Company Details
singtel
8,231
281,970
517
singtel.com
0
SIN_1556632
In-progress

Singtel Company CyberSecurity Posture
singtel.comSingtel is Asia's leading communications technology group, providing a portfolio of services from next-generation communication, 5G and technology services to infotainment to both consumers and businesses. The Group has presence in Asia, Australia and Africa and reaches over 740 million mobile customers in 21 countries. Its infrastructure and technology services for businesses span 21 countries, with more than 428 direct points of presence in 362 cities. For consumers, Singtel delivers a complete and integrated suite of services, including mobile, broadband and TV. For businesses, Singtel offers a complementary array of workforce mobility solutions, data hosting, cloud, network infrastructure, analytics and cyber security capabilities. Singtel is dedicated to continuous innovation, harnessing next-generation technologies to create new and exciting customer experiences as we shape a more sustainable, digital future. The Group’s purpose is grounded in empowering our people to innovate better ways to connect with customers, unlock new possibilities for future businesses to thrive and foster a sense of ownership and belonging to better serve our stakeholders, partners and communities.
Company Details
singtel
8,231
281,970
517
singtel.com
0
SIN_1556632
In-progress
Between 800 and 849

Singtel Global Score (TPRM)XXXX

Description: The Optus breach in 2022 involved attackers stealing millions of customer records through an unauthenticated API endpoint. This incident cost the telecom company $140 million AUD in fallout. The vulnerability was easy to exploit and similar issues are still being found in major organizations.
Description: Dennis Su, 19, texted 93 of the telco's customers, demanding they transfer $2000 to a CBA bank account He threatened them for exposing personal information being used for financial crimes. He was having a difficult time being unemployed and wanted to make some quick money.
Description: In September 2022, Optus, a major Australian telecommunications provider, suffered a massive data breach involving unauthorized access to the personal information of approximately **9.5 million Australians**—nearly **40% of the country’s population**. The exposed data included highly sensitive details such as **names, birth dates, addresses, contact information, and government-issued identifiers (passport, Medicare, and driver’s license numbers)**. A portion of the stolen data was later **leaked on the dark web**, increasing risks of identity theft, financial fraud, and phishing attacks. The Australian Information Commissioner (AIC) alleged that Optus **failed to implement reasonable security measures** between **October 2019 and September 2022**, violating the **Privacy Act 1988**. The breach stemmed from an **unsecured API endpoint**, allowing attackers to exploit weak authentication controls. The AIC is pursuing **civil penalties of up to AUD $2.22 million per affected individual**, potentially resulting in one of the largest fines in Australian data protection history. The incident severely damaged Optus’s reputation, triggered regulatory scrutiny, and prompted nationwide calls for stricter cybersecurity laws.
Description: The Australian Information Commissioner (AIC) has launched civil action against Optus for a 2022 data breach that exposed the personal details of 9.5 million Australians. The breach involved sensitive personally identifiable information, including names, dates of birth, home addresses, phone numbers, email addresses, and government-related identifiers such as passport numbers, driver’s licence numbers, and Medicare card numbers. The attackers exploited a misconfigured API to access the dataset without authentication and issued a ransom demand. Although Optus prevented the theft of payment details and account passwords, a portion of the stolen data was leaked online. The AIC alleges Optus failed to take reasonable steps to protect the data, potentially facing significant financial penalties.
Description: In August 2025, Australia’s privacy regulator filed a landmark lawsuit against **Optus** over a **2022 data breach** that exposed the personal information of **9.5 million customers**. The breach, one of the largest in Australian history, involved unauthorized access to sensitive customer data, including names, dates of birth, phone numbers, email addresses, and in some cases, government-issued identification numbers (e.g., driver’s license or passport details). The potential regulatory fines could reach **A$2.2 million per affected individual**, totaling a catastrophic financial penalty exceeding **A$20 billion** if applied at maximum scale.The incident underscored systemic vulnerabilities in third-party data handling, particularly in highly regulated sectors like financial services and telecommunications. The breach not only triggered massive reputational damage but also led to a surge in fraudulent activities targeting affected customers, including identity theft and phishing scams. Optus faced intense scrutiny from regulators, lawmakers, and the public, with the case setting a precedent for stricter enforcement of data protection laws in Australia. The fallout also accelerated industry-wide shifts toward **localized, no-retention software solutions** to mitigate similar risks in the future.
Description: Hackers have breached Optus’ systems. They accessed names, dates of birth, phone numbers, email addresses, physical addresses and driver’s licence numbers of millions of the telecommunications giant’s customers. Up to 9 million customers had been affected. Many had their contact details exposed to the hackers, who also pilfered even more sensitive details, such as passport and drivers’ licence numbers, for a smaller portion of Optus customers.
Description: Optus, a telecommunications company suffered a data breach that exposed the private information of 10,000 account holders. The hackers, OptusData, demanded a ransom payment of about AUD$1.5 million in Monero cryptocurrency and said 10,000 records would be released daily until the cash is paid. According to the ransom note, more than 3.8 million "identity document numbers", 3.2 million driver's license numbers and four million user data records were exposed in the breach.
Description: The personal identification information of about 129,000 customers of Singtel was breached in a cyber attack on data transfer software, Accellion’s FTA that it uses. The stolen data includes name, date of birth, phone number, and address of the customers along with bank account information of some former employees.


