Table of Contents
The NPC cybersecurity incidents data obtained through a Freedom of Information request reveals a trajectory that every Filipino with a digital identity needs to understand: reported cybersecurity incidents in the Philippines nearly doubled from 183 cases in 2019 to 345 cases in 2025. That is the National Privacy Commission’s own data — not a private security firm’s estimate, not a foreign intelligence assessment, but the official count of incidents reported to the Philippine government’s privacy regulator. The number does not include unreported incidents, which cybersecurity experts estimate could be 5-10 times higher. When the NPC’s numbers double, the real number is likely far worse. And the trends driving this increase — AI-powered phishing, supply chain attacks, and deepfake-driven fraud — are accelerating, not slowing down.
Key Takeaway
- Official incidents nearly doubled: NPC data shows 183 reported cybersecurity incidents in 2019 rising to 345 in 2025 — an 89% increase over six years. This is the official count only; actual incidents are estimated to be 5-10x higher.
- 34,839 phishing attacks in 2025 alone: Viettel Threat Intelligence recorded 34,839 phishing incidents in the Philippines in 2025 — roughly 95 per day. AI-driven social engineering campaigns are making these attacks more personalized and harder to detect.
- 100% of PH organizations hit via supply chain: BlueVoyant’s 6th annual report found that every surveyed organization in the Philippines experienced cybersecurity incidents linked to supply chain vulnerabilities. This is a systemic problem, not an isolated one.
- NPC issued new 2026 advisories: The NPC released Advisory No. 2026-01 on data scraping of publicly available personal data and Advisory No. 2026-02 on data breach notification procedures — tightening rules that organizations must follow.
- Every Filipino is affected: With 228 million credentials exposed in 2025 and 1.3 million breached accounts (3 per minute), the average Filipino’s digital identity — GCash, social media, government IDs, bank accounts — is under sustained attack.
The NPC Data: What the Numbers Show
The NPC cybersecurity incidents data was obtained through a Freedom of Information request filed by the Deep Web Konek (DWK) Team. The data provides an official overview of reported cybersecurity incidents submitted to the National Privacy Commission between 2019 and 2025. This is the most authoritative dataset available on the Philippine cybersecurity threat landscape — because it comes from the government agency mandated to receive and process these reports under the Data Privacy Act of 2012.
| Year | Reported Incidents | Trend |
|---|---|---|
| 2019 | 183 | Baseline |
| 2020 | ~200 (estimated) | Pandemic digital surge |
| 2021-2024 | Gradual increase | Rising digital adoption |
| 2025 | 345 | +89% from 2019 |
Why did incidents nearly double? Three structural forces are driving the increase — and none of them are going away.
Why NPC Cybersecurity Incidents Doubled: Three Forces
Force 1: Rapid Digital Adoption Outpacing Security Maturity
The Philippines underwent a massive digital transformation between 2019 and 2025. GCash grew from a niche e-wallet to a dominant finance superapp with millions of users. The BSP’s financial inclusion push brought millions of previously unbanked Filipinos into the digital financial system. Government services moved online — from SSS contributions to PhilHealth claims to passport renewals. Every new digital account is a new attack surface. When millions of Filipinos open their first digital accounts in a few years, the number of potential targets multiplies faster than security awareness can keep up.
The Philippine Security Summit and data from Viettel Threat Intelligence confirm this: data breaches in 2025 exposed over 228 million credentials and 1,382 GB of data across 266 incidents. Surfshark’s analysis found 1.3 million breached Philippine accounts — 3 accounts hacked every minute. These are not abstract statistics. Each compromised credential is a Filipino whose personal data is now in the hands of criminals who can use it for identity theft, financial fraud, or selling on the dark web.
Force 2: AI-Powered Attacks Getting Smarter
The same AI revolution that is transforming Philippine BPO work is also transforming cybercrime. The Philippine Security Summit’s 2025-2026 threat analysis identifies AI-driven social engineering campaigns as a growing threat. These are not the crude phishing emails of 2019 — badly spelled messages from “Nigerian princes.” AI-powered phishing can generate personalized, grammatically perfect messages in Tagalog, English, or Cebuano that reference the target’s real employer, real bank, and real transactions.
