Insights

From the director’s desk

Notes on AI, cybersecurity and staying safe in the agentic era, from Aaron Ang, our Regional Director for APAC.

Aaron Ang
Aaron Ang
Regional Director, APAC · CWG Innovations

Non-Executive Director of Edvance International Holdings (HKEX: 1410) and Vice-President of the Digital Defence Alliance Singapore. He writes about cybersecurity, AI and the people caught in the middle.

“The platform itself is the red flag”

The Straits Times — ST Explains: How do scammers exploit government directories, and how can they be stopped? (15 August 2026), featuring Aaron Ang of CWG Innovations
As featured in The Straits Times, 15 August 2026. Read the full article ↗

When The Straits Times asked me how scammers exploit our government directories, my answer probably wasn’t the one people expected. Yes, a public list of names, titles and numbers lends an impersonator credibility. You look up the officer, find a real match, and your guard drops. But the bigger shift is in where these scams now happen.

Government official impersonation scams more than doubled last year, to 3,363 cases, with $242.9 million lost. As the telcos clamped down on spoofed local and agency numbers, the fraudsters simply moved house. As I told ST, they have shifted to messaging apps like WhatsApp, where they can spoof numbers the telcos cannot police. They dress it up, too: official logos as profile pictures, and, in the bolder cases, someone in uniform against an office backdrop on a video call.

My advice is blunt, because it needs to be. No Singapore agency handles case matters over WhatsApp. The platform itself is the red flag, so you don’t even need to work out whether the officer is real. That one rule protects more people than any amount of detail-checking.

I also don’t think stripping every directory is the answer. Changing all our contact details at once could open fresh gaps in the confusion. It is a bit like changing your house number to stop junk mail. The lasting fix is the human layer. Make “pause, and verify on a number you looked up yourself” a reflex, and keep reminding people that officials will never ask you to move money or hand over passwords. That belief in education is a big part of the work I do with the Digital Defence Alliance Singapore.

There is a reason this matters to us at CWG Innovations, beyond good citizenship. The very same trick, a convincing message that says “do this now”, is what fools an AI agent. Give an agent your inbox and your files, and an attacker no longer has to break in. They just leave instructions it will read and obey. That is exactly what we built RealRelay.ai to defend against. Security is not bolted on after the agent is built. It is tested continuously inside the platform, by an agent that thinks like an attacker within the limits you set.

Scam calls, spoofed apps, autonomous agents. The channel keeps changing, but the discipline does not. Assume you will be targeted, make the easy attacks hard, and never hand your judgement to a stranger on the phone, or to a machine.

Aaron

The Straits Times · CNA

On how easily NRIC numbers could be pulled from a public portal

For years we treated the NRIC number like a secret. It never really was. Once a number can be looked up, it stops being proof of anything and becomes just another detail an attacker can quote back to you to sound convincing. What worried me then, and still does, is the imagination of the person on the other end.

That thinking runs through how we build at CWG. Assume your identifiers will leak, and design so that knowing them is nowhere near enough to get in. On RealRelay.ai it shows up as agents being tested continuously, never trusted just because a request happens to look legitimate.

The Straits Times

On how ordinary telco technical data helps an attacker

I described the exposed technical data as the blueprints and the guard schedules of a building. Any single detail looks harmless. Put them together and you have told an attacker where the doors are and when nobody is watching. AI only makes that assembly faster, which is why context is now more dangerous than any one secret.

We plan for exactly that. Least privilege between every agent, model and dataset, so one leaked detail never quietly unlocks the whole floor.

The Straits Times

On the telco outage and the emergency hotline

When the network fell over, the detail that stayed with me was the emergency hotline. Resilience is not the backup you own. It is the switchover you have actually practised. AI is no different. Standing up an impressive agent is easy; proving it fails safely when something breaks is the hard part, and the part that matters.

That is the question we keep asking at CWG. Not only does it work, but what happens on its worst day.

Mothership

On the eSIM takeover that needed no hacking at all

No system got hacked in that story. A person did. The attacker never beat the technology, they simply talked their way past a process, and a one-time password handed over in a chat throws away the whole reason you had one. It is the oldest lesson in security and the one I still teach most often. The human step is usually the real target.

It is also why RealRelay.ai treats an AI agent as something that can be talked into things, and checks what it is about to do instead of trusting the instruction it was handed.

Building AI you can actually trust

If secure, sovereign-ready AI is on your agenda, we should talk.