0% found this document useful (0 votes)
5 views5 pages

Scratch

The document outlines various sections related to cybercrime offenses, law enforcement authorities, and the governance of cyber-based attribution, emphasizing the importance of data quality, privacy, and defined attribution models. It discusses Singapore's recent public attribution of a cyber threat actor linked to China, marking a shift in its approach to cyber operations amidst geopolitical tensions. Additionally, it highlights the evolving threat landscape in the Philippines, focusing on organized cybercriminal networks and their impact on critical infrastructure.

Uploaded by

edpaala
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
5 views5 pages

Scratch

The document outlines various sections related to cybercrime offenses, law enforcement authorities, and the governance of cyber-based attribution, emphasizing the importance of data quality, privacy, and defined attribution models. It discusses Singapore's recent public attribution of a cyber threat actor linked to China, marking a shift in its approach to cyber operations amidst geopolitical tensions. Additionally, it highlights the evolving threat landscape in the Philippines, focusing on organized cybercriminal networks and their impact on critical infrastructure.

Uploaded by

edpaala
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Section 4. Cybercrime Offenses.

Section 9. Law Enforcement Authorities

Section 10. Powers and Functions of Law Enforcement Authorities

Section 11. Duties of Law Enforcement Authorities. –

Section 12. Preservation and Retention of Computer Data

Section 13. Collection of Computer Data.

Section 14. Disclosure of Computer Data.

Section 15. Search, Seizure and Examination of Computer Data.

Section 16. Custody of Computer Data

Section 17. Destruction of Computer Data.

Section 20. Extent of Liability of a Service Provider.

Section 27. Powers and Functions.

Section 28. Department of Justice (DOJ); Functions and Duties.

Section 29. Computer Emergency Response Team (CERT).

Section 30. Duties of a Service Provider

Cyber-Based Attribution Governance:

Cyber-Based Attribution Governance is attribution-ready governance to protect the


cyber environment on a framework of rules and processes designed to accurately
assign credit or responsibility for cybercrime offenses and cyberattacks to the specific
actions, datasets, touchpoints or (security) incidents that caused them. This is
especially relevant in data-driven environments, such as artificial intelligence (AI),
where multiple factors (e.g. attack vectors, attack surface) can influence a single
result.

Key components of Cyber-Based Attribution Governance

1) Data quality and integrity: Policies must ensure complaints data is accurate,
complete, and captured consistently. This includes standardizing the format for
different fields, such as customer information, complaint details, and resolution
steps.

2) Data quality and lineage: A robust system for data governance is foundational. It
ensures data is clean, complete, and properly labeled, with a clear history of its
origin and modifications
3) Privacy and security: Robust access controls are critical to protect sensitive
personal information. Governance rules must define who can view, edit, and
access complaints data, and all access must be logged for auditing purposes.

4) Defined attribution models: Governance establishes clear, organization-wide


rules for how to measure the sensitivity, impact, severity of different activities.
o In threat intelligence, it provides a structured methodology for linking cyber
activity to a specific threat actor.

Vis-à-vis Cyber-attribution

The policy framework for cyber-attribution is a complex and evolving domain that
combines principles of international law with national interests, intelligence gathering,
and diplomacy. The decision to attribute a cyberattack is not merely a technical finding
but a strategic political choice with significant consequences for international relations
and security

Policy grounding for Cyber-Based Attribution rests on international law, specifically the
law of state responsibility, complemented by national cybersecurity strategies and
diplomatic efforts. The complexity of cyberspace, which is defined by anonymity,
multiple actors, and cross-border operations, complicates the process significantly.
This necessitates a multi-faceted approach involving technical, legal, and political
component

The foundational legal policy for cyber-attribution is derived from the Articles on the
Responsibility of States for Internationally Wrongful Acts (ARSIWA). Under ARSIWA,
a state is responsible for an act that consists of both an action or omission and a
breach of an international obligation. Key articles applied to cyberspace include:

 Attribution of state organs (Article 4): A cyber operation conducted by a state's


formal government body or official is attributable to the state. This is the most
straightforward case for legal attribution. (This is outside the scope of the
Policy Strategy Paper)

What Singapore's First Public Cyber-attribution Tells Us


Source:
[Link]
singapores-first-public-cyber-attribution-tells-us

For the first time, Singapore has called out a China-linked cyber threat
actor group, to the chagrin of Asia's regional hegemon.

