Threat Intelligence
Security for AI
AI for Security
Use Cases
Resources
For Users
The 2026 Asia-Pacific threat landscape, mapped from 15,205 incidents.
ThreatBook Labs' inaugural mid-year report breaks down attack types, the most active ransomware and APT groups, and per-market threat profiles across Australia, Singapore, Indonesia, Malaysia, and Hong Kong — with the defensive priorities that follow from the data.
Data breaches dominate
39.91% of all incidents (8,856) — the region's leading attack type.
Ransomware is industrializing
120+ new brands emerged and victim counts rose 58% year over year, with dual-extortion now standard.
AI-driven phishing
AI-generated messages are 80% of phishing volume, with click rates topping 50%.
APT divergence in the financial hubs
Singapore and Hong Kong carry APT activity well above the regional norm.
What 15,205 incidents reveal
Across the region, data breaches led at 39.91% of all incidents, ransomware victim counts rose 58% year over year, and AI-generated messages now account for 80% of detected phishing — with click rates topping 50%. But the sharper story is regional divergence. In Singapore and Hong Kong — Asia-Pacific's two financial hubs — APT activity runs well above the regional norm: the signature of targeted espionage and multinational-headquarters intrusion, not opportunistic crime. This report shows how that plays out market by market, and what your team should prioritize as a result.
Inside the 48-page report
Attack-type breakdown
Data breaches, ransomware, phishing, and APT across APAC — regional shares and how the chains interconnect in real attacks.
Active ransomware & APT groups
Profiles of the most active clusters — Qilin, Akira, Lynx, plus Lazarus, APT41, Salt Typhoon and the shift toward pre-positioning.
Five in-depth market profiles
Attack-type composition, industry targeting, and market-specific actor activity for Australia, Singapore, Indonesia, Malaysia, and Hong Kong.
Singapore & Hong Kong spotlights
Financial-hub targeting, APT divergence, fake-recruiter and IT-worker lures, and AI-deepfake executive fraud.
Singapore|Hong Kong|Abu Dhabi|Riyadh|Beijing