Skip to the main content.
Resources
For Users
About ThreatBook
  2026 Mid-Year Report · Asia-Pacific

The 2026 Asia-Pacific threat landscape, mapped from 15,205 incidents.

ThreatBook Labs' inaugural mid-year report breaks down attack types, the most active ransomware and APT groups, and per-market threat profiles across Australia, Singapore, Indonesia, Malaysia, and Hong Kong — with the defensive priorities that follow from the data.

1

Data breaches dominate

39.91% of all incidents (8,856) — the region's leading attack type.

2

Ransomware is industrializing

120+ new brands emerged and victim counts rose 58% year over year, with dual-extortion now standard.

3

AI-driven phishing

AI-generated messages are 80% of phishing volume, with click rates topping 50%.

4

APT divergence in the financial hubs

Singapore and Hong Kong carry APT activity well above the regional norm.

By the numbers
15,205
Incidents analyzed, Jun 2025–Jun 2026
37.6%
Hong Kong APT share, vs 16.2% ransomware
22.4%
Singapore APT — nearly 1.4× the Asia-Pacific country average
Get the 2026 report
Complete the form to download the full report — PDF, 48 pages.
 
Your details are never shared with third parties.
The 2026 mid-year picture

What 15,205 incidents reveal

Across the region, data breaches led at 39.91% of all incidents, ransomware victim counts rose 58% year over year, and AI-generated messages now account for 80% of detected phishing — with click rates topping 50%. But the sharper story is regional divergence. In Singapore and Hong Kong — Asia-Pacific's two financial hubs — APT activity runs well above the regional norm: the signature of targeted espionage and multinational-headquarters intrusion, not opportunistic crime. This report shows how that plays out market by market, and what your team should prioritize as a result.

Inside the 48-page report

1

Attack-type breakdown

Data breaches, ransomware, phishing, and APT across APAC — regional shares and how the chains interconnect in real attacks.

2

Active ransomware & APT groups

Profiles of the most active clusters — Qilin, Akira, Lynx, plus Lazarus, APT41, Salt Typhoon and the shift toward pre-positioning.

3

Five in-depth market profiles

Attack-type composition, industry targeting, and market-specific actor activity for Australia, Singapore, Indonesia, Malaysia, and Hong Kong.

4

Singapore & Hong Kong spotlights

Financial-hub targeting, APT divergence, fake-recruiter and IT-worker lures, and AI-deepfake executive fraud.