Singapore Ransomware Attacks Aided by AI, Proofpoint Report Finds
Source: SecurityBrief Asia
Singapore has emerged as one of the markets most affected by AI-enhanced ransomware, with 68% of local organisations that experienced an attack saying artificial intelligence made the incident more effective.

Singapore has emerged as one of the markets most affected by AI-enhanced ransomware, with 68% of local organisations that experienced an attack saying artificial intelligence made the incident more effective. That finding comes from Proofpoint's 2026 AI-Era Ransomware Report, which surveyed 953 security professionals across 12 countries and reveals how attackers are using AI to turn social engineering into a precision weapon.
The report found that 10% of Singapore respondents said AI "significantly increased" the attack's effectiveness, while 58% said it "somewhat increased" it. Only 3% reported no evidence of AI being used. The data points to a clear shift: AI is not creating entirely new categories of ransomware, but it is making existing attack vectors — especially phishing and impersonation — dramatically more convincing and harder to detect.
In Singapore, 45% of affected organisations said employees did not suspect the attack because it appeared authentic. Email was the entry point for 28% of incidents, while malicious links were the most common vector at 53%. Three-quarters of organisations hit by ransomware reported data theft during the attack, and half said they paid a ransom — yet 45% of those that paid were then hit with a second extortion demand. The pattern suggests attackers are increasingly stealing credentials and data first, using those assets to press repeated demands rather than relying on encryption alone.
What stands out is how human-centric ransomware has become. Technical controls alone are not stopping these campaigns — attackers are targeting trusted communications, employee behaviour, and identity systems. The report shows that 48% of Singapore respondents said incidents occurred because users interacted with malicious content, the third-highest rate across all 12 surveyed markets.
Why it matters for Singapore: As one of Asia's most digitally connected economies, Singapore's exposure to AI-driven ransomware carries implications well beyond individual organisations. The city-state's push into AI adoption across banking, healthcare, and government services creates a larger attack surface that needs to be matched by equally sophisticated defences. The report's finding that paying a ransom often invites a second demand also underscores a hard truth: recovery strategies built on paying attackers are no longer viable when data theft gives them ongoing leverage. For Singapore's CISOs and security teams, the message is clear — the battleground has shifted from endpoints to people, and defences need to follow.