Key Takeaways

  • Two Cyber Command investigators illustrate how cryptocurrency tracing and ransomware response increasingly require financial, technical and cross-border expertise.
  • Singapore recorded fewer scam and cybercrime cases in 2025, but losses remained high and malware activity increased.
  • Businesses can support investigations by preserving evidence, reporting incidents quickly and preparing coordinated response procedures.

The Singapore Police Force is putting a human face on an increasingly technical area of law enforcement, highlighting how two Cyber Command investigators handle complex cryptocurrency heists and ransomware cases. Their work reflects a broader shift in cyber policing: investigators now need to understand blockchain transactions, malicious software, digital infrastructure and conventional financial crime at the same time.

That combination matters because cybercrime rarely stays within one system or jurisdiction. Funds stolen from a Singapore victim may pass through several cryptocurrency wallets, exchanges and intermediary accounts within hours. A ransomware operator might deploy infrastructure in one country, buy access from another criminal group and demand payment through a wallet controlled elsewhere.

The investigation therefore extends beyond identifying a suspicious IP address. Cyber Command personnel may need to reconstruct a timeline, preserve data from affected devices, analyze transaction flows and coordinate requests involving financial institutions, digital-asset businesses or overseas authorities. Attribution can be difficult. Recovering money before it moves again is often even harder.

Singapore’s cybercrime challenge remains heavily shaped by scams, not only by malware. The Singapore Police Force reported that scam and cybercrime cases fell 24.8% on year to 41,974 in 2025. Scams still represented 88.9% of all cases, while total scam losses reached S$913.1 million. Police recovered about S$140.5 million in proceeds.

Those figures offer a mixed picture. Lower case volumes are encouraging, but the median loss per scam case increased to S$1,644. Government official impersonation scams more than doubled to 3,363 cases and generated S$242.9 million in losses. For investigators, one apparently routine impersonation complaint can lead toward mule accounts, cryptocurrency conversion services and organized networks operating beyond Singapore.

Ransomware creates a different operational problem. Rather than focusing primarily on deceptive communications and fraudulent transfers, investigators may encounter compromised credentials, remote-access tools, encrypted servers and stolen corporate data. The Cyber Security Agency of Singapore reported increased ransomware activity and systems infected by malware more than doubled, with Malware-as-a-Service and poorly secured Internet of Things devices contributing to the threat environment.

What does that mean for businesses? Evidence can disappear quickly during an incident, particularly when teams rebuild systems, delete accounts or reset devices before preserving logs. Those actions may be understandable when operations are disrupted, but they can complicate later analysis. A more useful approach often involves isolating affected assets, retaining relevant cloud and identity logs, documenting response actions and establishing an early channel with law enforcement.

Speed helps, especially where money is moving. Cryptocurrency transactions are recorded on public blockchains, but that visibility does not automatically reveal the person controlling a wallet. Investigators still need to connect blockchain activity with exchange records, device evidence, account registrations and other identifiers. Rapid reporting can improve the chance that intermediaries receive alerts while assets remain within reachable accounts.

There is also a governance angle. Incident response plans should clarify who can engage the Singapore Police Force, the Cyber Security Agency of Singapore, insurers, outside counsel and forensic specialists. They should also address decision authority for ransomware demands, regulatory notifications and communications with customers. The goal is not paperwork for its own sake. It is reducing confusion when technical and financial decisions have to be made under pressure.

A Baker McKenzie review of Singapore’s cyber landscape similarly points to the importance of treating cyber risk as both an operational and legal issue. For corporate leaders, the practical lesson is fairly direct: cybersecurity monitoring, fraud controls and financial-crime processes increasingly overlap. Security teams may detect the intrusion, treasury teams may spot unusual transfers, and compliance personnel may hold the records that help connect them.

The two investigators featured by Cyber Command represent that convergence. Their cases may begin with code, a payment trail or a victim report, but successful investigations often depend on combining all three. Singapore’s falling case count suggests progress, yet the scale of losses and growth in infected systems show why specialized cyber investigation remains central to public safety and business resilience.