Cyber threats intensified across the Philippines in H1 2026, according to a report from Viettel Cyber Security (VCS). The findings show thousands of phishing and ransomware cases exposing millions of records, with criminals now using AI to target both people and organizations.
VCS recorded 16,619 phishing cases and 21 ransomware incidents in the first half of the year. Data breaches reached 255 cases, leaking about 335 million records and 2.6 TB of sensitive data. More than 19.2 million credentials were stolen, affecting finance, healthcare, education, logistics, and public services.
Big breaches included banks losing 99 million records and a public-service attack exposing 45 million records. Hackers also stole 1.8 TB of confidential financial data. At the same time, 34,650 new vulnerabilities were found, with 77 considered high-risk across widely used products.
Generative AI and deepfakes are now being used for impersonation scams, making phishing and social engineering harder to spot. Criminals pretend to be bank staff or government officials to trick victims into sharing one-time passwords or personal details.
Government agencies are responding with stricter rules and expanded programs. The BSP rolled out the Anti-Financial Account Scamming Act, while the DICT expanded cybersecurity efforts through DTAPs and CPAL.
The rise in romance scams, fake recruitment, delivery fraud, and espionage-linked attacks shows that human trust is now the main target. VCS recommends that individuals stay alert to unsolicited calls or messages claiming to be from banks or the government, especially those asking for OTPs, and to verify such requests through official channels before taking action.
Also Read: 79% of ransomware attacks begin with stolen credentials, reports find
Cybersecurity in the Philippines will stay a major issue as AI-driven fraud grows, pushing both government and industry to strengthen defenses.






