ThreatBook has released its inaugural “2026 Mid-Year Asia-Pacific Threat Landscape Report”, analysing 15,205 security incidents across more than 19 Asia-Pacific markets between June 2025 and June 2026.
The report argues that cyberattacks in the region are increasingly linked to macroeconomic and geopolitical developments, including supply chain shifts and accelerating digitalisation. It also points to the “industrialising” nature of cybercrime, citing the growth of large-scale scam operations and ransomware-as-a-service models.
ThreatBook’s data indicates that four incident types dominate the region’s attack landscape: data breaches (8,856 incidents, 39.9% of attacks), ransomware (4,068 incidents, 18.3%), phishing (4,061 incidents, 18.3%), and state-affiliated advanced persistent threats (APTs) (3,966 incidents, 17.9%). The report also claims ransomware payments in the region are frequently large, stating that 57% of initial ransom payments and 52% of all ransom payments exceed US$1 million.
ThreatBook also links increased phishing effectiveness to the use of artificial intelligence, claiming AI-generated activity accounts for 80% of phishing volume it tracks and that click rates now exceed 50%. The report describes common lures including e-commerce impersonation, fake government notices, bank verification prompts, QR code scams, and social engineering using themes such as wedding invitations.
“Two things are changing at once, and together they redraw the threat model. The vulnerability lifecycle is compressing: flaws that once took skilled researchers weeks to find and weaponize now emerge at a pace no human team can match. At the same time, the expertise barrier is falling, so attacks that used to require elite operators are increasingly within reach of far less-skilled actors – and our report shows the near term of that curve,” said Mr. Feng XUE, Co-founder and Chief Executive Officer of ThreatBook.
ThreatBook’s report states that APT activity is increasingly occurring alongside geopolitical tensions, with state-linked actors not only pursuing intelligence theft but also establishing footholds in communications networks and other critical infrastructure that could be activated in a broader conflict.
On targeting, the report says China, India, Australia, Japan and South Korea accounted for 61.78% of attacks during the period assessed. China was listed as the most targeted market with 3,299 incidents (15.4%), followed by India (3,144; 14.7%), Australia (2,537; 11.8%), Japan (2,282; 10.7%) and South Korea (1,978; 9.2%). Singapore ranked sixth (963 incidents; 4.5%), and Hong Kong ranked 14th (329 incidents; 1.5%).
Government was described as the most targeted industry (15% of attacks), followed by technology (around 12%) and financial services (9%). In the APT category, the report identified defence as the most targeted sector.
The report attributes a large share of ransomware activity to Russia-linked criminal groups, stating that eight of the top 10 named ransomware groups are reportedly affiliated with Russia. In the APT category, it says North Korean groups ranked prominently, occupying positions one, three, four and 10 by activity.
The report singles out Hong Kong as an outlier in the region, stating that APT incidents outweigh ransomware. According to ThreatBook’s figures, APT attacks account for 37.6% of incidents in Hong Kong, compared with 16.2% for ransomware. ThreatBook says objectives include long-term espionage, intellectual property theft, and “pre-positioning” in critical infrastructure networks, and claims exfiltrated data can later be used for fraud, precision phishing and fund theft.
Singapore is characterised in the report as a prime target due to its role as a regional business and financial hub, with attacks allegedly focusing on multinational headquarters and the flows of data and funds they manage. “Attackers scale by reuse, not by bespoke planning for each market. A technique that works against one organization works against every organization with the same exposure, and so does a compromised vendor, platform, or service provider that hands over access,” said Mr. Chase LI, Co-founder and Managing Director for International Business at ThreatBook.
ThreatBook also claims APT groups targeting Singapore operate with a dual mandate of revenue generation and espionage or sabotage. Tactics described in the report include phishing campaigns run by fake recruiters and other trusted service providers, stolen identities posing as IT workers, and AI deepfake video conferencing impersonation.
The report also analyses Australia, Indonesia and Malaysia in more detail, according to ThreatBook.
You can read the full report here.

