ThreatBook has published its first mid-year Asia-Pacific Threat Landscape Report, drawing on 15,205 security incidents recorded across more than nineteen markets between June 2025 and June 2026.
The report singles out five markets for detailed treatment — Australia, Singapore, Indonesia, Malaysia and Hong Kong — which makes it one of the more ASEAN-legible pieces of regional threat reporting published this year. Three of those five sit inside Southeast Asia.
What the dataset counts
Four categories cover most of what was recorded: data breaches at 39.91%, ransomware at 18.33%, phishing at 18.30% and APT activity at 17.87%.
Those categories overlap, and the report says so plainly — 51% of breach incidents also involved ransomware. An incident can be counted more than once, so the four shares should be read as overlapping views of the same body of events rather than slices of a pie. ThreatBook describes it as phishing opening the door, intrusion taking the room, and stolen data priming the next round.
Where ASEAN sits
By raw volume the region's largest economies dominate. China, India, Australia, Japan and South Korea together account for 61.78% of everything tracked, with China alone at 15.4%.
| Market | Share of incidents | Rank | Implied count |
|---|---|---|---|
| Australia | 11.84% | 3rd | ~1,800 |
| Singapore | 4.49% | 6th | ~683 |
| Malaysia | 2.91% | 10th | ~443 |
| Hong Kong | 1.53% | 14th | ~233 |
Shares are ThreatBook's. The implied-count column is RECATOOLS arithmetic — each share applied to the stated total of 15,205 incidents — and is indicative only, because the report's categories overlap. Indonesia is treated as a priority market but no share figure is published for it.
ThreatBook's own caveat is worth repeating: rank counts frequency, not what a single intrusion is worth. That matters most for hub economies — Singapore and Hong Kong can show modest counts sitting on concentrated financial and logistics infrastructure.
The sector picture in Southeast Asia
The market-level detail is where the report earns its keep. In Singapore, financial services show up in 71% of data-breach incidents and 40% of phishing incidents — a concentration that follows the shape of the economy rather than any particular campaign.
In Indonesia, government is the single most-targeted sector at 35.1%, and dual extortion — stealing data as well as encrypting it — appears in 63.8% of ransomware cases. Indonesia is also the fastest-deteriorating of the five priority markets, with attack activity growing 35.0% year over year.
| Attack type | Share of Indonesian incidents |
|---|---|
| Data breach | 49.4% |
| Ransomware | 26.2% |
| Phishing | 22.4% |
| APT activity | 15.0% |
ThreatBook's within-country mix for Indonesia. Shares overlap and do not sum to 100%. Every category except APT runs above the regional aggregate, and the report describes the signature Indonesian attack as a mobile identity-fraud chain that "runs on habit rather than on a vulnerability".
Hong Kong reports the highest data-breach share in the region at 58.6%, with APT activity at 37.6% and ransomware at 16.2%, less than half the regional average. ThreatBook reads that mix as long-horizon espionage and intellectual-property theft rather than smash-and-grab extortion.
Ransomware is professionalising
More than 120 new ransomware brands emerged over the period, and victim counts rose 58% year on year. On the money, 57% of initial ransom demands exceeded one million US dollars, and 52% of payments actually made cleared the same bar.
The second number matters more. A high demand says what attackers want; a high payment rate says what victims felt they had to do.
AI has moved into the delivery layer
ThreatBook attributes roughly 80% of detected phishing volume to AI generation, with click-through rates above 50% across email, SMS, QR codes, messaging apps and OAuth prompts. E-commerce impersonation accounts for close to half of phishing incidents.
This matches what we have been documenting through the month. An Iranian-linked group was using generative AI for phishing craft, and researchers recovered logs showing an AI agent running reconnaissance unattended inside a Thai ministry network. In each case the technology is absorbing work that used to need people.
Australia is the outlier
Australia sits third at 11.84%, well ahead of any Southeast Asian market and behind only China and India. It is the only economy in the top five that is neither a manufacturing hub nor a market of a billion-plus people, which makes its position a function of something other than size.
Put Hong Kong next to that — fourteenth by volume at 1.53%, but with the highest data-breach share in the region at 58.6% and APT activity at 37.6% — and two different problems come into view: high-volume markets soak up commodity crime, while concentrated financial hubs draw fewer incidents of a more deliberate kind.
What it changes for defenders here
Three findings translate into work rather than commentary.
The dual-extortion rate means an Indonesian organisation planning for ransomware has to plan for a disclosure event, not only a recovery one. Restoring from backup resolves the outage and does nothing about data already taken, and the regulatory clock runs on the theft.
The phishing findings shift where detection effort pays. If AI generates most of the volume and click rates run above 50%, the traditional signals — poor grammar, awkward phrasing, obvious formatting errors — have stopped carrying weight, and the delivery surface now spans QR codes, messaging apps and OAuth consent prompts as well as email.
And the persistence figure attached to Earth Bluecrow — a Linux kernel-level average of 8.7 months, roughly twice the global figure — is an argument about detection coverage rather than prevention. An intrusion measured in months is one that was survivable at every point where somebody could have looked.
Two actors named
The report names Earth Bluecrow, credited with Linux kernel-level persistence averaging 8.7 months — roughly twice the global average — and BlueNoroff, linked to North Korea and to attacks using AI-generated deepfakes in video conferencing.
On attribution more broadly, ThreatBook reports that eight of the top ten named ransomware groups are Russia-affiliated, and that North Korean groups occupy four of the top ten APT positions. Attribution of this kind is an assessment, not a finding of fact, and we have not hardened it.
The caveats
- This is one vendor's telemetry. Visibility is shaped by where ThreatBook has sensors and customers, and no commercial dataset sees an entire region.
- Categories overlap. The four attack-type shares are not mutually exclusive; the report states that 51% of breaches also involved ransomware.
- Published counts vary between write-ups. Some secondary coverage quotes absolute incident counts that do not reconcile with the 15,205 total. We have used ThreatBook's own percentages and flagged our arithmetic where we converted them.
- No Indonesia share is published, so its growth figure cannot be placed against the other markets by volume.
Key takeaways
- 15,205 incidents across 19-plus markets over twelve months to June 2026.
- Singapore ranks sixth by volume, Malaysia tenth; Indonesia is the fastest-growing at +35% year on year.
- Dual extortion is the default in Indonesia, at 63.8% of ransomware incidents.
- Singapore's financial sector appears in 71% of local breach incidents.
- AI generates around 80% of detected phishing, with click rates above 50%.