If you read only the headline from CSA’s latest national report, you might conclude Singapore had a quieter year. Phishing reports fell by about a fifth in 2025. Look one line down and the picture inverts: the number of infected systems detected in Singapore rose 142%, to 284,300. The attack did not stop. It moved to ground where nobody was watching, and where nobody files a report.
That gap between what gets reported and what actually happens is the most useful thing in the Singapore Cyber Landscape 2025/2026, published by the Cyber Security Agency of Singapore on 30 June 2026. This article walks through what the report measured, why the two headline numbers point in opposite directions, and what a Singapore business should reasonably do about it.
If you would rather work through it with someone, CFCI runs cybersecurity awareness training for Singapore organisations built for non-technical teams. No obligation, and the rest of this article is useful whether or not you ever speak to us.
What Does CSA’s Singapore Cyber Landscape 2025/2026 Actually Say?
The Singapore Cyber Landscape 2025/2026 is CSA’s annual review of cyber threat activity observed in Singapore, and the 2025 data it reports contains one clear reversal and one clear escalation. Phishing reports to CSA fell to about 4,800, roughly 21% down on the year before. Detected infected infrastructure rose to 284,300, up 142%. Ransomware cases edged up from 159 to 165, as set out in CSA’s accompanying release on the report.
Those three lines are worth keeping somewhere you will see them again, because they are the numbers a board or a management committee will ask you about.
| What CSA measured in 2025 | Figure | Change on 2024 | What it actually tells you |
|---|---|---|---|
| Phishing reports received by CSA | About 4,800 | Down about 21% | How much phishing was noticed and reported, not how much was sent |
| Infected infrastructure detected in Singapore | 284,300 | Up 142% | How many systems were already compromised and working for someone else |
| Ransomware cases reported | 165 | Up from 159 | Roughly flat in volume, with SMEs bearing more of it than their size suggests |
The reason to separate the measure from the meaning is that two of these numbers describe human behaviour and one describes machine reality. Reports depend on somebody noticing. Infections are counted whether anyone noticed or not.
Why Did Phishing Reports Fall While Infections Rose 142%?
A fall in phishing reports is not evidence of a fall in phishing. Reports are a measure of visibility: an email has to be received, recognised as suspicious, and then reported by someone willing to spend two minutes on the form. Any of those three links can weaken without a single attacker sending fewer messages.
Two mundane explanations fit the data better than a genuine retreat. Mail filtering has improved, so more phishing is quarantined before a human ever sees it and therefore never gets reported. And reporting fatigue is real in organisations where nothing visible happens after a staff member submits a report.
Some of that friction is fixable at almost no cost. Singapore’s government-run ScamShield service lets anyone check a suspicious message or number in minutes, or call the 1799 helpline, without waiting on an internal process at all. Pointing staff at it directly, rather than assuming they already know it exists, is one of the cheaper ways to close the visibility gap this section is about.
Set against a 142% rise in infected systems, the cautious reading is that attacks became less visible rather than less frequent. CSA attributes that infection rise to persistent malicious infrastructure activity, improved detection of infected botnet devices, wider use of Malware-as-a-Service operations, and the spread of consumer-grade Internet of Things devices running unpatched firmware or default passwords.
That distinction matters practically. If you had used reported phishing volume as your internal risk indicator during 2025, your dashboard would have shown improvement in the same year your exposure grew.
Why Are Singapore SMEs Hit Hardest by Ransomware?
Ransomware volume barely moved in 2025, rising from 159 to 165 reported cases, but the distribution is the story. CSA states that small and medium enterprises continued to be disproportionately affected, attributing this to comparatively lower cybersecurity maturity and limited resources.
That phrasing is worth sitting with, because it does not describe carelessness. It describes an SME where one person handles IT alongside three other jobs, where the firewall was configured by a contractor who has since moved on, and where nobody owns the question of which devices are still receiving security updates.
Malware-as-a-Service is what turns that gap into a business model. When attack tooling is rented rather than written, the skill required to run a campaign collapses, and the economics stop favouring only large, lucrative targets. A smaller organisation with weak perimeter hygiene becomes worth attacking simply because attacking it is nearly free.
If you want the financial shape of that risk, we have set it out separately in our breakdown of what a data breach costs a Singapore SME, and the mechanics of the rental model in our explainer on ransomware as a service.
What Does AI Change About the Threat Your Team Faces?
CSA’s report notes that threat actors are increasingly harnessing artificial intelligence to conduct attacks at greater speed, scale and sophistication, and flags agentic AI, meaning systems that carry out multi-step tasks on their own, as an emerging concern for how attacks are automated.
For a Singapore business, the near-term consequence is narrower than the headlines suggest. AI does not give attackers a new way in. It removes the friction from the ways in that already work. The badly worded email with the odd greeting was never the real defence; it was a bug in the attacker’s process, and it has now largely been fixed.
This is why advice built on spotting mistakes ages badly. Training that teaches staff to look for poor grammar or a strange sender name trains them to detect a symptom that is disappearing. Training that teaches a verification habit, such as confirming any payment or credential request through a separate channel the sender did not choose, survives the change, because it does not depend on the message looking wrong.
