Home BusinessFrom 16,619 phishing attacks to AI-driven fraud: cyber threats intensify across the Philippines in H1 2026

From 16,619 phishing attacks to AI-driven fraud: cyber threats intensify across the Philippines in H1 2026

by Contributor

MANILA, Philippines – Cyber threats across the Philippines reached a new level in the first half of 2026 as cybercriminals intensified attacks through data breaches, credential theft, ransomware and AI-driven fraud. According to the latest Cyber Threat Landscape Report released by Viettel Cyber Security (VCS), increasingly coordinated campaigns are exploiting software vulnerabilities, stolen credentials and artificial intelligence to target both critical industries and everyday users.

image.png

The number of compromised credentials in the Philippines over a 6-month period.

(Source: Viettel Threat Intelligence)

Viettel Threat Intelligence, VCS’s cyber threat monitoring platform, tracked the country’s cybersecurity landscape from January to June 2026 and found that more than 19.2 million credentials were compromised in H1 2026. VCS also recorded 255 data breach incidents, exposing roughly 335 million records and 2.6 terabytes of data. Together, these findings illustrate an increasingly complex threat landscape where attackers combine multiple techniques to maximize scale and impact.

High-Profile Incidents Reveal an Escalating Threat Landscape

The first half of 2026 saw a series of high-profile cyber incidents across the education, public, and financial sectors, highlighting a shift toward more coordinated attacks on organizations managing sensitive data and critical services.

Among the most significant incidents, coordinated attacks against financial institutions between March and April compromised around 99 million records, while a separate breach affecting a public-service organization exposed another 45 million records. In another major attack, threat actors exfiltrated approximately 1.8 TB of confidential internal data from financial institutions after deploying malicious payloads within enterprise systems.

Many of these attacks were enabled by the exploitation of known software vulnerabilities. Viettel Threat Intelligence identified 77 high-impact vulnerabilities affecting products and services widely used in the Philippines, underscoring how unpatched systems continue to provide critical entry points for increasingly targeted cyber campaigns.

image.png

Ratio of data breach incidents in the Philippines in H1 2026 by sector

(Source: Viettel Threat Intelligence)

In response to the evolving threat landscape, the financial institutions were required to comply with enhanced security requirements under the Bangko Sentral ng Pilipinas’ Anti-Financial Account Scamming Act (AFASA), while the Department of Information and Communications Technology (DICT) expanded initiatives such as the DICT Trusted Assessment Providers (DTAPs) program and the Cybersecurity Posture Assessment Laboratory (CPAL) to strengthen cybersecurity readiness across government agencies and critical infrastructure.

However, compliance alone is no longer sufficient. Organizations need continuous threat intelligence and real-time monitoring to detect and contain attacks before they escalate.

More importantly, the report shows that cybercriminals are increasingly combining multiple attack techniques, with phishing, vulnerability exploitation, and AI-enabled social engineering emerging among the fastest-growing threats.

Smarter Scams, Bigger Stakes

Rather than exploiting technical weaknesses, these campaigns increasingly target human trust. The combination of leaked personal data and generative AI enables attackers to create highly personalized scams. The report logged 16,619 phishing attempts nationwide, including the fake “your account is locked, click here” messages many Filipinos have started to recognize. VCS warns that the greater risk now lies in AI-generated deepfake voices and videos capable of impersonating bank staff, government officials, or even relatives. These impersonation techniques manipulate victims into revealing OTPs or authorizing fraudulent transactions. Additionally, romance scams, fake recruitment, and delivery fraud using leaked data are rising, alongside espionage-linked groups quietly targeting public services, healthcare, and tech firms.

AI Is Reshaping the Cyber Threat Landscape

The report indicates that AI is no longer an emerging threat but an operational tool increasingly adopted by cybercriminals. By combining generative AI with stolen credentials and leaked personal information, attackers can automate phishing campaigns, create convincing deepfake content, and launch highly personalized social engineering attacks at scale. As these capabilities continue to evolve, AI-enabled threats are expected to become increasingly difficult to detect.

Staying Safe and Sharp

As cybercriminals continue to develop more sophisticated methods, VCS recommends that individuals stay alert to unsolicited calls or messages claiming to be from banks or government, especially those asking for OTPs, and to verify such requests through official channels before taking action. For organizations, VCS recommends integrating threat intelligence into security operations, strengthening continuous vulnerability management, and investing in employee awareness. Together, these measures help organizations build a resilient cybersecurity posture for the secure and sustainable adoption of technology amid evolving global cyber threats.

To read the full report, visit https://viettelsecurity.com/resource-report/cyber-threat-landscape-in-the-philippines-h1-2026/.

You may also like

Verified by MonsterInsights