SPECIAL FEATURE | Ransomware claims surge in the Philippines

0

Fifteen ransomware groups posted claims involving Philippine organizations during the period, compared with 12 across all of 2025.

cyber 2026-10-07 at 11.03.00 PM

Cybersecurity activity affecting Philippine organizations increased in several high-impact areas during the first eight months of 2026, with ransomware claims more than doubling from the comparable period in 2025 and data exposure reaching nearly 25,000 cases, according to the 2026 Philippine Threat Landscape Report by Check Point Exposure Management.

The report recorded 264 cyber incidents affecting Philippine organizations from January to August 2026. Website defacement and information-system disruption accounted for 216 incidents, while ransomware, breaches and data leaks accounted for 48. Government agencies recorded the highest overall incident volume, while financial services had the highest concentration of ransomware, breach and data-leak activity.

“Volume and risk pointed in different directions in the Philippines,” the report said.

Ransomware activity accelerates

Ransomware showed the sharpest change in the report. Check Point tracked 31 public ransomware claims involving Philippine organizations during the first eight months of 2026, already exceeding the combined 26 claims recorded during 2024 and 2025.

Fifteen ransomware groups posted claims involving Philippine organizations during the period, compared with 12 across all of 2025. Ten of the groups appeared in the Philippine dataset for the first time in 2026.

The report said the increase appeared to be driven less by new attack techniques than by broader participation and the availability of existing access.

“The character of the threat, however, changed less than the volume,” the report said. “What changed was throughput and participation.”

August was particularly active, accounting for nine ransomware claims, nearly twice the previous monthly high of five. The report noted that every month from January through August exceeded or matched the 2025 monthly average of about 1.4 claims.

Finance and Business Services each recorded six claims, followed by Retail with five. Business Services, Government, Automotive, Transportation, Critical Infrastructure, Education, Mining and Technology recorded ransomware claims in 2026 after recording none during the comparable period in 2025. Telecommunications recorded one claim in both periods.

Qilin accounted for nine Philippine claims and increased its share of local claims from 23% in 2025 to 29% in 2026. The report said its increased presence reflected the scale of its affiliate base rather than a specific focus on the Philippines.

Despite the sharp increase, the Philippines remained relatively low in absolute ransomware volume compared with other monitored APAC markets, ranking 10th among 11 markets tracked by Check Point. 2026_Philippine_Threat_Landscap…

Data exposure and identity abuse

The report identified 24,875 cases of exposed data among monitored Philippine organizations during the first eight months of the year, equivalent to roughly 102 cases per day.

Customer credentials represented the largest category at 41.9% of observed exposure cases, followed by payment card data at 23.6% and employee credentials leaked through third-party platforms at 10.3%. Information-stealer logs accounted for almost 44% of observed exposed-data cases.

The report also recorded 1,194 social media impersonation alerts, including 972 involving companies and 222 involving executives. The number was 6% higher than the 1,124 alerts recorded during the same January-to-August period in 2025.

Facebook accounted for four out of every five identified impersonation cases. TikTok was the second-most targeted platform, while LinkedIn represented a smaller share but showed a stronger association with executive and senior-professional impersonation. 2026_Philippine_Threat_Landscap…

The report linked these attacks to a broader abuse of identity and trust rather than dependence on newly discovered technical vulnerabilities.

AI used mainly for deception

AI-related threats affecting Filipinos during the reporting period were concentrated on fraud and social engineering.

The report identified deepfake investment schemes, voice cloning, manipulated video calls and counterfeit AI applications used to distribute malware. However, it found no evidence that AI had been used to gain technical access to a Philippine organization during the period reviewed.

“The activity reviewed did not show AI being used to gain technical access to a Philippine organization,” the report said. “The evidence therefore points to an immediate deception risk, while more technical uses remain a forward-looking concern.”

The report also warned that fake versions of popular AI applications had been used to distribute remote-access trojans and information stealers. Installing such applications on work devices could expose credentials, session tokens, files and corporate-system access.

Govt, financial sectors face different risks

Government agencies recorded 72 of the 264 incidents in the dataset, the highest total among sectors. Much of the activity involved website defacement and information-system disruption, but government also recorded the highest absolute number of ransomware, breach and data-leak incidents.

Financial Services, meanwhile, accounted for a smaller share of total incidents but had the highest concentration of ransomware, breach and data-leak activity. More than half of its recorded incidents fell into those categories, according to the report.

The report recommended that organizations prioritize potential business impact rather than simply counting incidents, while treating identity and session exposure as continuous risks. It also called for stronger controls around common intrusion paths, ongoing third-party governance, tighter governance of enterprise AI and the conversion of threat intelligence into defined response actions.

“Identity and trust formed the common thread across the report,” the report said in its conclusion, pointing to the links among phishing, credential theft, fraud, impersonation, data exposure and ransomware.


Full disclosure: All news articles published on the TechSabado website are written by human journalists, unless otherwise specified. Final text editing is also performed by human editors, with artificial intelligence (AI) used only to assist with additional grammar and style guide corrections..


————————————————————————-
TEN YEARS OF TECHSABADO!


PLEASE LIKE our FACEBOOK PAGE and SUBSCRIBE to OUR YOUTUBE & SPOTIFY channels.



WATCH TECHSABADO ON OUR YOUTUBE CHANNEL:












WE ARE ALSO ON SPOTIFY



WATCH OUR OTHER YOUTUBE CHANNELS:




PLEASE LIKE our FACEBOOK PAGE and SUBSCRIBE to OUR YOUTUBE CHANNEL.

roborter
by TechSabado.com Research Team
Tech News Website at  | Website

Leave a Reply

Your email address will not be published. Required fields are marked *