Espionage stories usually arrive one company at a time. In February 2026, Singapore's Cyber Security Agency delivered a different kind: the China-linked group UNC3886 — a name the city-state had taken the rare step of speaking aloud months earlier — had breached all four of the country's major telecommunications providers. Not one carrier, or an unlucky pair. The set.
The completeness is the story. A nation's telecom layer is where everything converges — government, banking, shipping, the private conversations of five million people — and pre-positioned access across every major carrier is not a smash-and-grab posture; it is patient infrastructure for a future that hopefully never arrives. UNC3886's specialty had long been exactly this: quiet persistence inside routers, virtualization layers, and the network plumbing that security tooling watches least. February turned a suspicion into a national accounting.
For everyone else, Singapore's transparency was the actionable part. Most countries do not name the ghost in their phone system; some may simply not know it's there. The month's uncomfortable question, asked from Delhi to Berlin: if a state this small, rich, and competent found the ghost in all four carriers — what would an honest audit find in ours?
Iron Mountain meets Everest
There is a company whose entire brand is the safekeeping of other people's records — the underground vaults, the locked archives, the name that means permanence. In February, the Everest ransomware gang claimed Iron Mountain as a victim, compromising internal documents and client personal information. For a publication that calls its own archive The Vault, we note the lesson with appropriate humility: there is no such thing as a place too custodial to rob — only custodians who haven't been tested yet.
Substack, Flickr, and the third-party echo
On February 3, Substack discovered unauthorized access to user data — the platform where a million writers keep their audiences. Flickr followed, notifying users of a breach that arrived through a third-party provider rather than its own systems. Neither made the year's top ten by size; both fit its defining pattern: identity data leaking at the platform layer, often through someone else's door, eroding trust in services people don't think of as security decisions at all.
The ₹17,000 database
February's most instructive India item was also its cheapest. A threat actor going by "KaruHunters" advertised a database of roughly 35,000 Indian records on a dark-web forum for $200 — about ₹17,000, or dinner for four at a nice Delhi restaurant. Thirty-five thousand people's information, priced like a second-hand phone. The listing, documented in a mid-February intelligence report, said more about the economics of Indian data than any mega-breach: supply is so plentiful that identity has become a commodity sold in sachets. It is exactly the market the DPDP regime — then two months into its rulebook era — exists to shrink.
Agent teams, and a label that failed
On 5 February 2026 two frontier labs shipped on the same day. Anthropic released Claude Opus 4.6, whose headline addition was what it called agent teams — several model instances splitting one task between them and coordinating directly rather than reporting to a single orchestrator. OpenAI released GPT-5.3-Codex, which the company described as its first model instrumental in creating itself. Google followed on 19 February with Gemini 3.1 Pro. The month's more instructive AI story was smaller and internal. Microsoft confirmed a code fault, logged as service advisory CW1226324, that let Microsoft 365 Copilot Chat summarise messages sitting in Sent Items and Drafts despite the confidentiality labels applied to them, bypassing the data-loss policies meant to hold them shut; customers had reported it from late January and a fix rolled out through mid-February. Capability shipped in a day; the controls around it took four weeks to catch up.
The endpoint stops being a laptop
February's endpoint news was mostly transactional. On 5 February 2026 Zscaler bought SquareX, a browser detection and response firm whose product is an extension rather than a separate enterprise browser; terms were not disclosed. On 11 February Palo Alto Networks closed its purchase of CyberArk, the identity security company it had agreed to buy the previous July, paying $45.00 in cash and 2.2005 of its own shares for each CyberArk share. Five days later it announced its intent to acquire Koi, an endpoint posture management firm, and named the category it was buying into: agentic endpoint security, meaning protection for the AI tools and agents that now hold broad permissions on a machine while remaining invisible to controls designed around human users. SecurityWeek counted 42 security acquisitions announced across the month. The number that explained the appetite arrived on 24 February, when CrowdStrike's annual threat report put the average eCrime breakout time for 2025 at 29 minutes, the fastest observed intrusion at 27 seconds.
⏳ Time capsule — February 2026
- The month's trend-watchers converged on a phrase: identity compromise and "exposure without extortion" — stolen quietly, sold quietly.
- National registries and payment infrastructure kept appearing in incident ripple-effects — the collateral-damage era.
- In India, the first post-DPDP-Rules quarter turned "consent manager" into a job title recruiters actually posted.
- Security budgets met their new line item: AI agents — defending with them, and against them.
The ghost stayed newsworthy
Singapore's four-carrier disclosure kept unspooling long after February — a benchmark other governments now get measured against, and the clearest proof yet that telecom security is national security wearing work clothes. It slotted into the runway quarter's pattern with eerie neatness: January was the grid, February the carriers, March would be the wipers — infrastructure, communications, then destruction. And Iron Mountain's month served as the quarter's parable: in 2026, the question isn't whether your vault is impressive. It's when it gets tested, and by whom.