time, but I can say it is serious and it is ongoing and it has been identified to UNC 3886. We will assess whether it is in our interest to disclose more details later. I have also, in an annex to the speech, set out more details on UNC 3886.
The takeaway for all of us is that Singapore has been and Singapore continues to be under attack by APTs and foreign actors. They seriously threaten our national security. Let me explain with an illustration which really this audience doesn't need, but let me put it. Say there's a cyber attack on our power systems. They can disrupt our electricity supply, and the knock-on implications are other essential services like water supply, transport, medical services. In fact, everything that depends on power. Everything will be affected, and there are economic implications. Banks, airports, industries would not be able to operate. Our economy can be substantially impacted. And it's not just power systems. Attacks to our telco systems, payment systems can have very serious consequences.
Attacks on our systems and infrastructure will then impact on how we do business. Who will be our vendors and what sort of supply chains? All of that will have to be relooked at. And if we decide that we cannot trust them, then we may choose not to use them. And at the same time, trust and confidence in Singapore as a whole can also be affected. Businesses may shy away if they are unsure about our systems and whether the systems are clean, resilient, safe. We will act in Singapore's interests and defend Singapore's cyberspace.
I earlier shared about a global botnet. Upon discovery, Singapore participated in a global operation to disrupt it. This is just one example. There are many others. But we have to be realistic as well. We are up against very sophisticated actors, some backed by countries, countries with vast resources, unlimited, almost unlimited resources, both in manpower and in technology and frontline technology. They can deploy their resources at formidable scale. And even countries at the frontier of technology have not been able to prevent APT attacks on their systems. So realistically, we will have to accept that some attacks, at least, will get through.
And in the face of such threats, we have to continue to strengthen Singapore's cyber defenses, focus on not just preventing the attacks, or preventing the successful attacks, but also containing the threat when the attacker manages to penetrate the system. CSA and other security agencies have been coordinated and united in national cyber defense. They are on constant alert, working hard together to detect, contain cyber threats, and defend our systems. CSA will continue to work with partners like critical information infrastructure owners to strengthen the protection of our critical infrastructure. We will continue to look at improving our crisis response capabilities and readiness. Cyber security exercises like Exercise Cyberstar help. We will also update our Cyber Security Act to give more powers to deal with the threats.
Beyond owners of CII, CSA will continue to build up our digital ecosystems, help companies raise their cybersecurity posture. And on the international stage, Singapore will continue to do our part to preserve a secure and rules-based cyberspace. We recently concluded our chairing of the second UN Open-Ended Working Group on security of and in the use of ICTs. The Singapore International Cyber Week is also an important platform for governments and industry players from around the world to come together, have important conversations, and deepen partnerships on cybersecurity.