AI Enters the Criminal Toolkit, Singapore's Cyber Command Warns
Source: CNA Tech
A cybersecurity specialist inside Singapore's new Cyber Command says criminals are using AI to write malicious code and hunt for exploitable weaknesses.

Singapore's police force now fields a unit called Cyber Command, and a cybersecurity specialist attached to it says criminals are already putting artificial intelligence to work — drafting harmful code and scouting for flaws worth exploiting.
That assessment lands differently because of its source. It comes from inside the agency that polices cyberspace here, not from an outside researcher or a vendor hawking defences. It signals that law enforcement's own reading of the threat now counts offenders who farm out part of the job to machines that propose code and point at soft targets, shrinking the expertise a would-be intruder needs.
Two uses sit at the heart of the warning. One is generation, where AI assists in producing malicious software. The other is reconnaissance, where it accelerates the hunt for exploitable gaps. Speed is the common thread: work that once stretched across days can be compressed, and people with shallow technical backgrounds can attempt things that previously demanded real craft.
For defenders, the takeaway is uncomfortable. If attackers borrow automation to move faster, security teams cannot keep answering with slow manual review. Detection, patching and incident response all get judged against a clock that keeps accelerating, and the distance between a flaw appearing and an attack landing keeps narrowing.
It also reframes how budgets get argued. Tooling that filters noise, flags suspicious behaviour early and shortens response time stops looking like a luxury once the other side is running machine-assisted campaigns. The pressure is on to match tempo, not merely to tick compliance boxes.
Why it matters for Singapore: The city-state runs on connected systems, from banking to transport, so any shift in how intruders operate hits close to home. A police cyber unit naming AI as part of the criminal toolkit is a clear cue for local firms — treat AI-assisted attacks as today's baseline rather than a distant scenario.


