Thu, 23 Jul 2026

Structural rise in APAC cyber risk as AI-driven attacks accelerate

ThreatBook’s inaugural mid-year Asia-Pacific threat landscape report paints a sharper and more industrialised cyber risk picture for the region, with attacks increasingly tied to geopolitical tension, digitalisation and supply-chain shifts.

Conducted between June 2025 and June 2026, the report covered 15,205 incidents across more than 19 markets concluding that APAC’s threat environment is becoming more complex, faster-moving and more monetised.

The report says four incident types dominate the landscape: data breaches, ransomware, phishing and state-affiliated advanced persistent threat activity.

Data breaches accounted for 39.9% of attacks, followed by ransomware and phishing at 18.3% each, and APT activity at 17.9%, underscoring how closely criminal and state-linked operations are now intertwined across the region.

ThreatBook chief executive Feng Xue said the market is facing two simultaneous shifts: the vulnerability lifecycle is compressing, while the expertise barrier for attackers is falling.

“AI already generates roughly 80% of the phishing volume we track,” he said, warning that deepfake video conferencing is now being used to impersonate executives and move money.

That assessment is echoed in the report’s phishing findings. E-commerce impersonation makes up almost half of phishing incidents, while fake government notices, bank prompts, QR-code scams and even fake wedding invitations are being used to trap victims. ThreatBook said AI is helping attackers scale faster, with click rates now exceeding 50%.

The report also highlights the strategic importance of Hong Kong and Singapore. Hong Kong sees more APT incidents than ransomware, with long-term espionage, intellectual property theft and pre-positioning inside critical infrastructure taking priority.

Related:  Report highlights AI’s role in collapsing cyber exploitation windows

Singapore, meanwhile, is a prime target for regional data and financial flows, with attackers using fake recruiters, stolen identities and AI-deepfake meetings to breach multinationals and their vendors.

China received the most attacks in the region, followed by India, Australia, Japan and South Korea, while government was the most targeted sector overall. Russia-linked criminal gangs dominate ransomware activity, while North Korean APT groups are among the most active state-linked actors, according to the report.

The broader trend is clear: APAC cyber defence is moving from reactive alert handling to intelligence-led, machine-speed threat hunting. For CISOs, the report reinforces the need to harden identity, vendor and cross-border exposure, while preparing for attacks that increasingly blend financial crime, espionage and AI-enabled social engineering

Related Stories

MORE STORIES