We go deeper into what changes and what does not in our guides to phishing and employee training in Singapore and deepfake CEO fraud and payment verification.
What Should Your Business Actually Do in the Next 90 Days?
The response the data supports is not a new platform or a larger budget. It is basic asset hygiene applied to the specific weaknesses CSA named: unpatched firmware, default passwords, unmanaged internet-facing devices, and staff who have no fast way to report something odd.
- 1
Find out what you actually have Weeks 1 to 2
List every device in the business with an internet connection, including routers, network video recorders, printers, smart displays and anything a contractor installed. Note who owns each one and whether it still receives firmware updates. Most organisations find something on this list they had forgotten about.
- 2
Close the two cheapest gaps Weeks 3 to 6
Replace every default and shared password, and apply outstanding firmware updates across the inventory. Switch on multi-factor authentication for email, remote access and any administrative account. These directly address the drivers CSA identified behind the rise in infections.
- 3
Make reporting fast and consequence-free Weeks 7 to 10
Give staff one obvious way to report something suspicious, and acknowledge every report. A reporting culture is what converts an unnoticed compromise into a contained incident, and it collapses quickly if people feel reports go nowhere.
- 4
Write the plan down and test it Weeks 11 to 13
Produce a one-page incident response plan naming who decides, who calls whom, and what happens first. Then walk a team through a realistic scenario for an hour. The rehearsal is what makes the page useful at 7am on a bad morning.
None of this requires a security specialist on staff. It requires somebody to own the list and to be given the time to work through it, which is usually the harder of the two. If you want an external benchmark to work towards, the Cyber Essentials Mark (Singapore, CSA) is built around this same set of basics, and we compare it with the Cyber Trust mark in our guide to which CSA mark your business needs.
How Will You Know Whether Any of It Worked?
Measure behaviour and exposure, not report volume. The Singapore Cyber Landscape data is a useful warning against the obvious metric: reported phishing fell nationally in the same year compromise rose sharply, so a falling report count on its own tells you very little about whether you are safer.
Three indicators are more honest. Track the proportion of your inventory that is fully patched and no longer using default credentials, because that is exposure you can actually close. Track median time from a staff member seeing something suspicious to reporting it, because speed is what limits damage. And track how many reports you receive at all, treating a rise as a healthy sign that people trust the process rather than as a sign things are getting worse.
If a breach does happen, what you do in the first day matters more than any of it, and we have set that out step by step in our cyber incident response playbook for Singapore SMEs.
The Shift Worth Remembering
The Singapore Cyber Landscape 2025/2026 is not a story about a quieter year. It is a story about a threat that became harder to see: fewer reports filed, far more systems quietly compromised, ransomware concentrated on the organisations least equipped to absorb it, and AI steadily removing the tells that awareness training used to rely on.
The response is available to any organisation, regardless of budget. Know what you own, close the default gaps, make it easy for people to speak up, and write down what you will do when something goes wrong.
If you would like help building that last part with your team, CFCI delivers cybersecurity awareness training designed for non-technical staff across Singapore organisations, covering the verification habits and reporting behaviour this data argues for. It is a conversation with no obligation, and you are welcome to work through the 90-day plan above on your own first.
Frequently Asked Questions
What is the Singapore Cyber Landscape report?
The Singapore Cyber Landscape is an annual publication from the Cyber Security Agency of Singapore (CSA) that reviews the cyber threats observed in Singapore over the previous calendar year. The 2025/2026 edition was published on 30 June 2026 and covers activity during 2025, including phishing reports, infected infrastructure, ransomware cases and emerging AI-enabled attack techniques. It is a retrospective national picture rather than a live threat feed, so it is best used for planning rather than as breaking news.
Did phishing actually fall in Singapore in 2025?
Phishing reports made to CSA fell by about 21%, from roughly 6,100 in 2024 to roughly 4,800 in 2025, but that is a measure of reporting rather than of attacker activity. A report only exists when somebody notices something suspicious and takes the trouble to submit it, so a fall can reflect reporting fatigue or better inbox filtering as easily as fewer attempts. Read alongside the 142% rise in infected infrastructure, the more cautious reading is that phishing became less visible, not less common.
Why did infected infrastructure in Singapore rise 142%?
CSA detected 284,300 infected systems in Singapore during 2025, up 142% on the previous year. The report attributes the rise to persistent malicious infrastructure activity, better detection of infected botnet devices, the growing use of Malware-as-a-Service operations that lower the skill needed to run an attack, and the spread of consumer-grade Internet of Things devices shipped with unpatched firmware or default passwords. Much of that expanded attack surface sits on devices nobody thinks of as computers.
What should a Singapore SME do first in response to the report?
Start with an inventory of everything in your business that connects to the internet, including routers, network video recorders, printers, smart displays and any device installed by a contractor. Change every default password, apply outstanding firmware updates, and switch on multi-factor authentication for email and remote access. These four steps address the specific weaknesses CSA names, cost little beyond time, and are the foundation the CSA Cyber Essentials Mark (Singapore, CSA) is built on.