Smishing attacks — SMS phishing — have also grown. A Filipino receives a text message that appears to come from GCash, Maya, or BDO, warning of a “suspended account” and linking to a fake login page. The page looks identical to the real one. The Filipino enters their credentials. The attacker now has access to their e-wallet or bank account. This is happening thousands of times per day — 34,839 phishing incidents were recorded in 2025 alone, roughly 95 per day.
The cybersecurity guide for Filipinos and OFWs we published earlier this year documented 7,914 phishing incidents in early 2026 alone — showing the pace is accelerating, not slowing.
Force 3: Supply Chain Attacks — Your Security Is Only as Strong as Your Weakest Vendor
The most alarming finding is from BlueVoyant’s 6th annual State of Supply Chain Defense Report: 100% of organizations in the Philippines experienced cybersecurity incidents linked to supply chain vulnerabilities. This means every company surveyed — not some, not most, but all — was negatively impacted by a security weakness in a vendor, supplier, or partner.
What does a supply chain attack look like for the average Filipino? Imagine a company that processes your credit card payments. That company uses a third-party software vendor for its payment system. The software vendor gets hacked. The attacker now has access to every company that uses that software — including the one processing your credit card. You did nothing wrong. The company you trusted did nothing wrong. But the vendor’s security failure became your problem.
This is why the NPC cybersecurity incidents data nearly doubled: the attack surface is no longer just your own accounts. It is every company you interact with, and every vendor those companies interact with. The supply chain cybersecurity crisis is not a future prediction — it is the present reality for every Filipino with a digital footprint.
NPC 2026 Advisories: What Changed and What It Means for You
The National Privacy Commission did not just collect data — it acted. In 2026, the NPC issued two significant advisories that change how organizations must handle personal data in the Philippines.
Advisory No. 2026-01: Data Scraping of Publicly Available Personal Data
The NPC issued guidelines on the lawful scraping of publicly available personal data. This matters because AI companies are scraping massive amounts of personal data from social media, public records, and websites to train their models. If your Facebook profile, LinkedIn history, or government records are publicly accessible, they may have been scraped into AI training datasets without your knowledge.
The advisory emphasizes compliance with the Data Privacy Act of 2012 — meaning organizations that scrape personal data must have a legal basis, must inform data subjects, and must protect the data they collect. For the average Filipino, this means the NPC is pushing back against the uncontrolled harvesting of your personal information by AI companies and data brokers.
Advisory No. 2026-02: Data Breach Notification Procedures
The NPC tightened data breach notification rules. Under the new advisory, the full breach report is due within five days from the date of discovery — regardless of any pending request for postponement or exemption. The NPC’s silence on a submitted request cannot be treated as approval. This closes a loophole where organizations delayed breach notifications while waiting for NPC responses to exemption requests.
For the average Filipino, this means you should be notified faster when a company you trust suffers a data breach. If your bank, your e-wallet, or your healthcare provider is hacked, they cannot sit on the information for weeks while negotiating with the NPC. They have five days to report — and the clock starts when they discover the breach, not when they finish investigating.
What Every Filipino Must Do Right Now
The NPC cybersecurity incidents data is not a government report to file and forget. It is a warning that every Filipino’s digital identity is under attack — and the attacks are getting more sophisticated. Here is what you should do.
1. Enable two-factor authentication on every account. GCash, Maya, BDO, BPI, Facebook, Google, Apple ID — every account that offers 2FA should have it enabled. This is the single most effective defense against credential theft. When an attacker steals your password, they still cannot access your account without the second factor.
2. Never click links in SMS or email messages. If you receive a text claiming your GCash account is suspended, do not click the link. Open the GCash app directly. If you receive an email claiming your bank account is locked, do not click the link. Go to the bank’s website directly by typing the URL. AI-powered phishing makes fake messages indistinguishable from real ones — but the links always lead to fake sites.
3. Check if your credentials have been breached. Go to Have I Been Pwned and enter your email address. The site will tell you if your credentials have appeared in known data breaches. If they have, change your password immediately — and do not reuse that password anywhere else.
4. Use a password manager. The average Filipino has 10-20 digital accounts. You cannot remember 20 unique, strong passwords. A password manager (Bitwarden, 1Password, or even your browser’s built-in manager) generates and stores unique passwords for every account. When one account is breached, the attacker cannot use those credentials to access your other accounts.
5. Monitor your financial accounts. Check your GCash, bank, and credit card transactions weekly. If you see a transaction you did not make, report it immediately. The Philippine data breach crisis means your financial data may already be compromised — the question is whether you catch the fraud before it drains your account.
