Home Business News Cyber Attack | 2026 APAC Cybersecurity Report: Hong Kong Faces Elevated APT Threats, Becomes Key Target for Cross-Border Data Theft
Business NewsTech & Startups

Cyber Attack | 2026 APAC Cybersecurity Report: Hong Kong Faces Elevated APT Threats, Becomes Key Target for Cross-Border Data Theft

Share
Share

AI-native cybersecurity firm ThreatBook has released its 2026 Mid-Year Asia-Pacific Threat Landscape Report, analyzing more than 15,205 security incidents across 19 APAC markets from June 2025 to June 2026. The report highlights that cyberattacks in the region are becoming increasingly industrialized and AI-driven, with Hong Kong and Singapore—two major financial hubs—exhibiting distinct threat profiles. Local enterprises are urged to build intelligence-led defense capabilities to mitigate cross-border risks.

The report categorizes APAC cyber threats into four main types. Data breaches are the most prevalent, accounting for 39.9% of all attacks, followed by ransomware and phishing at 18.3% each, and advanced persistent threat (APT) attacks at 17.9%. The region has become the world’s most lucrative market for ransomware, with approximately 57% of initial ransom demands exceeding USD 1 million, and over half of all paid ransoms surpassing that threshold. AI has fundamentally reshaped the attack landscape: around 80% of phishing content is now AI-generated, with click-through rates exceeding 50%. Hackers are increasingly using deepfake video technology to impersonate executives and authorize unauthorized fund transfers—tactics that traditional firewalls struggle to detect.

Mr. Feng XUE, Co-founder and Chief Executive Officer of ThreatBook

ThreatBook co-founder and CEO Xue Feng emphasized that the cyber threat environment is undergoing a dual transformation that is redefining traditional defense logic: “Two shifts are happening simultaneously, reshaping the threat model. Vulnerability lifecycles are shortening—flaws that once took skilled researchers weeks to discover and weaponize now emerge at speeds no human team can match. At the same time, the barrier to entry is dropping. Attacks that once required elite hackers are now within reach of less technically adept actors, a trend our report also captures in the near term.”

Xue added that the widespread availability of AI tools has significantly lowered the threshold for phishing scams, necessitating a parallel evolution in corporate defense strategies: “Of the phishing attacks we tracked, about 80% were AI-generated, and deepfake video conferencing is now being used to impersonate executives todivert funds and gain access. As attack velocity increases and the pool of adversaries grows, human-only incident triage can no longer scale. Defenses must shift to autonomous, agent-based, intelligence-led threat hunting that operates at machine speed—augmenting analysts, not replacing them.”

Cyberattacks are frequent, with China ranking first in the region in the number of attacks. (Photo: internet)

In terms of geographic distribution, China, India, Australia, Japan, and South Korea together account for 61.78% of all attacks, with China experiencing the highest volume in the region. Hong Kong and Singapore, though both financial centers, face markedly different threat landscapes. Hong Kong recorded 329 security incidents, with APT attacks comprising 37.6% of local cases—far exceeding ransomware’s 16.2%—making it one of the few markets where state-sponsored espionage is the primary threat. Hackers have long targeted confidential corporate data and intellectual property in Hong Kong, pre-positioning backdoors in enterprise networks to steal data for cross-border phishing campaigns and infrastructure infiltration.

Singapore, as a hub for multinational headquarters, faces APT groups with dual objectives: financial gain and strategic disruption. (Photo: internet)

Singapore, as a hub for multinational headquarters, faces APT groups with dual objectives: financial gain and strategic disruption. Attacks are highly sophisticated, with hackers posing as recruiters, financial advisors, or legal consultants to induce employees into leaking sensitive information. These are often combined with AI-powered deepfake video calls to execute high-level financial fraud. Ransomware attacks in Singapore commonly employ double extortion—encrypting data while simultaneously exfiltrating it to increase ransom leverage.

Chase Li, ThreatBook’s co-founder and Managing Director of International Business, who oversees APAC markets, highlighted the cross-border contagion risk between Hong Kong and Singapore’s financial sectors: “Attackers scale by reusing proven tactics rather than customizing for each market. A method that works against one institution is equally effective against others with similar risk profiles. Likewise, once a supplier, platform, or service provider is compromised, the impact is replicated across all dependent entities. Techniques that successfully breach Singaporean banks can just as easily compromise Hong Kong banks operating on the same technology stack. This is why data breaches do not stop at national borders—a single intrusion within a multinational can ripple across its global offices, and the compromise of one trusted node grants access to all enterprises relying on it.”

Mr. Chase LI, Co-founder and Managing Director for International Business at ThreatBook

Li concluded with a strategic recommendation for APAC enterprises: “In this environment, institutions with the latest threat intelligence hold the advantage. An organization’s risk exposure depends more on its technology stack and supply chain than on perimeter defenses. Access to real-time intelligence on attacks targeting peers and suppliers enables proactive defense before the same tactics are turned against you.”

The report also notes that attack playbooks proven effective against Singaporean financial institutions can be directly applied to Hong Kong banks with similar architectures, underscoring the high degree of cross-border risk transmission.

On the threat actor front, Russia-affiliated criminal groups dominate the global ransomware ecosystem, with eight of the top ten ransomware families linked to Russia. North Korean APT teams remain highly active in cross-regional espionage, with several leading groups consistently targeting APAC commercial and defense sectors. The report observes that cyberattacks have become modular and commercialized, with “ransomware-as-a-service” lowering entry barriers for hackers. Traditional perimeter-based defenses are no longer sufficient.

Xue and Li jointly recommend that, in light of accelerating vulnerability weaponization and the proliferation of AI-powered hacking tools, Hong Kong enterprises should urgently transition to intelligence-driven, AI-autonomous defense architectures. By continuously monitoring threat intelligence from peers and supply chains, organizations can proactively intercept cross-border APT espionage and AI-enabled fraud, preventing irreversible leakage of intellectual property and operational data.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Tech & StartupsBusiness News

Domestic Chips Surge: Huawei and Xiaomi Unveil Self-Developed Processors, Sparking a Tech Upgrade

China’s tech industry is hitting a milestone in chip self-sufficiency. Amid a...

WealthBusiness News

Baidu Added to HK Stock Connect: Short-Term Southbound Inflows Could Reach HK$47 Billion

Baidu (9888.HK) has been officially included in the Shanghai–Hong Kong and Shenzhen–Hong...

Business NewsHot TopicTech & Startups

Anthropic Accelerates IPO Plans: Roadshow Targeted for Mid-October, Listing Before U.S. Midterms

Reuters, citing people familiar with the matter, reports that AI company Anthropic...

Business NewsHot Topic

OpenAI AI Agents Suspected of Mass “Jailbreak”: Hijacked German Wiki to Share Evasion Tactics

OpenAI’s AI agents are alleged to have staged a coordinated breakout from...

Market TrendsBusiness News

Jollibee Plans Overseas Spin-Off, Eyes Hong Kong Listing to Build Global Dining Platform

Philippine fast-food leader Jollibee Foods Corporation (JFC) has announced plans to spin...