A Global Issue: Cybercrime In Singapore

Singapore’s Cybercrimes nearly doubled in proportion between 2014 and last year, rising from 7.9 per cent to 13.7 per cent of all crimes, according to the inaugural Singapore Cyber Landscape report.

This issue is now global and is not being properly monitored or dealt with by the governmental authorities and national police forces.

The report by the Cyber Security Agency of Singapore (CSA) found that more than eight in 10 cybercrimes (83 per cent) involved online cheating. This was followed by unauthorised access to computer material (15 per cent) and cyber extortion (2 per cent).

The authorities received 19 reports of ransomware cases from individuals and small and medium enterprises (SMEs) last year, up from two cases in 2015. The figures could be under-reported as companies are reluctant to let their reputation take a hit, noted the agency.

Other cyber threats included phishing and defacements, 2,512 phishing URLs were detected and 1,750 websites were defaced last year.

Singapore’s high level of connectivity comes with a corresponding level of vulnerability, said CSA chief executive David Koh.

“While advances in digital technology have opened up new possibilities to enhance our lives, they have also exposed us to cyber threats that aim to cheat us, steal or alter our data, disrupt our daily business activities, and cripple our critical infrastructure.”

Offences under the Computer Misuse and Cybersecurity Act soared over the past three years, from 197 cases in 2014 to 691 cases last year. Criminals tend to make use of ransomware and hacking, as well as compromise online accounts, SingPass and Internet banking accounts.

Cyber criminals will continue to adopt “more sophisticated social engineering techniques to lure their victims”, said the CSA.

Victims of website defacements tend to be SMEs. One in 10 defaced websites were hosted on an outdated operating system, such as Windows Server 2003.

“Such operating systems may no longer have security patches for new vulnerabilities and hence are easier for hackers to exploit,” the CSA said.

Websites for banking and financial services were the most commonly spoofed here, forming 31 per cent of phishing websites found last year.

Electronic payments platform PayPal and file-hosting services such as Dropbox and Google Drive were popular targets, and even government bodies such as the Ministry of Manpower and the Immigration and Checkpoints Authority were not spared.

The CSA said attackers sought personal data, such as passport numbers, that could be traded in underground markets.

The Internet Surfing Separation policy, announced in June last year, would “go a significant way” towards securing the information communication technology environment for public agencies. By cutting off Internet access on work computers, cyber attackers will not be able to gain remote access to the Government’s network and extract data as easily, said the CSA.

The report also stated that around two in five security incidents (43 per cent) that individuals and SMEs flagged to the authorities involved phishing. “Cyber criminals may attack SMEs as a means of getting to larger corporations, to which SMEs are suppliers,” said the CSA.

Business email scams were one of the top cyber threats that SMEs faced last year, with millions of dollars lost through phishing scams, where hackers impersonated company executives or business partners via email, said the agency.

Accordingly, crime statistics reflected a 20 per cent jump in email impersonation scams between 2015 and last year.

Over 60 command and control servers were detected in Singapore’s cyber space last year. Hackers use these servers to communicate with malware-infected devices and carry out malicious attacks such as data theft, email spam campaigns and DDoS (Distributed Denial of Service) attacks.

A DDoS attack involves flooding a system with data, causing disruption to business operations or distracting victims from ongoing cybercrimes.

Singapore saw a spike in DDoS extortion threats last year, with several unnamed organisations receiving emails from hackers demanding payment in lieu of launching such attacks.

Stressing the importance of resilience in the cyber realm, Mr Koh said: “This is because it is impossible to prevent successful attacks 100 per cent of the time. As Singapore pursues its plans to build a Smart Nation, we cannot afford to ignore the threats that come with it.”

Today Online

You Might Also Read:

Singapore’s Mounting Cyber Threats:

Singapore Defense Ministry Under Remote Attack:

 

 

« The Shifting Sands of Cybersecurity
What Is Selling On the Dark Net? »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

Directory of Cyber Security Suppliers

Directory of Cyber Security Suppliers

Our Supplier Directory lists 7,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

Messageware

Messageware

Messageware is the market leader in securing, enhancing, and customizing Microsoft Exchange and Outlook Web App.

Computer Laboratory - University of Cambridge

Computer Laboratory - University of Cambridge

Computer security has been among the Laboratory’s research interests for many years, along with related topics such as cryptology

CSIRT-NQN

CSIRT-NQN

CSIRT-NQN is the Computer Incident Response Team for the Argentine province of Neuquen.

NodeSource

NodeSource

NodeSource helps organizations run production-ready Node.js applications with greater visibility into resource usage and enhanced awareness around application performance and security.

Inflexor Ventures

Inflexor Ventures

Inflexor Ventures is a technology focused venture capital firm that invests in early stage companies from seed to Series-A+ stages.

HancomWITH

HancomWITH

Hancomwith is an information security company. We provide optimized blockchain solutions in areas including next-generation authentication, security and digital asset transaction.

ChaosSearch

ChaosSearch

ChaosSearch is a massively scalable ELK-compatible log analysis platform delivered as a fully managed service with high-performance and low cost.

Vantage Point Security

Vantage Point Security

Vantage Point are specialists in penetration testing and application security with a focus on the industries undergoing rapid digital transformation.

Plante Moran

Plante Moran

Plante Moran is a leading audit, tax, consulting, and wealth management firm. Areas of consulting expertise include cybersecurity.

TPx Communications

TPx Communications

TPx is a leading managed services provider offering a full suite of managed IT, unified communications, network connectivity and security services.

Arctic Group

Arctic Group

Arctic Group is a Swedish service provider focusing on cybersecurity, integration services and deployment of software development tools.

American Technology Services (ATS)

American Technology Services (ATS)

American Technology Services provides unparalleled services in information technology to support small and mid-sized business. From top-level strategy, to managed services and infrastructure support.

Assured Clarity

Assured Clarity

Assured Clarity are a global consultancy, specialising in Risk Management and Data Privacy, through Education, Awareness and Training, throughout an organisation.

Jera IT

Jera IT

Jera IT provide fully managed IT support, cybersecurity services, telecoms systems, and IT strategy consultancy to businesses based in Aberdeen and the surrounding area.

TRM Labs

TRM Labs

TRM enables risk management and compliance for a global community of financial institutions, cryptocurrency businesses and government agencies.

Averlon

Averlon

Averlon offers organizations peerless cloud security through Panoptic Cloud Visibility, Predictive Attack Intelligence and Rapid Remediation.