5 min read

ThreatBook’s 2026 Mid-Year APAC Report Reveals a Structural Increase in Cybersecurity Risk in the Region

  • Security threats are fast-evolving and intrinsically linked to real-world developments
  • Risk in Asia-Pacific is concentrated in four main activity types: data breaches, ransomware, phishing, and APT activity
    • APT groups targeting Singapore have a dual mandate: direct revenue generation; and cyber espionage and sabotage
    • Unlike other APAC markets, Hong Kong experiences more APT attacks than ransomware incidents
    • China receives more attacks than any other market, while Russia and North Korea are the top perpetrators

Singapore and Hong Kong, 21 July 2026 — ThreatBook, the agentic security company, today released its inaugural “2026 Mid-Year Asia-Pacific Threat Landscape Report”, which draws on a detailed analysis of 15,205 security incidents (or attacks) that took place in over 19 markets (country/region) between June 2025 and June 2026, serving as a definitive resource on the region’s vast and fast-evolving threat universe.

Key findings from the report:

1. Cyber-attacks are intrinsically linked to real-world developments — and advancing fast

Today’s attacks directly correlate with fast-moving macroeconomic developments — and are linked to geopolitical tensions, digitalization, and the redrawing of supply chains, to name a few. All sectors are targeted, and no Asian market is immune.

At the same time, the criminal ecosystem is industrializing. The past year has seen the creation of large-scale, professionalized scam centers, and the maturing of Ransomware-as-a-Service business models, among others. Just as technology and organizational management improves the operations of legitimate businesses, they are also improving the effectiveness of criminal groups.

 

2. Data breaches, ransomware, phishing and APT activity prevail

Four interconnected incident types dominate the attack landscape:

  • Data breaches (8,856 incidents, accounting for 39.9% of all attacks)
  • Ransomware (4,068 incidents; 18.3%)
  • Phishing (4,061 incidents; 18.3%)
  • State-affiliated Advanced Persistent Threats, or APTs (3,966 incidents; 17.9%)

The Asia-Pacific is now one of the fastest-growing and largest monetization markets for ransomware and data extortion. Some 57% of initial ransom payments top US$1 million; while 52% of all ransom payments exceed US$1 million.

“Two things are changing at once, and together they redraw the threat model. The vulnerability lifecycle is compressing: flaws that once took skilled researchers weeks to find and weaponize now emerge at a pace no human team can match. At the same time, the expertise barrier is falling, so attacks that used to require elite operators are increasingly within reach of far less-skilled actors – and our report shows the near term of that curve,” said Mr. Feng XUE, Co-founder and Chief Executive Officer of ThreatBook.

E-commerce impersonation accounts for almost half of phishing incidents. Other techniques include fake government notices like tax reminders; bank verification prompts; equipment rental QR codes — and even wedding invites. Notably, artificial intelligence (AI) is rapidly increasing phishing success rates, accounting for 80% of activity volume, with click rates now exceeding 50%.

Feng added, “AI already generates roughly 80% of the phishing volume we track, and deepfake video conferencing is impersonating executives to move money and open doors. Faster offense in more hands is not something human-only triage can scale to meet, which is why defense has to move to agentic, intelligence-led threat hunting that runs at machine speed and augments analysts rather than replacing them."

Notably, APT incidents increasingly occur in tandem with regional geopolitical tensions: state-linked APTs are no longer solely pursuing intelligence theft, and are establishing a strategic presence within communications networks and other critical infrastructure, which can be activated should geopolitical conflicts escalate.

 

3. China and government entities are prime targets, while Russia and North Korea are the top perpetrators

In terms of targeting, China, India, Australia, Japan, and South Korea together accounted for 61.78% of all attacks. Economic scale, digital-asset density, industrial-intelligence value, and geopolitical sensitivity form the structural reasons for high-attack concentration.

China receives more attacks than any other market, accounting for 15.4% (3,299 incidents) of all incidents. The nation is followed by India (14.7%; 3,144 incidents), Australia (11.8%; 2,537 incidents), Japan (10.7%; 2,282 incidents), South Korea (9.2%; 1,978 incidents); and Singapore ranks sixth (4.5%; 963 incidents), while Hong Kong ranks 14th (1.5%; 329 incidents).

Government is the most targeted industry, accounting for 15% of all attacks, followed by Technology (around 12%) and financial services (9%). In the APT space, defense is the most targeted sector, reflecting today’s national security focus of APT activity.

The report found that Russia-linked criminal gangs dominate the ransomware space, with eight out of the top 10 named groups reportedly affiliated with the country[i]. APT groups are more dispersed, despite North Korean APT groups occupying positions one, three, four and 10 in terms of activity. The top Ransomware and APT groups are listed in the report.

 

4. Hong Kong: APT attacks prevail with espionage, IP theft and pre-positioning the priority

Unlike other Asia-Pacific markets, Hong Kong experiences more APT attacks than ransomware incidents. Hong Kong is an intelligence-collection venue for APT groups; APT attacks account for 37.6% of all incidents, while ransomware amounts to just 16.2%. The focus is long-term espionage and IP theft. Once data is exfiltrated, it is used for cross-border fraud, precision phishing and fund theft. The stolen data is also used for sustained attacks on high-value individuals and is leveraged to gain pre-positioning within critical infrastructure networks.

