Cyber threats across the Philippines reached a new level during the first half of 2026 as cybercriminals intensified attacks through data breaches, credential theft, ransomware, and AI-driven fraud.
According to the latest Cyber Threat Landscape Report from Viettel Cyber Security (VCS), increasingly coordinated campaigns are exploiting software vulnerabilities, stolen credentials, and artificial intelligence to target critical industries and everyday users. Among the report’s key findings were 16,619 phishing attacks and 21 ransomware incidents, with finance, hospitality, logistics, manufacturing, and energy among the sectors most affected. The report also identified 34,650 new vulnerabilities during the six-month period, including 77 high-impact vulnerabilities affecting products and services used in the Philippines.
Millions of credentials compromised
Viettel Threat Intelligence, VCS’s cyber threat monitoring platform, tracked the country’s cybersecurity landscape from January to June 2026. It found that more than 19.2 million credentials were compromised during the period. VCS also recorded 255 data breach incidents, exposing approximately 335 million records and 2.6 terabytes of data. Together, these findings point to an increasingly complex threat landscape in which attackers combine several techniques to expand the reach and impact of their campaigns.
High-profile attacks target sensitive sectors
The first half of 2026 saw several high-profile cyber incidents across the education, public, and financial sectors, highlighting a shift toward more coordinated attacks against organizations that manage sensitive data and critical services. Among the most significant incidents, coordinated attacks against financial institutions between March and April compromised around 99 million records. A separate breach affecting a public-service organization exposed another 45 million records.
In another major incident, threat actors exfiltrated approximately 1.8TB of confidential internal data from financial institutions after deploying malicious payloads within enterprise systems. Many of these attacks were enabled by known software vulnerabilities. Viettel Threat Intelligence identified 77 high-impact vulnerabilities affecting products and services widely used in the Philippines, underscoring how unpatched systems continue to provide entry points for targeted cyber campaigns.
Compliance measures strengthen cybersecurity readiness

In response to the evolving threat landscape, financial institutions have been required to comply with enhanced security requirements under the Bangko Sentral ng Pilipinas’ Anti-Financial Account Scamming Act.
The Department of Information and Communications Technology has also expanded initiatives such as the DICT Trusted Assessment Providers program and the Cybersecurity Posture Assessment Laboratory to strengthen cybersecurity readiness across government agencies and critical infrastructure.
However, VCS said compliance alone is no longer sufficient. Organizations also need continuous threat intelligence and real-time monitoring to detect and contain attacks before they escalate.
The report further showed that cybercriminals are increasingly combining phishing, vulnerability exploitation, and AI-enabled social engineering.
Smarter scams raise the stakes
Rather than relying only on technical weaknesses, many cybercriminal campaigns are increasingly targeting human trust. The combination of leaked personal information and generative AI allows attackers to create highly personalized scams. The report logged 16,619 phishing attempts nationwide, including familiar messages falsely warning users that their account has been locked and directing them to click a link.
VCS warned that the greater risk now lies in AI-generated deepfake voices and videos capable of impersonating bank personnel, government officials, or relatives. These techniques can manipulate victims into revealing one-time passwords or authorizing fraudulent transactions.
Romance scams, fake recruitment schemes, and delivery fraud using leaked personal data are also rising. At the same time, espionage-linked groups are quietly targeting public services, healthcare organizations, and technology companies.
AI becomes an operational cybercrime tool
The report indicates that artificial intelligence is no longer merely an emerging threat. It has become an operational tool increasingly used by cybercriminals.
By combining generative AI with stolen credentials and leaked personal information, attackers can automate phishing campaigns, produce convincing deepfake content, and launch highly personalized social engineering attacks at scale.
As these capabilities develop, AI-enabled cyber threats are expected to become increasingly difficult to detect.
Staying safe and alert
VCS recommends that individuals remain cautious of unsolicited calls or messages claiming to come from banks or government agencies, particularly those requesting one-time passwords.
Users should verify such requests through official channels before taking any action.
For organizations, VCS recommends integrating threat intelligence into security operations, strengthening continuous vulnerability management, and investing in employee awareness.
Together, these measures can help organizations build a more resilient cybersecurity posture as global cyber threats continue to evolve.