Skip to content
The Cyber Security Place

All four of a country's telecoms, and nowhere to switch to

Event dated 20 February 2026 · Published 2 September 2026 · 3 sources

Researchers reported that a group tracked as UNC3886, described by them as China-linked, reached all four of Singapore's major telecommunications providers in a campaign running for months, using zero-day exploits and rootkits for persistent access. The attribution comes from security researchers rather than from the operators. What distinguishes it from a large breach is the coverage: the standard customer response to a compromised supplier — move to a competitor — had no destination, because the competitors were in the same report.

Supplier risk is usually framed as a choice. You assess providers, you pick one, and if it turns out badly you move. The framing survives because it is usually true: for most categories of supplier there is somewhere else to go.

Telecommunications in a single country is not one of those categories, and this campaign made the point in the most complete way available. Four providers, all of them, over months. A business that had done thorough due diligence and chosen the best-regarded of the four ended up in the same position as one that had chosen on price.

Persistence without a loss to investigate

The reported profile is quiet: zero-days for entry, rootkits for staying, months of access. No extortion note, no data dumped for sale, no outage. That is the signature of positioning rather than theft — establishing access and holding it, so that a capability exists on the day it is wanted.

It is also the hardest kind of intrusion to justify spending against, because it produces no incident to point at. A ransomware event writes its own business case. An intrusion whose entire output is continued presence generates a finding that reads: nothing has happened, and something is there.

Why telecoms specifically

A telecommunications operator is not primarily a target for what it holds. It is a target for what passes through it: who called whom, which devices were where, and — where lawful interception infrastructure exists — a system built for the express purpose of listening to selected people without their knowledge.

That last point is worth stating plainly because it recurs. The interception capability that a state requires its operators to build is, from the perspective of anybody who reaches it, a ready-made surveillance system with the hard part already done.

What a customer can actually change

Not the provider, in this instance. What remains is the assumption underneath the relationship: that the network is a trusted transport. Traffic encrypted end to end between endpoints you control is unaffected by who is inside the carrier. Traffic that relies on the carrier being honest is not.

The same applies to authentication that depends on a phone network — one-time codes sent by message, or verification by call. Those were already the weakest of the widely deployed second factors. A campaign that reaches every operator in a market moves them from weak to unsound, and the replacement does not depend on any carrier being trustworthy.