A Global Issue: Cybercrime In Singapore

Singapore’s Cybercrimes nearly doubled in proportion between 2014 and last year, rising from 7.9 per cent to 13.7 per cent of all crimes, according to the inaugural Singapore Cyber Landscape report.

This issue is now global and is not being properly monitored or dealt with by the governmental authorities and national police forces.

The report by the Cyber Security Agency of Singapore (CSA) found that more than eight in 10 cybercrimes (83 per cent) involved online cheating. This was followed by unauthorised access to computer material (15 per cent) and cyber extortion (2 per cent).

The authorities received 19 reports of ransomware cases from individuals and small and medium enterprises (SMEs) last year, up from two cases in 2015. The figures could be under-reported as companies are reluctant to let their reputation take a hit, noted the agency.

Other cyber threats included phishing and defacements, 2,512 phishing URLs were detected and 1,750 websites were defaced last year.

Singapore’s high level of connectivity comes with a corresponding level of vulnerability, said CSA chief executive David Koh.

“While advances in digital technology have opened up new possibilities to enhance our lives, they have also exposed us to cyber threats that aim to cheat us, steal or alter our data, disrupt our daily business activities, and cripple our critical infrastructure.”

Offences under the Computer Misuse and Cybersecurity Act soared over the past three years, from 197 cases in 2014 to 691 cases last year. Criminals tend to make use of ransomware and hacking, as well as compromise online accounts, SingPass and Internet banking accounts.

Cyber criminals will continue to adopt “more sophisticated social engineering techniques to lure their victims”, said the CSA.

Victims of website defacements tend to be SMEs. One in 10 defaced websites were hosted on an outdated operating system, such as Windows Server 2003.

“Such operating systems may no longer have security patches for new vulnerabilities and hence are easier for hackers to exploit,” the CSA said.

Websites for banking and financial services were the most commonly spoofed here, forming 31 per cent of phishing websites found last year.

Electronic payments platform PayPal and file-hosting services such as Dropbox and Google Drive were popular targets, and even government bodies such as the Ministry of Manpower and the Immigration and Checkpoints Authority were not spared.

The CSA said attackers sought personal data, such as passport numbers, that could be traded in underground markets.

The Internet Surfing Separation policy, announced in June last year, would “go a significant way” towards securing the information communication technology environment for public agencies. By cutting off Internet access on work computers, cyber attackers will not be able to gain remote access to the Government’s network and extract data as easily, said the CSA.

The report also stated that around two in five security incidents (43 per cent) that individuals and SMEs flagged to the authorities involved phishing. “Cyber criminals may attack SMEs as a means of getting to larger corporations, to which SMEs are suppliers,” said the CSA.

Business email scams were one of the top cyber threats that SMEs faced last year, with millions of dollars lost through phishing scams, where hackers impersonated company executives or business partners via email, said the agency.

Accordingly, crime statistics reflected a 20 per cent jump in email impersonation scams between 2015 and last year.

Over 60 command and control servers were detected in Singapore’s cyber space last year. Hackers use these servers to communicate with malware-infected devices and carry out malicious attacks such as data theft, email spam campaigns and DDoS (Distributed Denial of Service) attacks.

A DDoS attack involves flooding a system with data, causing disruption to business operations or distracting victims from ongoing cybercrimes.

Singapore saw a spike in DDoS extortion threats last year, with several unnamed organisations receiving emails from hackers demanding payment in lieu of launching such attacks.

Stressing the importance of resilience in the cyber realm, Mr Koh said: “This is because it is impossible to prevent successful attacks 100 per cent of the time. As Singapore pursues its plans to build a Smart Nation, we cannot afford to ignore the threats that come with it.”

Today Online

You Might Also Read:

Singapore’s Mounting Cyber Threats:

Singapore Defense Ministry Under Remote Attack:

 

 

« The Shifting Sands of Cybersecurity
What Is Selling On the Dark Net? »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

FT Cyber Resilience Summit: Europe

FT Cyber Resilience Summit: Europe

27 November 2024 | In-Person & Digital | 22 Bishopsgate, London. Business leaders, Innovators & Experts address evolving cybersecurity risks.

Prewen

Prewen

Prewen provide solutions to protect sensitive data across the organisation.

Apricorn

Apricorn

Apricorn provides hardware-based 256-bit encrypted external storage products to companies and organizations that require high-level protection for their data at rest.

Qubitekk

Qubitekk

Qubitekk has developed quantum cryptography solutions for the machine-to-machine (M2M) communications market.

InstaSafe Technologies

InstaSafe Technologies

InstaSafe®, a Software Defined Perimeter based (SDP) one-stop Secure Access Solution for On-Premise and Cloud Applications.

CopSonic

CopSonic

Copsonic provide a technology solution based on ultrasonic waves to send secure and encrypted data between two devices in order to achieve authentication.

Yelbridges

Yelbridges

Yelbridges is your reliable partner in all fields of IT-Security, from developing of Security Policies and Guidelines to the design and implementation of secure processes.

IT Security Jobs

IT Security Jobs

IT Security Jobs is a dedicated portal for everything related to IT professionals looking for IT Security jobs.

CYSEC SA

CYSEC SA

Cysec is equipped to deliver agile security solutions for the most challenging IT infrastructures around the world.

Soffid

Soffid

Soffid provides full Single-Sign-On experience and full Identity and Access Management features by policy-based centralised orchestration of user identities.

Network Utilities (NetUtils)

Network Utilities (NetUtils)

Network Utilities provide identity centric network and security solutions to organisations from Telecoms and ISPs to SMEs and large corporates.

Darkscope

Darkscope

Darkscope is an award-winning personalised cyber intelligence service provider. Our cutting-edge AI and Deep Artificial Neural Networks lead the world of cyber intelligence solutions.

Blacksands

Blacksands

Blacksands is a leader in network architecture, identity & services management, threat analysis, industrial IoT architecture, and invisible dynamic networks.

Censinet

Censinet

Censinet provides the first and only third-party risk management platform for healthcare organizations to manage the threats to patient care that exist within an expanding ecosystem.

Bores Security Consultancy

Bores Security Consultancy

Bores Security Consultancy are an established family-run business delivering expertise in security and technology.

Information Security Society of Africa – Nigeria (ISSAN)

Information Security Society of Africa – Nigeria (ISSAN)

The Information Security Society of Africa – Nigeria (ISSAN) is a not-for-profit organization dedicated to the protection of Nigeria’s cyberspace.

Verosint

Verosint

Verosint (formerly 443ID) provides real-time account fraud prevention that reveals fraudsters hiding in user accounts and proactively blocks them before their attacks can cause harm.