No incidents recorded for Singtel in 2025.
No incidents recorded for Singtel in 2025.
No incidents recorded for Singtel in 2025.
Singtel cyber incidents detection timeline including parent company and subsidiaries

Singtel is Asia's leading communications technology group, providing a portfolio of services from next-generation communication, 5G and technology services to infotainment to both consumers and businesses. The Group has presence in Asia, Australia and Africa and reaches over 740 million mobile customers in 21 countries. Its infrastructure and technology services for businesses span 21 countries, with more than 428 direct points of presence in 362 cities. For consumers, Singtel delivers a complete and integrated suite of services, including mobile, broadband and TV. For businesses, Singtel offers a complementary array of workforce mobility solutions, data hosting, cloud, network infrastructure, analytics and cyber security capabilities. Singtel is dedicated to continuous innovation, harnessing next-generation technologies to create new and exciting customer experiences as we shape a more sustainable, digital future. The Group’s purpose is grounded in empowering our people to innovate better ways to connect with customers, unlock new possibilities for future businesses to thrive and foster a sense of ownership and belonging to better serve our stakeholders, partners and communities.


We advance how people connect with each other and the world #ConnectionIsEverything. Bell is Canada's largest communications company providing advanced Bell broadband wireless, Internet, TV, media and business communications services. Founded in Montréal in 1880, Bell is wholly owned by BCE Inc. T

Safaricom is the leading provider of converged communication solutions in Kenya. In addition to providing a broad range of first-class products and services for Telephony, Broadband Internet and Financial services, Safaricom seeks to uplift the welfare of Kenyans through value-added services and sup
We are driving the digital transition of Italy and Brazil with innovative technologies and services because we want to contribute to accelerating the sustainable growth of the economy and society by bringing value and prosperity to people, companies and institutions. We offer diversified solutions

(Formerly etisalat UAE) For more than four decades, we have connected people and now we’ve evolved to become the digital telco of the future. Our mission is to grow, transform and excel as the region’s technology leader while enhancing digital customer experience and operation agility. e& UAE offe

Vodafone Idea Limited is an Aditya Birla Group and Vodafone Group partnership. It is India’s leading telecom service provider. The Company provides pan India Voice and Data services across 2G, 3G and 4G platform. With the large spectrum portfolio to support the growing demand for data and voice, the

Idea Cellular is an Aditya Birla Group Company, India's first truly multinational corporation. Idea is a pan-India integrated GSM operator offering 2G and 3G services, and has its own NLD and ILD operations, and ISP license. With revenue in excess of $4 billion; revenue market share of 18%; and subs

Lumen connects the world. We digitally connect people, data and applications – quickly, securely and effortlessly. Everything we do at Lumen takes advantage of our network strength. From metro connectivity to long-haul data transport to our edge cloud, security, and managed service capabilities, we

Telcel (Radiomóvil Dipsa) es subsidiaria de América Móvil, uno de los mayores proveedores de comunicaciones celulares de Latinoamérica, grupo líder con inversiones en telecomunicaciones en varios países del continente americano. Telcel es la empresa de telefonía celular líder en México. Nuestra s

