Philippines records 16,619 phishing attacks amid rise in AI-driven cyber threats

by

Ansherina Baes

-

2 hours ago

Philippines — Cyber threats across the Philippines intensified in the first half of 2026, with more than 19.2 million credentials compromised alongside hundreds of data breaches, according to a report by Viettel Cyber Security (VCS).

According to the latest Cyber Threat Landscape Report, based on monitoring by VCS’ Viettel Threat Intelligence platform from January to June 2026, there were 255 data breach incidents that exposed approximately 335 million records and 2.6 terabytes of data.

There were also 16,619 phishing attacks and 21 ransomware incidents recorded in the report during the six-month period. The finance, hospitality, logistics, manufacturing, and energy sectors were among those most affected.

The report identified 34,650 new vulnerabilities during H1 2026, including 77 high-impact vulnerabilities affecting products and services widely used in the Philippines.

High-profile breaches

Several major incidents during the period affected organisations in the education, public and financial sectors, highlighting what VCS described as increasingly coordinated attacks against organisations handling sensitive information and critical services.

Coordinated attacks against financial institutions between March and April compromised around 99 million records, while a separate breach involving a public-service organisation exposed a further 45 million records.

In another incident, threat actors reportedly exfiltrated approximately 1.8 terabytes of confidential internal data from financial institutions after deploying malicious payloads within enterprise systems.

The exploitation of known software vulnerabilities played a role in many of these attacks, with the 77 high-impact vulnerabilities identified by its threat intelligence platform highlighting the risks posed by unpatched systems.

Financial institutions have also faced enhanced security requirements under the Bangko Sentral ng PilipinasAnti-Financial Account Scamming Act (AFASA). Meanwhile, the Department of Information and Communications Technology (DICT) has expanded initiatives including the DICT Trusted Assessment Providers (DTAPs) programme and the Cybersecurity Posture Assessment Laboratory (CPAL).

Compliance measures alone are no longer sufficient, with organisations also requiring continuous threat intelligence and real-time monitoring to detect and contain attacks.

AI-enabled scams

The report found that phishing, vulnerability exploitation and AI-enabled social engineering are among the fastest-growing threats.

Of the 16,619 phishing attempts recorded nationwide, VCS noted that familiar scams, including messages claiming that a recipient’s account has been locked, continue to be used. However, the company warned that generative AI is enabling more convincing impersonation attempts using deepfake voices and videos.

These techniques can be used to impersonate bank employees, government officials or relatives in an effort to persuade victims to disclose one-time passwords (OTPs) or authorise fraudulent transactions.

The report also identified rising romance scams, fake recruitment schemes and delivery fraud involving leaked personal information. It said espionage-linked groups were also targeting public services, healthcare and technology companies.

It said AI is increasingly being used as an operational tool by cybercriminals, rather than simply representing an emerging threat. Generative AI can be combined with stolen credentials and leaked personal information to automate phishing campaigns, produce deepfake content and create more personalised social engineering attacks.

According to the report, it is expected that AI-enabled threats will become more difficult to detect as these capabilities develop.

Recommendations

The report advised individuals to be cautious of unsolicited calls and messages claiming to come from banks or government agencies, particularly when they request OTPs. It recommended verifying such requests through official channels before taking action.

For organisations, the company recommended incorporating threat intelligence into security operations, strengthening continuous vulnerability management and increasing employee cybersecurity awareness.

It also said these measures can help organisations strengthen their cybersecurity posture as they adopt new technologies amid an evolving cyber threat landscape.

Recognise the innovators redefining commerce at the Retail & E-commerce Excellence Awards Asia Pacific 2026! Taking place this December 2026, we celebrate the region’s most impactful retail strategies, standout e-commerce experiences, and forward-thinking leaders—submit your entries today!
Honour the women shaping the future of marketing and technology at the Empowered Women Awards 2026! This December 2026, we celebrate inspiring leaders, changemakers, and rising voices driving impact across the industry—submit your entries today!
Share

RECENT ARTICLES

AsiaPay and PGA Insurance expand digital payment options for policyholders
Forrester launches AI disruption model to map AI's impact across tech markets 
Philippines records 16,619 phishing attacks amid rise in AI-driven cyber threats
AI use among Hong Kong traders surges from 25% to 79% in a year
ShardLab invests in StoreHub to explore payments and rewards for merchants in Southeast Asia
Ellipse 3

RELATED ARTICLES

IMDA partners with Grab and RSM to expand AI, cybersecurity support for Singapore SMEs
Around 893 million phishing attempts blocked in 2024 amid rising cyber threats report_11zon
SEA records 41% rise in financial phishing attacks in 2024 compared to the previous year report_11zon
Ellipse 3

FEATURED ARTICLES

'Retail & E-Commerce Innovation Summit' returns for its 2nd edition in the Philippines — initial speaker lineup revealed
‘Retail & E-Commerce Excellence Awards Asia Pacific
EW2025_(UT)Launch Article_Feature Image_11zon

Subscribe to UpTech Media Newsletter

JOIN OUR NEWSLETTER

Subscribe to our newsletter to get the latest APAC marketing news.