Singapore and Hong Kong, 21 July 2026 — ThreatBook, the agentic security company, today released its inaugural “2026 Mid-Year Asia-Pacific Threat Landscape Report”, which draws on a detailed analysis of 15,205 security incidents (or attacks) that took place in over 19 markets (country/region) between June 2025 and June 2026, serving as a definitive resource on the region’s vast and fast-evolving threat universe.
Key findings from the report:
1. Cyber-attacks are intrinsically linked to real-world developments — and advancing fast
Today’s attacks directly correlate with fast-moving macroeconomic developments — and are linked to geopolitical tensions, digitalization, and the redrawing of supply chains, to name a few. All sectors are targeted, and no Asian market is immune.
At the same time, the criminal ecosystem is industrializing. The past year has seen the creation of large-scale, professionalized scam centers, and the maturing of Ransomware-as-a-Service business models, among others. Just as technology and organizational management improves the operations of legitimate businesses, they are also improving the effectiveness of criminal groups.
2. Data breaches, ransomware, phishing and APT activity prevail
Four interconnected incident types dominate the attack landscape:
The Asia-Pacific is now one of the fastest-growing and largest monetization markets for ransomware and data extortion. Some 57% of initial ransom payments top US$1 million; while 52% of all ransom payments exceed US$1 million.
“Two things are changing at once, and together they redraw the threat model. The vulnerability lifecycle is compressing: flaws that once took skilled researchers weeks to find and weaponize now emerge at a pace no human team can match. At the same time, the expertise barrier is falling, so attacks that used to require elite operators are increasingly within reach of far less-skilled actors – and our report shows the near term of that curve,” said Mr. Feng XUE, Co-founder and Chief Executive Officer of ThreatBook.
E-commerce impersonation accounts for almost half of phishing incidents. Other techniques include fake government notices like tax reminders; bank verification prompts; equipment rental QR codes — and even wedding invites. Notably, artificial intelligence (AI) is rapidly increasing phishing success rates, accounting for 80% of activity volume, with click rates now exceeding 50%.
Feng added, “AI already generates roughly 80% of the phishing volume we track, and deepfake video conferencing is impersonating executives to move money and open doors. Faster offense in more hands is not something human-only triage can scale to meet, which is why defense has to move to agentic, intelligence-led threat hunting that runs at machine speed and augments analysts rather than replacing them."
Notably, APT incidents increasingly occur in tandem with regional geopolitical tensions: state-linked APTs are no longer solely pursuing intelligence theft, and are establishing a strategic presence within communications networks and other critical infrastructure, which can be activated should geopolitical conflicts escalate.
3. China and government entities are prime targets, while Russia and North Korea are the top perpetrators
In terms of targeting, China, India, Australia, Japan, and South Korea together accounted for 61.78% of all attacks. Economic scale, digital-asset density, industrial-intelligence value, and geopolitical sensitivity form the structural reasons for high-attack concentration.
China receives more attacks than any other market, accounting for 15.4% (3,299 incidents) of all incidents. The nation is followed by India (14.7%; 3,144 incidents), Australia (11.8%; 2,537 incidents), Japan (10.7%; 2,282 incidents), South Korea (9.2%; 1,978 incidents); and Singapore ranks sixth (4.5%; 963 incidents), while Hong Kong ranks 14th (1.5%; 329 incidents).
Government is the most targeted industry, accounting for 15% of all attacks, followed by Technology (around 12%) and financial services (9%). In the APT space, defense is the most targeted sector, reflecting today’s national security focus of APT activity.
The report found that Russia-linked criminal gangs dominate the ransomware space, with eight out of the top 10 named groups reportedly affiliated with the country[i]. APT groups are more dispersed, despite North Korean APT groups occupying positions one, three, four and 10 in terms of activity. The top Ransomware and APT groups are listed in the report.
4. Hong Kong: APT attacks prevail with espionage, IP theft and pre-positioning the priority
Unlike other Asia-Pacific markets, Hong Kong experiences more APT attacks than ransomware incidents. Hong Kong is an intelligence-collection venue for APT groups; APT attacks account for 37.6% of all incidents, while ransomware amounts to just 16.2%. The focus is long-term espionage and IP theft. Once data is exfiltrated, it is used for cross-border fraud, precision phishing and fund theft. The stolen data is also used for sustained attacks on high-value individuals and is leveraged to gain pre-positioning within critical infrastructure networks.
APT groups focus on three paths:
By contrast, ransomware incidents lean towards data ransom, rather than pure encryption shutdowns. Hong Kong-focused ransomware groups execute one of two common strategies:
5. Singapore: A prime target for regional data and financial flows
Singapore’s threat landscape bears all the traits of a regional business and financial center, with attacks predominantly targeting regional multinational (MNC) headquarters, and the data and financial flows they orchestrate. Typically, a single breach within an MNC spreads to multiple offices across different countries.
Mr. Chase LI, Co-founder and Managing Director for International Business at ThreatBook said, “Attackers scale by reuse, not by bespoke planning for each market. A technique that works against one organization works against every organization with the same exposure, and so does a compromised vendor, platform, or service provider that hands over access. An attack proven against a bank in Singapore lands just as well on a Hong Kong bank running the same stack. That is why a breach rarely stays in one market: a single compromise inside a multinational reaches its offices across countries, and one trusted node that falls carries the attacker into every business relying on it.”
In the ransomware space, two attack tactics prevail: “double extortion”, where data is both stolen and encrypted to maximize the likelihood of payment; while organizations with robust business continuity plans are heavily targeted, as ransom payments are usually included in these plans.
APT groups targeting Singapore have a dual mandate: direct revenue generation; and cyber espionage and sabotage. The techniques used in Singapore APT attacks are incredibly novel, including:
“The advantage here belongs to organizations that stay in the know. Your exposure is defined by your stack and your vendors, not your borders, and current firsthand intelligence on what is already hitting your peers and their vendors lets you act on the same technique before it reaches you,” concluded Chase.
Other APAC markets analyzed in depth within the report include Australia, Indonesia and Malaysia. To view the full findings, download the 2026 Mid-Year Asia-Pacific Threat Landscape Report here.
[i] The following eight of the top-10 gangs listed in the report are linked with Russia: Qilin; Clop; Akira; Inc Ransom; The Gentlemen; LockBit; Everest; and Lynx.