Insider Spotlight
The cybersecurity firm's latest Cyber Threat Landscape Report recorded 16,619 phishing attacks, 21 ransomware incidents and 255 data breaches nationwide between January and June.
The attacks exposed about 335 million records and 2.6 terabytes of data, while more than 19.2 million user credentials were compromised. Finance, hospitality, logistics, manufacturing and energy were among the hardest-hit industries.
Why it matters
The findings underscore the growing sophistication of cyberattacks in the Philippines as threat actors increasingly combine stolen credentials, software vulnerabilities and AI-enabled social engineering to maximize the scale and impact of attacks.
VCS also identified 34,650 new vulnerabilities globally during the period, including 77 high-impact cases affecting products and services widely used in the Philippines. The report said unpatched systems continue to provide critical entry points for attackers.
Among the most significant incidents were coordinated attacks on financial institutions between March and April that compromised around 99 million records.
A separate breach affecting a public-service organization exposed another 45 million records, while another attack exfiltrated about 1.8 terabytes of confidential internal data from financial institutions after malicious software was deployed inside enterprise systems.
The big picture
The report noted that Philippine authorities have strengthened cybersecurity measures through the Bangko Sentral ng Pilipinas' Anti-Financial Account Scamming Act and the Department of Information and Communications Technology's Trusted Assessment Providers and Cybersecurity Posture Assessment Laboratory initiatives.
However, VCS said regulatory compliance alone is no longer enough to counter evolving cyber threats.
The cybersecurity firm warned that generative AI is enabling criminals to automate phishing campaigns, create convincing deepfake voices and videos, and launch highly personalized scams using leaked personal information.
It added that organizations should integrate threat intelligence into security operations, strengthen vulnerability management and invest in employee awareness, while individuals should verify unsolicited requests through official channels and never disclose one-time passwords. —Vanessa Hidalgo| Ed: Corrie S. Narisma