Asia-Pacific cyber threats rise on AI & geopolitics
Tue, 21st Jul 2026 (Yesterday)
ThreatBook has published a mid-year Asia-Pacific cyber threat report covering 15,205 security incidents across more than 19 markets in the region.
The report points to rising cyber risk tied to economic shifts, geopolitical tensions, digitalisation, and supply chain changes. It identifies four dominant categories in the regional threat landscape: data breaches, ransomware, phishing, and state-affiliated Advanced Persistent Threat activity.
Data breaches made up the largest share of recorded incidents, with 8,856 cases, or 39.9% of the total. Ransomware accounted for 4,068 incidents, phishing for 4,061, and APT activity for 3,966, giving those three categories broadly similar shares of 17.9% to 18.3%.
The findings suggest attacks are not evenly spread across the region. China, India, Australia, Japan, and South Korea together accounted for 61.78% of all incidents tracked, with China alone representing 15.4%, or 3,299 incidents.
India followed with 3,144 incidents, or 14.7% of the total. Australia recorded 2,537 incidents, Japan 2,282, and South Korea 1,978. Singapore ranked sixth with 963 incidents, while Hong Kong placed 14th with 329.
By sector, government was the most frequently targeted, accounting for 15% of all attacks, followed by technology at about 12% and financial services at 9%. In APT-related activity, defence was the main target, which the report links to the growing national security focus of state-backed operations.
Regional patterns
The report says criminal groups and state-linked actors are adapting their methods as quickly as businesses adopt new technology and operating models. It describes a more organised criminal ecosystem, including large scam centres and mature ransomware-for-hire models.
ThreatBook says Asia-Pacific has become a major market for ransomware and data extortion. The report found that 57% of initial ransom demands exceeded USD $1 million, while 52% of all ransom payments were above that level.
Phishing remained a major route into organisations, with eCommerce impersonation accounting for almost half of such incidents. Other methods included fake tax reminders, counterfeit bank verification prompts, equipment-rental QR codes, and false wedding invitations.
Artificial intelligence is increasing the volume and success rate of phishing campaigns. The report attributes about 80% of phishing activity volume to AI-assisted methods and says click-through rates now exceed 50%.
"Two things are changing at once, and together they redraw the threat model. The vulnerability lifecycle is compressing: flaws that once took skilled researchers weeks to find and weaponize now emerge at a pace no human team can match. At the same time, the expertise barrier is falling, so attacks that used to require elite operators are increasingly within reach of far less-skilled actors - and our report shows the near term of that curve," said Mr. Feng XUE, Co-founder and Chief Executive Officer, ThreatBook.
He added that AI was reshaping phishing and fraud techniques.
"AI already generates roughly 80% of the phishing volume we track, and deepfake video conferencing is impersonating executives to move money and open doors. Faster offense in more hands is not something human-only triage can scale to meet, which is why defense has to move to agentic, intelligence-led threat hunting that runs at machine speed and augments analysts rather than replacing them," said Mr. XUE.
Hong Kong focus
One of the clearest market-specific findings concerned Hong Kong, where APT activity exceeded ransomware incidents. APT attacks represented 37.6% of all incidents in Hong Kong, compared with 16.2% for ransomware.
The report describes Hong Kong as an intelligence-collection venue for APT groups, focused on long-term espionage and intellectual property theft. It says stolen data is later used in cross-border fraud, targeted phishing, fund theft, and efforts to gain footholds in critical infrastructure networks.
According to ThreatBook, APT groups in Hong Kong typically follow three routes: targeted social engineering aimed at virtual asset and technology staff, theft of multinational company intelligence, and remote-access attacks followed by the wiping of mobile endpoint data.
Ransomware activity in the city showed a different pattern. Attackers often focus on data extortion rather than simply locking systems, particularly where infrastructure operators face high downtime costs or where leaked intellectual property would have lasting commercial value.
Singapore risks
In Singapore, the report found a threat profile shaped by the city-state's role as a regional business and financial hub. Attackers frequently targeted the regional headquarters of multinational companies and the data and financial flows that run through them.
That means a single compromise can spread across multiple offices in different countries through shared systems, vendors, or trusted service providers. The report also says ransomware operations in Singapore commonly rely on double extortion, in which attackers both steal and encrypt data to increase pressure on victims.
It identified a separate APT pattern in Singapore, with groups pursuing both direct financial gain and cyber espionage or sabotage. Techniques included phishing by people posing as recruiters, developers, financiers, and legal advisers; the use of stolen worker identities to pose as Singapore-based IT talent; and deepfake video meetings designed to mimic senior executives.
"Attackers scale by reuse, not by bespoke planning for each market. A technique that works against one organization works against every organization with the same exposure, and so does a compromised vendor, platform, or service provider that hands over access. An attack proven against a bank in Singapore lands just as well on a Hong Kong bank running the same stack. That is why a breach rarely stays in one market: a single compromise inside a multinational reaches its offices across countries, and one trusted node that falls carries the attacker into every business relying on it," said Mr. Chase LI, Co-founder and Managing Director for International Business, ThreatBook.
He said exposure was increasingly shaped by shared technology and supplier relationships rather than national borders.
"The advantage here belongs to organizations that stay in the know. Your exposure is defined by your stack and your vendors, not your borders, and current firsthand intelligence on what is already hitting your peers and their vendors lets you act on the same technique before it reaches you," said Mr. LI.