Blog | ThreatBook

APAC's Cyber Threat Landscape: Inside the 2026 Mid-Year Data

Written by ThreatBook Research Team | 20 July 2026, 11:07 PM

ThreatBook Labs recorded 15,205 security incidents across Asia-Pacific between June 2025 and June 2026. Read one at a time, they look like an ordinary run of bad quarters. Read together, they show something an ordinary bad quarter never does: the region's risk did not spike, it shifted.

Structural is the word that matters. A spike passes, and your numbers settle back to where they were. A structural change moves the baseline underneath you, and every alert your team triages for the next year is measured against the new floor. For a security leader in Singapore or Hong Kong, two markets wired into the region's data and capital flows, that floor moved further than the raw incident count admits.

Here is what the data says, and where the regional pattern breaks.

Four incident types now carry the region

Four categories account for most of what was recorded. Each one is a familiar name. Together they are not doing familiar things.

  • Data breaches: 39.91%. Nearly 40% of everything recorded, and the dominant risk form. 80% came from active system intrusion rather than misconfiguration, and 51% of breach incidents also involved ransomware.
  • Ransomware: 18.33%. Law enforcement kept the pressure on the major operators, and volume still climbed. More than 120 new ransomware brands emerged and victim counts rose 58% year over year. Dual extortion, stealing the data and encrypting it in one operation, is now the default.
  • Phishing: 18.30%. AI-generated phishing made up 80% of detected volume, with click rates above 50%. It no longer arrives only by email. It arrives by SMS, QR code, messaging app and OAuth prompt.
  • Advanced persistent threat (APT) activity: 17.87%. Some state-linked actors have moved past collecting intelligence and started pre-positioning inside communications backbones and critical infrastructure.

These four do not sit in separate lanes. Phishing opens the door. Intrusion takes the room. Stolen data then feeds the ransom, the fraud and the next intrusion. Treat any one of them as a standalone problem and you will misread how the whole chain actually moves.

Where the attacks land, and where rank misleads

By target, the volume clusters at the top. China, India, Australia, Japan and South Korea absorb 61.78% of all incidents between them, for the reasons large digital economies always draw fire: economic scale, dense digital assets, industrial-intelligence value and geopolitical exposure.

While the headline ranks put Singapore sixth (4.49%) and Hong Kong 14th (1.53%), the ranking is the wrong instrument for either. Rank counts how often something was recorded. Rank does not count what a single intrusion is worth. In a hub economy those two numbers pull apart, and both Singapore and Hong Kong are hubs.

Singapore: hub economics turn one breach into many

Singapore reads exactly like the regional business and financial center it is. Attackers go after the multinational headquarters and the data and money those headquarters move. A breach inside a regional HQ rarely stays inside it. One intrusion reaches customers, contracts and employee identities in every market that office touches.

The attack mix confirms the profile. Data breaches lead at 49.9% of local incidents and ransomware follows at 33.1%, but the number to watch is APT activity at 22.4%, running nearly 1.4× the Asia-Pacific country average. That premium is the tell. Singapore's financial services sector carries the densest threat mix in the whole report, with data breach involvement at 71% and phishing at 40%, both the highest of any industry.

What makes that APT number matter is not its size but its craft. The techniques logged against Singapore are genuinely new:

  • Fake recruiters and trusted-service impersonation. Operators pose as recruiters, developers, financiers and legal counsel, then open targeted phishing on fintech staff and blockchain engineers.
  • Stolen IT-worker identities. Forged and stolen identities let operators pass as local IT talent, using remote-interview and remote-work arrangements to get a person inside the enterprise before a single vulnerability is touched.
  • AI-deepfake video conferencing. Executives are impersonated almost perfectly on live calls, a technique the report ties to North Korea-linked BlueNoroff activity against crypto and fintech decision-makers.

Read those three together and the pattern is plain. Singapore's APT threat goes after identity and trust, not the perimeter. The control that pays off here is the one watching who is already inside, not only what is knocking at the edge.

Hong Kong: the market where espionage outweighs extortion

Hong Kong breaks the pattern outright. Where every other priority market is led or pressed by ransomware, Hong Kong is led by espionage: APT activity accounts for 37.6% of local incidents and ransomware for just 16.2%, less than half the five-country composite. Data breaches sit on top at 58.6%, the highest share of any market in the report.

