Check Point Research: Ransomware Takes Over Singapore in 2025
Tested Incident Response Playbooks, Clear Escalation Paths, and Employees Who Know What to Do When Something Looks Off Will Be Critical in 2026

There is a troubling new statistic that every CISO in Singapore should have stuck on their wall. In 2025, ransomware accounted for 58% of all recorded cyber incidents in the country. That is not a majority—that is a dominance.The Singapore Cyber Threat Landscape 2025 report by Check Point Research, released just recently puts a hard number on what many in the industry have long suspected: that Singapore’s status as a global digital hub has made it a magnet for the most aggressive and sophisticated threat actors operating today. The findings are not just alarming—they are a wake-up call.
Not Your Average Hackers
A decade ago, the typical cyber attacker was a nuisance. Opportunistic, technically limited, and largely after low-hanging fruit. That is not the case anymore.
The Check Point report identifies groups like Qilin and Lynx as among the key players driving the ransomware surge in Singapore, deploying what the industry calls double-extortion tactics—first stealing sensitive data, then encrypting it, leaving victims with a lose-lose choice. In one particularly striking case, a local chemical manufacturer allegedly had 165 GB of sensitive data siphoned off by Qilin alone.
“Singapore’s status as a global digital hub makes it a primary target for both financially motivated criminals and strategic nation-state actors,” said Rebecca Law, Check Point’s Country Manager for Singapore. “The 2025 landscape shows that attackers are successfully bypassing traditional controls through impersonation and social engineering.”
Put simply: they are not breaking through the walls anymore. They are walking in through the front door.
The Government Is in the Crosshairs of Ransomware
If the ransomware numbers are striking, the DDoS data is no less sobering. Government sites bore the brunt of disruption campaigns in 2025, accounting for 44% of DDoS victims—the majority of them identifiable by their ‘gov.sg’ domains. Business services followed at 30%.
That sounds like a headline about government IT failures. It is not. It is a headline about the strategic intent of attackers who have identified public institutions as soft, high-visibility targets. Hacktivist collectives—among them HIME666 and NullSec Philippines—were largely behind these disruption campaigns, turning government web presence into a geopolitical battleground.
And where are the financial stakes highest? Retail. Despite being the second most targeted sector overall at 17%, retail led the pack in actual data breaches, accounting for 42% of all breach incidents in 2025. Business services, meanwhile, remained the most targeted sector broadly, with 32% of incidents—a reflection of Singapore’s deep integration into global financial and data flows.
The New Threat No Firewall Can Stop
Here is where it gets genuinely unsettling.
Imagine an organisation that has invested heavily in firewalls, endpoint protection, and network monitoring. Its perimeter is solid. Its patches are current. And yet, an employee receives a video message—apparently from the CEO—instructing them to approve an urgent wire transfer. The face is real. The voice is real. The CEO never sent it.
That is the threat that Check Point is flagging for 2026: AI-generated materials and deepfake-enabled scams moving into the mainstream. Unlike ransomware, which targets systems, this threat targets people—exploiting human trust rather than technical vulnerabilities. It is the difference between picking a lock and convincing someone to hand you the key.
“As we move into 2026, organisations must assume that trust, not just systems, will be exploited,” Law noted.
Prevention Alone Will Not Save You
The report’s outlook for 2026 makes one thing abundantly clear: the organisations that will weather what is coming are not necessarily those with the biggest security budgets. They are the ones that have done the unglamorous work—tested incident response playbooks, clear escalation paths, and employees who know what to do when something looks off.
Check Point puts it plainly: organisations that focus solely on traditional prevention will struggle, whether with ransomware, DDoS, or any other cyber threat. What is needed now is resilience—the ability to absorb a hit, verify a threat, and respond in a coordinated way, even when the attack looks like it came from inside the house.
That is a harder sell than a new firewall. But given what 2025 just served up, it may be the only one worth making.



