Espionage stories usually arrive one company at a time. In February 2026, Singapore's Cyber Security Agency delivered a different kind: the China-linked group UNC3886 — a name the city-state had taken the rare step of speaking aloud months earlier — had breached all four of the country's major telecommunications providers. Not one carrier, or an unlucky pair. The set.
The completeness is the story. A nation's telecom layer is where everything converges — government, banking, shipping, the private conversations of five million people — and pre-positioned access across every major carrier is not a smash-and-grab posture; it is patient infrastructure for a future that hopefully never arrives. UNC3886's specialty had long been exactly this: quiet persistence inside routers, virtualization layers, and the network plumbing that security tooling watches least. February turned a suspicion into a national accounting.
For everyone else, Singapore's transparency was the actionable part. Most countries do not name the ghost in their phone system; some may simply not know it's there. The month's uncomfortable question, asked from Delhi to Berlin: if a state this small, rich, and competent found the ghost in all four carriers — what would an honest audit find in ours?
Iron Mountain meets Everest
There is a company whose entire brand is the safekeeping of other people's records — the underground vaults, the locked archives, the name that means permanence. In February, the Everest ransomware gang claimed Iron Mountain as a victim, compromising internal documents and client personal information. For a publication that calls its own archive The Vault, we note the lesson with appropriate humility: there is no such thing as a place too custodial to rob — only custodians who haven't been tested yet.
Substack, Flickr, and the third-party echo
On February 3, Substack discovered unauthorized access to user data — the platform where a million writers keep their audiences. Flickr followed, notifying users of a breach that arrived through a third-party provider rather than its own systems. Neither made the year's top ten by size; both fit its defining pattern: identity data leaking at the platform layer, often through someone else's door, eroding trust in services people don't think of as security decisions at all.
The ₹17,000 database
February's most instructive India item was also its cheapest. A threat actor going by "KaruHunters" advertised a database of roughly 35,000 Indian records on a dark-web forum for $200 — about ₹17,000, or dinner for four at a nice Delhi restaurant. Thirty-five thousand people's information, priced like a second-hand phone. The listing, documented in a mid-February intelligence report, said more about the economics of Indian data than any mega-breach: supply is so plentiful that identity has become a commodity sold in sachets. It is exactly the market the DPDP regime — then two months into its rulebook era — exists to shrink.
⏳ Time capsule — February 2026
- The month's trend-watchers converged on a phrase: identity compromise and "exposure without extortion" — stolen quietly, sold quietly.
- National registries and payment infrastructure kept appearing in incident ripple-effects — the collateral-damage era.
- In India, the first post-DPDP-Rules quarter turned "consent manager" into a job title recruiters actually posted.
- Security budgets met their new line item: AI agents — defending with them, and against them.
The ghost stayed newsworthy
Singapore's four-carrier disclosure kept unspooling long after February — a benchmark other governments now get measured against, and the clearest proof yet that telecom security is national security wearing work clothes. It slotted into the runway quarter's pattern with eerie neatness: January was the grid, February the carriers, March would be the wipers — infrastructure, communications, then destruction. And Iron Mountain's month served as the quarter's parable: in 2026, the question isn't whether your vault is impressive. It's when it gets tested, and by whom.