The goal here is long-term espionage and IP theft, not a payout. Roughly 60% of Hong Kong's APT activity targets commercial entities rather than government, the reverse of the global norm and a direct read on Hong Kong's role as a cross-border commercial hub. Once the data is out, it is reused for cross-border fraud, precision phishing, fund theft and pre-positioning inside critical-infrastructure networks.

Dwell time is where that intent stops being abstract. The report tracks one APT operator, Earth Bluecrow, holding kernel-level persistence on Linux for an average of 8.7 months, roughly twice the global average, with almost no alerts along the way. Even the ransomware behaves differently. The leading operators increasingly steal and publish data rather than lock it, because against an IP-heavy target a design file on a dark-web market outlasts any server you can restore from backup.

Hong Kong is also where hub economics compound. One compromised Hong Kong headquarters can open lateral access to eight to 12 subsidiary networks across Asia-Pacific. The 14th-place ranking describes how often. It says nothing about how far.

Beyond the hubs: three markets, three different pressures

The report goes deep on three more markets, and none of them wears the same threat as another. What forces a payment in one is not what forces a payment in the next. That difference is the whole point, and Indonesia shows it most sharply.

Indonesia is the fastest-deteriorating of the five priority markets, with attack activity growing 35.0% year over year in 2026. The within-country mix runs data breach 49.4%, ransomware 26.2%, phishing 22.4% and APT activity 15.0%, and government is the single most-targeted sector at 35.1%. The number that should hold your attention is the growth rate, because a market moving that fast has already outrun last year's control set.

The signature Indonesian attack is a mobile identity-fraud chain, and it runs on habit rather than on a vulnerability. A forged government notice, a tax reminder or a WhatsApp message arrives, the user sideloads a malicious APK, and a banking Trojan goes to work: intercepting one-time passcodes over SMS, then taking the account over. Nothing in that chain exploits a CVE. It exploits the fact that people are used to doing everything on their phones.

Ransomware in Indonesia leans on operational disruption, not on disclosure. Manufacturing, mining, energy, aviation and agriculture take the brunt of it, because a stopped production line or a grounded fleet bleeds money by the hour and shrinks the room a victim has to negotiate. Dual extortion has stabilized here too, with 63.8% of ransomware incidents also exfiltrating data. The leverage is downtime first and exposure second.

Australia inverts that model. It ranks third in the region at 11.84% of all attacks and carries the heaviest ransomware pressure of the five priority markets, but the squeeze arrives through compliance and reputation rather than downtime. Amended breach-notification laws handed attackers a second lever: report the victim to the regulator, or let the exposure become the headline. Where Indonesia's ransom pressure is counted in idle machines, Australia's is counted in disclosure duties and brand damage.

Malaysia closes the set as a second-tier market, tenth in the region at 2.91%, with the familiar Southeast Asian gap at its core: digitalization has outpaced the security investment meant to keep up with it. The attack surface grew faster than the controls did. That sentence describes more of the region than Malaysia alone.

What defenders should take from this

The regional read and the market reads land on the same operating truth. The attacks are chaining across categories, moving toward identity and data instead of pure disruption, and paying off well past the place they first touch down. Prioritizing by volume, weighting your defenses toward wherever the most alerts fire, walks you straight past the intrusions that matter most in a hub.

That gap is where APAC-native visibility earns its keep. ThreatBook has tracked Asian threat actors with firsthand collection since 2015, more than 200 APT groups among them, which is what lets this report separate a loud commercial ransomware market from a quiet, high-consequence espionage one. As Chase LI, Co-founder and Managing Director for International Business, puts it, only with "a 360-degree view of the region's attack landscape can organizations implement the necessary security measures to shield them from today's threats."

The full 2026 Mid-Year Asia-Pacific Threat Landscape Report runs to 48 pages, with country analyses for Australia, Singapore, Indonesia, Malaysia and Hong Kong covering attack composition, industry targeting, active ransomware groups and the APT threats specific to each market. The regional numbers set the floor. The country chapters tell you where you are standing on it.

Read the full report. Download the 2026 Mid-Year Asia-Pacific Threat Landscape Report.