ESET: Phishing, Credential Abuse to Dominate Singapore’s 2026 Cyber Landscape
Risk Is Shifting Away From Headline-Grabbing Zero-Day Exploits and Towards Scalable Initial Access Tactics

ESET has released the findings of its latest study, and it is not looking too good for Singapore.
Singapore’s cybersecurity posture faced a serious test in 2025, when advanced persistent threat group UNC3886 launched a targeted campaign against the country’s four major telecommunications operators. Authorities confirmed that no sensitive data was exfiltrated, but the incident underscored a more pressing concern—sophisticated actors no longer need dramatic breaches to succeed. Persistent access and quiet exploitation are already enough.
That reality sets the tone for 2026.
According to ESET’s H2 2025 Threat Report, enterprise risk is shifting away from headline-grabbing zero-day exploits and toward scalable initial access tactics. In Singapore, HTML/Phishing.Agent alone accounted for 31.86% of all detected threats, reinforcing a familiar but dangerous truth: phishing and credential abuse remain the easiest—and most effective—entry points into corporate environments.
Phishing at scale, in particular, is becoming harder to ignore. It accounted for nearly one-third of detected threats in the second half of 2025, with most successful breaches beginning with socially engineered emails and malicious links. The scale of activity is striking. Rapid domain churn, including 159,010 detections linked to usrpubtrk[.]com, points to highly automated infrastructure designed to outpace traditional defences and increase the odds of success.
Once attackers gain access, the impact quickly escalates.
ESET Finds Compromised Credentials a Cause of Major Disruption
Compromised credentials are now a major driver of operational disruption. Infostealers such as Formbook (23.45%), MSIL/Spy.Agent (16.31%), and AgentTesla (13.51%) ranked among the most prevalent threats locally, with SnakeStealer also maintaining visibility across the region. These malware strains are built to capture keystrokes and stored credentials, giving attackers direct access to corporate systems. From there, the risks multiply—fraud, account takeovers, and lateral movement across networks.
The growing reliance on mobile devices for multi-factor authentication, banking, and enterprise SaaS platforms only adds another layer of vulnerability, amplifying both operational and financial risks.
Ransomware Remains Big Threat
Meanwhile, ransomware remains a persistent, if somewhat fragmented, threat. In 2025, 64 publicly reported ransomware incidents were linked to Singapore, with Qilin, Lynx, and Dire Wolf emerging as the top actors. Dire Wolf, in particular, stands out for its strong focus on Asian markets and its rising global profile.
The sectors most affected—construction, manufacturing, and IT/technology—mirror global trends. These industries are often targeted not for their data alone, but for their dependence on uptime and complex supply chains, making them more susceptible to opportunistic attacks following initial access.
“When we look at ESET’s H2 2025 threat data alongside real-world incidents like the UNC3886 campaign in Singapore, it’s evident that phishing, credential abuse, and automated attack infrastructure are central to current risk patterns,” said Parvinder Walia, President of the Asia Pacific Region at ESET.
“With cyber resilience now firmly embedded in Singapore’s national agenda, 2026 will be defined not just by response capabilities, but by how effectively business leaders build operational resilience.”
What Organisations Need to Do
To that end, ESET is urging enterprises to rethink their priorities. Strengthening delivery-layer defences—such as advanced email protection, attachment sandboxing, and real-time URL inspection—will be critical in stopping threats before credentials are compromised. At the same time, organisations must treat identity as the primary control plane, enforcing mandatory multi-factor authentication and conditional access across both corporate and mobile environments.
Finally, as attackers continue to scale through automation, businesses must respond in kind. Investments in behavioural analytics and extended detection and response (XDR) capabilities will be key to detecting threats early, reducing dwell time, and preventing attackers from establishing a foothold.
In 2026, the battleground is clear. The question is no longer whether organisations can respond to attacks, but whether they can prevent attackers from getting in at all.