The intent of this threat actor in attacking Singapore is quite clear’, Singapore’s
Coordinating Minister for National Security and Minister for Home Affairs Mr. K
Shanmugam noted.
They are going after high value, strategic targets. Vital infrastructure that
delivers our essential services. If it succeeds, it can conduct espionage, and it
can cause major disruption to Singapore and Singaporeans,’ he continued.

On 18 July, during the Cyber Security Agency’s 10th anniversary dinner, Minister
Shanmugam used his first speech in his new role to call out a Chinese-linked
cyber threat actor group ‘UNC3886' for targeting the country’s critical
infrastructure.

Singapore, like most countries – and especially Southeast Asian ones – has
historically refrained from publicly ‘naming and shaming’ other states or state-
linked actors conducting cyber operations. But the speech marked a shift in that
posture. For the first time, Singapore publicly attributed a cyber incident to an
Advanced Persistent Threat (APT) group, signalling a new phase in how the
country addresses the complex interplay between geopolitics and cyber
operations, restraint and responses.

For many it might seem unprecedented, but a closer look reveals a Singapore
that has been thinking and testing a ‘naming without (fully) naming’ strategy for
some time. While Singapore did not go as far as to attribute explicitly to China,
there are lessons to be learnt from a small, highly digitised city-state’s use of
attribution in a region fraught with geopolitical tensions and with the pressures of
a cyber power such as China.

Testing and Calibrating Approaches to Attribution

While this might have been the first time that Singapore named a cyber threat
actor targeting the country, this was not a sudden leap into the spotlight. As a
highly digitized small state with ambitious goals in technology and finance,
Singapore is uniquely exposed economically, regionally, and geopolitically to a
complex regional context. It is also deeply tied to China economically, as both a
trading partner and investor. These conditions have historically shaped
Singapore’s tightrope walk: strengthening national resilience and asserting
sovereignty without jeopardising its strategic ambiguity or drawing direct
retaliation.

Example of successful public Cyber-attribution case

A successful public Cyber-attribution case, where governments or private


security firms officially linked a cyberattack to a specific actor, demonstrates how
technical evidence and intelligence are used to hold malicious groups
accountable
.
WannaCry ransomware (2017)
 Attack details: The WannaCry ransomware worm spread to over 300,000
computers in 150 countries, encrypting data and demanding payment.
Notable victims included the UK's National Health Service, FedEx, and
Honda.

 Attribution: In late 2017, the U.S. and UK governments formally asserted that
North Korea was behind the attack, an assessment that was also supported
by Australia, Canada, and New Zealand. The attribution was based on
analysis from security researchers, who found code similarities between
WannaCry and previous malware used by the North Korea-linked Lazarus
Group

 Direction or control of non-state actors (Article 8): The conduct of a non-state


actor is attributable to a state if it is acting on the instructions of, or under the
"direction or control" of, that state. This is the most complex legal aspect of cyber-
attribution.

Non-state Actors.

The Philippine financial and cybercrime threat landscape is shaped by the


activities of organized cybercriminal networks. The rapid digitalization of the
country, coupled with security vulnerabilities, provides a fertile ground for
sophisticated and pervasive attacks.

Key threats include social engineering scams, malware, and supply chain
attacks, which impact both private citizens and critical infrastructure in the
government, finance, and telecommunications sectors.

Non-state actors, ranging from financially motivated cybercriminals are the most
prevalent threat, constantly evolving their tactics.

Organized cybercriminals

 Money muling: Criminal networks target low-income individuals to open


"sleeper" bank accounts to be used for money laundering. The rise of digital
IDs has worsened this problem by relaxing some account opening
restrictions.

 Scam hubs: Authorities have conducted raids on multiple scam hubs


operated by a mix of Chinese and Filipino nationals. These hubs run
widespread scams, including phishing campaigns targeting bank customers.

 Philippine Offshore Gaming Operators (POGOs): The government has


moved to close POGOs by the end of 2025 due to their links with various
financial crimes, including money laundering, scams, and human trafficking.

You might also like