We are a forward-focused digital champion always been focused on innovation and evolution. Our purpose is to create and bring greater dimension and richness to people’s personal and professional lives. With stc, You will always be empowered to focus on delivering what’s next through collaborati
.png)
Under the agreement, SoftBank and Singtel will jointly explore go-to-market initiatives spanning global connectivity services, satellite-enabled...
[SINGAPORE] Singtel on Thursday (Oct 23) announced the launch of the first hybrid quantum-safe network (QSN) in South-east Asia,...
Singtel launches Southeast Asia's first Hybrid Quantum-Safe Network to deliver flexible, scalable security for enterprises. Cyber Security...
IMDA and Enterprise Singapore (EnterpriseSG) have partnered with Singtel to launch the Singtel Cyber Protect Programme,...
Singtel, in partnership with Enterprise Singapore (EnterpriseSG) and the Infocomm Media Development Authority (IMDA), today launched the...
The Singtel Cyber Protect Programme will help SMEs identify risks, adopt better cyber hygiene, and improve overall security. It aims to...
The programme comprises practical cybersecurity workshops to help SMEs defend against sophisticated threats. Singtel, EnterpriseSG and IMDA will...
The programme aims to secure business mobile lines and office networks of SMEs against threats. Read more at straitstimes.com.
Find out how Singtel is proactively mitigating threats by deploying advanced quantum-resistant cryptographic solutions.

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Singtel is http://www.singtel.com.
According to Rankiteo, Singtel’s AI-generated cybersecurity score is 800, reflecting their Good security posture.
According to Rankiteo, Singtel currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Singtel is not certified under SOC 2 Type 1.
According to Rankiteo, Singtel does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Singtel is not listed as GDPR compliant.
According to Rankiteo, Singtel does not currently maintain PCI DSS compliance.
According to Rankiteo, Singtel is not compliant with HIPAA regulations.
According to Rankiteo,Singtel is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Singtel operates primarily in the Telecommunications industry.
Singtel employs approximately 8,231 people worldwide.
Singtel presently has no subsidiaries across any sectors.
Singtel’s official LinkedIn profile has approximately 281,970 followers.
Singtel is classified under the NAICS code 517, which corresponds to Telecommunications.
No, Singtel does not have a profile on Crunchbase.
Yes, Singtel maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/singtel.
As of November 27, 2025, Rankiteo reports that Singtel has experienced 8 cybersecurity incidents.
Singtel has an estimated 9,532 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include .
.png)
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF token leakage via protocol-relative URLs in angular HTTP clients. The vulnerability is a Credential Leak by App Logic that leads to the unauthorized disclosure of the Cross-Site Request Forgery (XSRF) token to an attacker-controlled domain. Angular's HttpClient has a built-in XSRF protection mechanism that works by checking if a request URL starts with a protocol (http:// or https://) to determine if it is cross-origin. If the URL starts with protocol-relative URL (//), it is incorrectly treated as a same-origin request, and the XSRF token is automatically added to the X-XSRF-TOKEN header. This issue has been patched in versions 19.2.16, 20.3.14, and 21.0.1. A workaround for this issue involves avoiding using protocol-relative URLs (URLs starting with //) in HttpClient requests. All backend communication URLs should be hardcoded as relative paths (starting with a single /) or fully qualified, trusted absolute URLs.
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft deep ASN.1 structures that trigger unbounded recursive parsing. This leads to a Denial-of-Service (DoS) via stack exhaustion when parsing untrusted DER inputs. This issue has been patched in version 1.3.2.
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overflow vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft ASN.1 structures containing OIDs with oversized arcs. These arcs may be decoded as smaller, trusted OIDs due to 32-bit bitwise truncation, enabling the bypass of downstream OID-based security decisions. This issue has been patched in version 1.3.2.
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, working with large buffers in Lua scripts can lead to a stack overflow. Users of Lua rules and output scripts may be affected when working with large buffers. This includes a rule passing a large buffer to a Lua script. This issue has been patched in versions 7.0.13 and 8.0.2. A workaround for this issue involves disabling Lua rules and output scripts, or making sure limits, such as stream.depth.reassembly and HTTP response body limits (response-body-limit), are set to less than half the stack size.
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, a NULL dereference can occur when the entropy keyword is used in conjunction with base64_data. This issue has been patched in version 8.0.2. A workaround involves disabling rules that use entropy in conjunction with base64_data.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.