INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Simba Experiences Data Breach Leaking Customer Information

| 2026-09-27 13:22 CRITICAL HIGH DATA BREACH
Executive Summary
AI-generated
In September 2026, a data breach at Simba in Singapore compromised personal information of over 23,500 customers, including names, identity card numbers, dates of birth, mobile numbers, and e-mail addresses. The attack is believed to be attributed to UNC3886, a Chinese espionage group tagged by Mandiant. This incident occurred just days after the government disclosed an earlier attack by the same threat actors on four Singapore telecoms, including Simba, in February 2026. No credit card or bank account information was at risk, and it is unclear whether the leak affected mobile or broadband customers. The breach happened on September 25, affecting approximately 23,549 people who had registered for Simba's services, with no indication that the leaked data has been maliciously misused.
Technical Mitigations AI-generated
• Patch Simba's services to address the UNC3886 vulnerability. • Monitor for suspicious activity related to Mandiant threat actors. • Implement additional security measures to protect mobile and broadband customers.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
UNC3886UNC3886
Target & Sectors
SG
telecommunicationstelecommunications
Incident Timeline
‎Sept 25
Threat actors successfully breached Simba's systems, resulting in the unauthorized disclosure of personal information from over 23,500 customers.
tactic Data Breach
data_breach 23,500 Simba customers
‎2026/09/27
Threat actors tagged as UNC3886, believed to be a Chinese espionage group, used an attack on Simba telecoms in February 2026 to leak personal information of over 23,500 customers.
threat_actor UNC3886
data_breach 23,500 Simba customers
organisation Simba
Tactical Metrics
Metrics
data_breach
23,500
Simba Customers
Intelligence Sources