Skip to content

Cyber Risk Assessment

UNC3886 breach of Singapore’s four largest telcos

Date of Incident: 2024 Overview: In 2024, the APT group UNC3886 breached Singapore’s four major telecom companies—Singtel, StarHub, M1 Limited, and TPG Telecom. The attackers accessed some critical systems but failed to cause service disruptions or access sensitive customer data. Techniques used included exploiting public-facing applications and leveraging valid accounts, with attempts at lateral movement… Read More »UNC3886 breach of Singapore’s four largest telcos

Autonomous Penetration Testing Is Growing Up

For the last few years, autonomous penetration testing has been defined by proof of possibility that machines can plan and execute attacks without human operators. That question has been answered. The real question today is far more important: Can autonomous penetration testing operate credibly inside real enterprise environments continuously, safely, and at scale? At FireCompass,… Read More »Autonomous Penetration Testing Is Growing Up

AI and the Future of Offensive Security: Insights from Bruce Schneier and Bikash Barai

In a recent Fireside Chat, Bruce Schneier- renowned cryptographer, Harvard professor, and one of the most influential voices in cybersecurity- joined Bikash Barai, Founder & CEO of FireCompass, to discuss how AI is fundamentally reshaping pentesting, red teaming, and the future of cyber defense. Watch the Full Fireside Chat Recording Gain first-hand insights from Bruce… Read More »AI and the Future of Offensive Security: Insights from Bruce Schneier and Bikash Barai

Freedom Mobile Data Breach

Date of Incident: October 23, 2023 Overview: The Freedom Mobile Data Breach occurred on October 23, 2023, impacting the telecommunications sector. Unauthorized access led to the theft of personal information, including names, addresses, dates of birth, phone numbers, and account numbers of a limited number of customers. While there is no evidence of data misuse… Read More »Freedom Mobile Data Breach

Iberia Customer Data Leak

Date of Incident: 2024-04 Overview: The Iberia Customer Data Leak, reported on November 23, 2025, involved unauthorized access to a third-party vendor’s system supporting Iberia in April 2024. This breach exposed customer names, email addresses, and loyalty card IDs but did not compromise login credentials, passwords, or payment card information. The attack leveraged vulnerabilities and… Read More »Iberia Customer Data Leak