CYBERSECURITY | Philippines logs 16,619 phishing attacks in H1 2026

Source: HID
Cyber threats intensified across the Philippines during the first half of 2026, with thousands of phishing attacks, ransomware incidents, data breaches, and AI-enabled fraud targeting businesses and consumers, according to a new report from Viettel Cyber Security (VCS).
The Cyber Threat Landscape Report for H1 2026 found that the Philippines recorded 16,619 phishing attacks and 21 ransomware incidents from January through June. The finance, hospitality, logistics, manufacturing, and energy sectors were among the hardest hit.
VCS said more than 19.2 million user credentials were compromised during the six-month period. The report also documented 255 data breach incidents that exposed about 335 million records and 2.6 terabytes of data, highlighting what researchers described as an increasingly complex cyber threat environment.
The report identified 34,650 new software vulnerabilities worldwide during the period, including 77 high-impact vulnerabilities affecting products and services used in the Philippines. According to VCS, attackers continue to exploit unpatched systems to gain unauthorized access to organizations.
Among the major incidents cited were coordinated attacks against financial institutions between March and April that reportedly compromised about 99 million records. Another breach involving a public service organization exposed around 45 million records. In a separate incident, attackers allegedly exfiltrated about 1.8 terabytes of confidential internal data from financial institutions after deploying malicious payloads within enterprise systems.
The report said cybercriminals are increasingly combining phishing, vulnerability exploitation, and artificial intelligence to improve the effectiveness of their attacks. AI-generated deepfake voices and videos are being used to impersonate bank employees, government officials, and even family members to persuade victims to disclose one-time passwords or authorize fraudulent transactions.
Other scams highlighted in the report include fake recruitment offers, romance scams, delivery fraud, and espionage-linked campaigns targeting public services, health care organizations, and technology companies.
VCS noted that financial institutions are now required to comply with enhanced cybersecurity measures under the Bangko Sentral ng Pilipinas’ Anti-Financial Account Scamming Act, while the Department of Information and Communications Technology continues to expand cybersecurity assessment initiatives for government agencies and critical infrastructure.
The company recommended that organizations strengthen vulnerability management, integrate threat intelligence into security operations, and improve employee cybersecurity awareness. It also advised consumers to verify unsolicited calls and messages through official channels and never share one-time passwords with unknown parties.
Full disclosure: All news articles published on the TechSabado website are written by human journalists, unless otherwise specified. Final text editing is partially assisted by artificial intelligence (AI).
————————————————————————-
TEN YEARS OF TECHSABADO!
PLEASE LIKE our FACEBOOK PAGE and SUBSCRIBE to OUR YOUTUBE & SPOTIFY channels.
WATCH TECHSABADO ON OUR YOUTUBE CHANNEL:
WE ARE ALSO ON SPOTIFY
WATCH OUR OTHER YOUTUBE CHANNELS:
PLEASE LIKE our FACEBOOK PAGE and SUBSCRIBE to OUR YOUTUBE CHANNEL.

