The Philippines faced a sharp escalation in cyber threats during the first half of 2026, with data breaches, credential theft, ransomware, phishing, and AI-enabled fraud emerging as major concerns across industries.
According to the latest Cyber Threat Landscape Report from Viettel Cyber Security (VCS), more than 19.2 million credentials were compromised in the country from January to June 2026. Viettel Threat Intelligence, VCS’s cyber threat monitoring platform, also recorded 255 data breach incidents, exposing approximately 335 million records and 2.6 terabytes of data.
The report highlights an increasingly coordinated threat environment in which cybercriminals combine stolen credentials, software vulnerabilities, social engineering, and artificial intelligence to maximize the scale and impact of their attacks.
Financial and Critical Sectors Among Key Targets
Several high-profile incidents during the first half of the year demonstrated the growing sophistication of cyberattacks targeting organizations that manage sensitive information and essential services.
Coordinated attacks against financial institutions between March and April reportedly compromised around 99 million records, while a separate breach involving a public-service organization exposed another 45 million records. In another major incident, attackers reportedly extracted approximately 1.8 terabytes of confidential internal data from financial institutions after deploying malicious payloads within enterprise systems.
VCS also identified 34,650 new vulnerabilities during the first half of 2026, including 77 high-impact vulnerabilities affecting products and services widely used in the Philippines. The findings underscore the risks organizations face when vulnerabilities remain unpatched.
Finance, hospitality, logistics, manufacturing, and energy were among the sectors affected by the country’s cyber threat activity.
AI Makes Scams More Convincing
Beyond technical vulnerabilities, cybercriminals are increasingly exploiting human behavior and trust.
VCS recorded 16,619 phishing attacks across the Philippines during the six-month period. While familiar schemes such as fake account-lockout messages remain prevalent, the report warns that generative AI is making social engineering attacks increasingly sophisticated.
By combining leaked personal information with AI-generated content, attackers can create highly personalized messages, deepfake voices, and convincing videos designed to impersonate bank employees, government officials, or even family members.
These tactics can be used to persuade victims to disclose one-time passwords or authorize fraudulent transactions. Romance scams, fake recruitment offers, and delivery-related fraud using leaked information are also emerging threats, while espionage-linked groups continue to target sectors including public services, healthcare, and technology.
From Emerging Technology to Cybercrime Tool
The report notes that artificial intelligence is no longer simply an emerging cybersecurity concern. It is increasingly being used as an operational tool by cybercriminals.
Generative AI can help automate phishing campaigns, produce convincing impersonation materials, and tailor social engineering attacks using stolen credentials and personal information. As these capabilities improve, AI-assisted attacks could become increasingly difficult for individuals and organizations to identify.
The growing use of AI also highlights the need for organizations to look beyond traditional compliance measures. VCS emphasizes the importance of continuous threat intelligence and real-time monitoring to identify and contain attacks before they escalate.
Strengthening Cybersecurity Readiness
In response to the evolving threat environment, financial institutions have faced enhanced security requirements under the Bangko Sentral ng Pilipinas’ Anti-Financial Account Scamming Act (AFASA). Meanwhile, the Department of Information and Communications Technology has expanded cybersecurity initiatives, including the DICT Trusted Assessment Providers program and the Cybersecurity Posture Assessment Laboratory.
For individuals, VCS recommends remaining cautious when receiving unsolicited calls or messages claiming to come from banks or government agencies, particularly those requesting OTPs. Such requests should be verified through official channels before any action is taken.
For organizations, the cybersecurity firm recommends integrating threat intelligence into security operations, strengthening continuous vulnerability management, and investing in employee cybersecurity awareness.
As cybercriminals increasingly combine traditional attack methods with AI-powered tools, the report underscores the importance of building stronger defenses that can keep pace with a rapidly changing digital threat landscape.