Britain’s warning to Iran — clear, uncompromising, and backed by evidence — should be read by every business owner as a blunt reminder: hostile actors will not respect borders, and they will use the most intimate channels to reach inside organisations. The National Cyber Security Centre’s attribution of CHOSEN BRICK campaigns, using spear‑phishing on WhatsApp and Telegram to harvest emails, messages and credentials, turned a geopolitical spat into a practical threat for small and medium enterprises everywhere, including Singapore.
Why this matters to Singapore SMEs, right now
Threat actors do not discriminate. State‑linked groups and independent criminal gangs use the same playbook: research, impersonation, emotional leverage, and a final lure that feels just familiar enough to be believable. That familiar platform could be the company WhatsApp group where suppliers confirm invoices. It could be the Telegram channel where a local partner posts shipping updates. One carefully crafted message is enough to open a door.
“Who opened this link? It looked like it came from the boss,” the office manager asked during a call. Silence followed. Payroll was exposed.
That exchange happened to a Singapore client. The message mimicked a trusted supplier, contained a benign‑looking PDF link, and executed credential theft when the link prompted a login. The result: stolen emails, exposed attachments, and weeks of scramble. No dramatic ransomware banner — just quiet, targeted extraction.
CHOSEN BRICK: a short, pragmatic read
CHOSEN BRICK is not glamorous. It is precise. It leverages social engineering delivered via messaging apps that most teams treat as casual tools. The attacker crafts messages tailored to targets — often using public profiles, corporate announcements, or recent transactions to build trust. Once credentials or a malicious payload are captured, lateral movement begins, data exfiltration follows, and the business that ignored the warning notices the damage when it is already deep.
Practical, high‑impact controls that actually work
Complex frameworks feel good on slides. For SMEs with stretched budgets and busy teams, focus matters. Prioritise controls that stop the top attack vectors used by CHOSEN BRICK and similar campaigns.
- Multi‑factor authentication (MFA): Enforce MFA on email, cloud services and MFA‑supported admin tools. A stolen password should never be enough.
- Messaging hygiene: Treat WhatsApp and Telegram as official channels only with hardened controls. Disable automatic link previews and train staff to verify unusual requests by voice call to a known number.
- Endpoint hygiene: Keep devices patched, limit administrative privileges, and enforce screen locks and device encryption. A compromised laptop is a vault opened.
- Phishing simulations and role play: Regularly test staff with realistic scenarios. Debrief fully — explain why the message worked and how to spot the red flags.
- Backups and data segmentation: Ensure backups are immutable where possible, segmented from primary systems, and tested regularly for recovery speed.
Immediate incident steps when exposure is suspected
Speed saves value. When a suspicious message, unexpected credential reset, or unusual outbound data flow appears, act without hesitation.
- Isolate affected accounts and devices. Do not power off devices if forensic preservation is needed — disconnect network access instead.
- Rotate credentials and revoke sessions for compromised accounts. Force MFA re‑enrolment where available.
- Preserve logs: application logs, messaging histories, and system event logs matter for root cause and recovery.
- Notify regulators and local incident response bodies. In Singapore, engage SG‑CERT and relevant authorities early; their guidance saves time and reduces compliance risk.
- Communicate clearly to stakeholders: admit the issue, outline actions taken, and commit to frequent, transparent updates.
A cultural fix, not just a technical one
Technology without culture is decoration. A technical control can fail when staff feel pressured to act fast. Build a culture where verification is routine and where calling out a suspicious message earns praise, not reproach. Train leaders to role‑model verification behaviour. Encourage the simple habit of a quick callback to confirm an instruction that looks unusual — it will frustrate attackers more than any firewall.
Final verdict: prepare like a sovereign, act like a neighbour
Britain’s stance is resolute because the risk is real. That level of resolve is not exclusive to governments; every SME can adopt it. Implement layered controls, rehearse incident response, and treat messaging apps with the same caution given to email. When a threat is noisy and public, the defensive response must be louder and straighter. When a threat is quiet and targeted, the defensive response must be smarter and faster.
Enough warnings. The next message that arrives in a work chat could be ordinary or it could be CHOSEN BRICK‑style reconnaissance. Pause. Verify. Report. Recover if needed. The difference between an inconvenience and a catastrophe is often just one careful decision made early.

