INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Simba Experiences Data Breach Leaking Customer Information
| 2026-09-27 13:22 CRITICAL HIGH DATA BREACH
Executive Summary
AI-generated
In September 2026, a data breach at Simba in Singapore compromised personal information of over 23,500 customers, including names, identity card numbers, dates of birth, mobile numbers, and e-mail addresses. The attack is believed to be attributed to UNC3886, a Chinese espionage group tagged by Mandiant. This incident occurred just days after the government disclosed an earlier attack by the same threat actors on four Singapore telecoms, including Simba, in February 2026. No credit card or bank account information was at risk, and it is unclear whether the leak affected mobile or broadband customers. The breach happened on September 25, affecting approximately 23,549 people who had registered for Simba's services, with no indication that the leaked data has been maliciously misused.
Technical Mitigations AI-generated
• Patch Simba's services to address the UNC3886 vulnerability.
• Monitor for suspicious activity related to Mandiant threat actors.
• Implement additional security measures to protect mobile and broadband customers.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
UNC3886UNC3886
Target & Sectors
SG
telecommunicationstelecommunications
Incident Timeline
Sept 25
Threat actors successfully breached Simba's systems, resulting in the unauthorized disclosure of personal information from over 23,500 customers.
Click on any entity below to view its context and source!
tactic
Data Breach
Rhea Yasmine reports:
Personal information of more than 23,500
Simba
customers has been compromised in a data breach, the telco said in a statement on Sept 25.
data_breach
23,500 Simba customers
Rhea Yasmine reports:
Personal information of more than 23,500
Simba
customers has been compromised in a data breach, the telco said in a statement on Sept 25.
2026/09/27
Threat actors tagged as UNC3886, believed to be a Chinese espionage group, used an attack on Simba telecoms in February 2026 to leak personal information of over 23,500 customers.
Click on any entity below to view its context and source!
threat_actor
UNC3886
In February, the Singapore government
disclosed that an attack by threat actors tagged as UNC3886
by Mandiant, believed to be a Chinese espionage group, had hit four Singapore telecoms, including Simba.
data_breach
23,500 Simba customers
Personal information of over 23,500 Simba customers leaked in data breach.
organisation
Simba
The data involved included names, identity card numbers, dates of birth, mobile numbers, and e-mail addresses belonging to 23,549 people, who had registered for Simba’s services.
Tactical Metrics
Metrics
data_breach
23,500
Simba Customers
Click for context!
Personal information of over 23,500 Simba customers leaked in data breach.
Rhea Yasmine reports:
Personal information of more than 23,500
Simba
customers has been compromised in a data breach, the telco said in a statement on Sept 25.
Intelligence Sources
Data Breaches
2026-09-27
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-06T11:50
Comprehensive Tactical Telemetry
Highly Correlated Entities
2x
tactic
Cyber Operation Type
Espionage
tactic
Contextual Telemetry
Context Block
8 METRICS
target region
Target Country
Singapore
country
industry
Targeted Sector
Government
sector
threat actor
APT Group
UNC3886
actor
source region
Origin Country
China
country
data breach
Simba Customers
23,500
simba customers
timeline
Temporal Reference
Sept 25
date
organisation
Identified Entity
Simba
entity
general metric
People
23,549
people
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.