Manila, Philippines – Ransomware groups publicly claimed 31 attacks on Philippine organisations between January and August 2026, more than the 26 claims recorded across 2024 and 2025 combined, according to a report from Check Point Software Technologies.
The report analyses cyber activity over those eight months. It draws on telemetry from monitored Philippine organisations, intelligence from open-source, deep web, and dark web environments, and activity publicly claimed by threat actors.
The rise in ransomware was not limited to volume. Fifteen distinct groups posted claims against local organisations this year, compared with 12 in all of 2025, and ten of them appeared in the local dataset for the first time.
Qilin remained the most active group, accounting for 29% of claims in 2026, up from 23% in 2025. In addition, eight sectors, including government, business services and critical infrastructure, were targeted after recording no claims in the same period of 2025.
The impact varied by sector. Government agencies recorded the highest overall number of attacks, at 72 incidents, but these were mostly website defacements and disruptions to information systems.
Financial institutions faced fewer incidents but more serious ones. More than half of their recorded cases involved ransomware, data breaches or leaks.
Stolen data was another major concern, with the report tracking 24,875 data exposure cases. Nearly 44% originated from malware that quietly collected login credentials from infected devices, and customer passwords and credit card data made up most of the leaked information.
Exposed payment card data accounted for almost 24% of cases. A further 10% involved employee credentials leaked through third-party platforms, which heightened the risks from credential theft, weak access controls and exposed supply chains.
Such stolen information feeds directly into phishing, which held steady at 2,386 alerts but changed in method. Attackers moved away from intercepting one-time passwords (OTPs) and instead used fake reward points and loyalty programme updates to obtain personal information and payment card details.
Phishing alerts peaked at 518 in January and dropped to a low of 117 in May. The report suggested the fall may reflect enforcement of BSP Circular No. 1213.
Criminals also exploited trust on social media, where the report logged 1,194 impersonation alerts. Company impersonation made up 972 of these (81.4%), while executive impersonation accounted for 222 (18.6%).
Facebook was involved in four out of five cases, and TikTok was heavily used to impersonate executives. Threat actors mimicked executives and official brand accounts to make fraudulent messages appear credible.
Artificial intelligence (AI) played a similar role in deception. Cybercriminals used deepfake videos, cloned voices and AI applications to drive romance scams, investment fraud, and malware distribution, rather than to break directly into technical networks.
This concludes that cyber threats in the Philippines were driven less by new attack methods than by easier access to proven tools, stolen credentials, and AI-enabled deception. Abuse of identity and trust underpinned attacks ranging from phishing to ransomware.
The report advises organisations to prioritise threats by their potential business impact rather than by volume. It also recommends phishing-resistant multi-factor authentication (MFA), audits of internet-facing systems, closer monitoring of third-party access, and governance of enterprise AI tools.

