Philippines — Cyber threats across the Philippines intensified in the first half of 2026, with more than 19.2 million credentials compromised alongside hundreds of data breaches, according to a report by Viettel Cyber Security (VCS).
According to the latest Cyber Threat Landscape Report, based on monitoring by VCS’ Viettel Threat Intelligence platform from January to June 2026, there were 255 data breach incidents that exposed approximately 335 million records and 2.6 terabytes of data.
There were also 16,619 phishing attacks and 21 ransomware incidents recorded in the report during the six-month period. The finance, hospitality, logistics, manufacturing, and energy sectors were among those most affected.
The report identified 34,650 new vulnerabilities during H1 2026, including 77 high-impact vulnerabilities affecting products and services widely used in the Philippines.
High-profile breaches
Several major incidents during the period affected organisations in the education, public and financial sectors, highlighting what VCS described as increasingly coordinated attacks against organisations handling sensitive information and critical services.
Coordinated attacks against financial institutions between March and April compromised around 99 million records, while a separate breach involving a public-service organisation exposed a further 45 million records.
In another incident, threat actors reportedly exfiltrated approximately 1.8 terabytes of confidential internal data from financial institutions after deploying malicious payloads within enterprise systems.
The exploitation of known software vulnerabilities played a role in many of these attacks, with the 77 high-impact vulnerabilities identified by its threat intelligence platform highlighting the risks posed by unpatched systems.
Financial institutions have also faced enhanced security requirements under the Bangko Sentral ng Pilipinas’ Anti-Financial Account Scamming Act (AFASA). Meanwhile, the Department of Information and Communications Technology (DICT) has expanded initiatives including the DICT Trusted Assessment Providers (DTAPs) programme and the Cybersecurity Posture Assessment Laboratory (CPAL).
Compliance measures alone are no longer sufficient, with organisations also requiring continuous threat intelligence and real-time monitoring to detect and contain attacks.
AI-enabled scams
The report found that phishing, vulnerability exploitation and AI-enabled social engineering are among the fastest-growing threats.
Of the 16,619 phishing attempts recorded nationwide, VCS noted that familiar scams, including messages claiming that a recipient’s account has been locked, continue to be used. However, the company warned that generative AI is enabling more convincing impersonation attempts using deepfake voices and videos.
These techniques can be used to impersonate bank employees, government officials or relatives in an effort to persuade victims to disclose one-time passwords (OTPs) or authorise fraudulent transactions.
The report also identified rising romance scams, fake recruitment schemes and delivery fraud involving leaked personal information. It said espionage-linked groups were also targeting public services, healthcare and technology companies.
It said AI is increasingly being used as an operational tool by cybercriminals, rather than simply representing an emerging threat. Generative AI can be combined with stolen credentials and leaked personal information to automate phishing campaigns, produce deepfake content and create more personalised social engineering attacks.
According to the report, it is expected that AI-enabled threats will become more difficult to detect as these capabilities develop.
Recommendations
The report advised individuals to be cautious of unsolicited calls and messages claiming to come from banks or government agencies, particularly when they request OTPs. It recommended verifying such requests through official channels before taking action.
For organisations, the company recommended incorporating threat intelligence into security operations, strengthening continuous vulnerability management and increasing employee cybersecurity awareness.
It also said these measures can help organisations strengthen their cybersecurity posture as they adopt new technologies amid an evolving cyber threat landscape.