APT groups focus on three paths:

  • Targeted social engineering against virtual asset and technology personnel.
  • Stolen MNC intelligence and information.
  • Remote control access, followed by data wiping of mobile endpoints.

By contrast, ransomware incidents lean towards data ransom, rather than pure encryption shutdowns. Hong Kong-focused ransomware groups execute one of two common strategies:

  • When targeting infrastructure assets with extremely high downtime costs, use of data encryption maximizes negotiation leverage.
  • When targeting IP-intensive technology scenarios, once design files enter dark web markets, and competitors and nation-state actors can obtain them, data exposure becomes a sustained and irreversible threat — making typically more effective than encryption.

 

5. Singapore: A prime target for regional data and financial flows

Singapore’s threat landscape bears all the traits of a regional business and financial center, with attacks predominantly targeting regional multinational (MNC) headquarters, and the data and financial flows they orchestrate. Typically, a single breach within an MNC spreads to multiple offices across different countries.

Mr. Chase LI, Co-founder and Managing Director for International Business at ThreatBook said, “Attackers scale by reuse, not by bespoke planning for each market. A technique that works against one organization works against every organization with the same exposure, and so does a compromised vendor, platform, or service provider that hands over access. An attack proven against a bank in Singapore lands just as well on a Hong Kong bank running the same stack. That is why a breach rarely stays in one market: a single compromise inside a multinational reaches its offices across countries, and one trusted node that falls carries the attacker into every business relying on it.”

In the ransomware space, two attack tactics prevail: “double extortion”, where data is both stolen and encrypted to maximize the likelihood of payment; while organizations with robust business continuity plans are heavily targeted, as ransom payments are usually included in these plans.

APT groups targeting Singapore have a dual mandate: direct revenue generation; and cyber espionage and sabotage. The techniques used in Singapore APT attacks are incredibly novel, including:

  • Targeted phishing campaigns orchestrated by fake recruiters, developers, financiers, legal counsel and other trusted service providers.
  • Stolen worker identities posing as Singapore IT talent and capitalizing on remote interview and work arrangements.
  • AI-deepfake video conferencing meetings, where organization executives are impersonated near perfectly.

“The advantage here belongs to organizations that stay in the know. Your exposure is defined by your stack and your vendors, not your borders, and current firsthand intelligence on what is already hitting your peers and their vendors lets you act on the same technique before it reaches you,” concluded Chase.

Other APAC markets analyzed in depth within the report include Australia, Indonesia and Malaysia. To view the full findings, download the 2026 Mid-Year Asia-Pacific Threat Landscape Report here.


[i] The following eight of the top-10 gangs listed in the report are linked with Russia: Qilin; Clop; Akira; Inc Ransom; The Gentlemen; LockBit; Everest; and Lynx.

About ThreatBook

ThreatBook is the agentic security company focused on AI for Security, and Security for AI. Founded in 2015, ThreatBook is a global cybersecurity company with offices in Singapore and Hong Kong, combining AI with deep threat intelligence to defend enterprises across all stages of the security lifecycle: precise threat detection, automated triage and response, and risk reduction.

With unique vantage points across the Asia Pacific region, ThreatBook delivers intelligence that bridges Eastern and Western threat landscapes, providing an unmatched perspective for global defenders against nation-state actors, cybercriminal groups, and emerging attack campaigns.
ThreatBook operates the number-one security community in APAC and empowers the industry with free security tools, including ThreatBook Investigator, SafeSkill, and Flocks.

Leading analyst firms Gartner and Forrester have recognized ThreatBook, featuring the company in Forrester's Network Analysis And Visibility Solutions Landscape, Q2 2025 report, and the inaugural Gartner® Magic Quadrant™ for Network Detection and Response (NDR), among others. In all instances, ThreatBook was one of a limited number of vendors recognized.

To learn more, visit www.threatbook.io or follow us on LinkedIn.

ThreatBook Launches Best-of-Breed Advanced Threat Intelligence Solution

1 min read

ThreatBook Launches Best-of-Breed Advanced Threat Intelligence Solution

Analyzing over 14 billion cyber-attack records daily, ThreatBook ATI is a global solution enriched with granular, local insights; and can offer...

Read More
ThreatBook Peer-Recognized as a Strong Performer in the 2025 Gartner® Peer Insights™ Voice of the Customer for Network Detection and Response — for the Third Consecutive Year

1 min read

ThreatBook Peer-Recognized as a Strong Performer in the 2025 Gartner® Peer Insights™ Voice of the Customer for Network Detection and Response — for the Third Consecutive Year

Recognition we believe underscores global customer trust and proven product excellence for security teams evaluating NDR solutions

Read More
ThreatBook Selected in the First-ever Gartner® Magic Quadrant™ for Network Detection and Response (NDR)

1 min read

ThreatBook Selected in the First-ever Gartner® Magic Quadrant™ for Network Detection and Response (NDR)

BEIJING - June 4, 2025 - After nearly a year of research and evaluation, Gartner released the first "Magic Quadrant for Network Detection and...

Read More