What This Means for Philippine Businesses
For Philippine businesses, the NPC cybersecurity incidents data and the new 2026 advisories create both obligations and opportunities.
The obligation: Under the Data Privacy Act, organizations must report security incidents to the NPC. The new advisory tightens the timeline to five days. Organizations that fail to report face compliance orders, fines, and reputational damage. The BusinessWorld Cybersecurity Summit 2026 documented that data breach notifications rose 40% in Q1 2026 compared to Q1 2025 — meaning more organizations are reporting, but also that more breaches are happening.
The opportunity: Organizations that invest in cybersecurity — vendor risk management, zero-trust frameworks, employee training, and AI-powered threat detection — will be the ones that survive the next wave. The cybersecurity skills gap means qualified security professionals are in high demand. Companies that build security into their operations rather than bolting it on after a breach will have a competitive advantage in a market where trust is becoming the most valuable currency.
The Bigger Picture: Cybersecurity as National Security
The NPC cybersecurity incidents data does not exist in a vacuum. It connects to a broader national security picture that every Filipino should understand.
The Philippine military’s cyber command chief confirmed in February 2026 that the Philippines continues to face cyberattacks from China, linked to the West Philippine Sea territorial dispute. DICT Secretary Ivan Uy described the escalating cyber threats as part of a global arms race: “World War III is happening and it is cyber. These weapons are non-kinetic. They are cyber, digital, virtual, but it’s happening.”
This means the NPC cybersecurity incidents data is not just about criminals stealing credit card numbers. It includes state-sponsored attacks targeting government systems, intelligence data, and critical infrastructure. Advanced Persistent Threats (APTs) have repeatedly attempted to infiltrate Philippine government systems — and while the country’s cyber defenses have held firm so far, the attacks are persistent and escalating.
For the average Filipino, this means cybersecurity is not just a personal responsibility — it is a national one. Every compromised account, every breached database, every successful phishing attack weakens the country’s overall digital defenses. The Filipino who enables 2FA and uses a password manager is not just protecting their own GCash account — they are reducing the attack surface that state-sponsored actors exploit.
Frequently Asked Questions About NPC Cybersecurity Incidents
What are NPC cybersecurity incidents?
NPC cybersecurity incidents are security breaches and data privacy incidents reported to the National Privacy Commission of the Philippines under the Data Privacy Act of 2012. The NPC’s data shows reported incidents increased from 183 in 2019 to 345 in 2025 — an 89% increase. These include data breaches, phishing incidents, ransomware attacks, unauthorized access, and supply chain compromises.
Why did NPC cybersecurity incidents nearly double from 2019 to 2025?
Three forces drove the increase: rapid digital adoption that outpaced security maturity (millions of new digital accounts creating new attack surfaces), AI-powered attacks becoming more sophisticated and personalized, and supply chain attacks where 100% of Philippine organizations were impacted by vendor vulnerabilities. The actual number of incidents is likely 5-10x higher than reported, as many incidents go unreported.
What are the NPC’s new 2026 advisories?
The NPC issued Advisory No. 2026-01 on data scraping of publicly available personal data, requiring organizations that scrape personal data to comply with the Data Privacy Act. Advisory No. 2026-02 tightened data breach notification procedures, requiring full breach reports within five days of discovery regardless of pending exemption requests. The NPC’s silence on requests cannot be treated as approval.
How many phishing attacks happened in the Philippines in 2025?
Viettel Threat Intelligence recorded 34,839 phishing attacks in the Philippines in 2025 — approximately 95 per day. Data breaches exposed over 228 million credentials across 266 incidents. Surfshark analysis found 1.3 million breached Philippine accounts, equivalent to 3 accounts hacked every minute. Ransomware attacks reached 22 reported incidents in 2025.
What should Filipinos do to protect themselves from cybersecurity incidents?
Filipinos should: enable two-factor authentication on all accounts, never click links in SMS or email messages (go directly to the app or website), check if their credentials have been breached at HaveIBeenPwned.com, use a password manager for unique passwords, and monitor financial accounts weekly for unauthorized transactions. These five steps address the most common attack vectors identified in the NPC data.
Are Philippine government systems being targeted by foreign cyberattacks?
Yes. The Philippine military’s cyber command chief confirmed in February 2026 that the Philippines continues to face cyberattacks from China, linked to the West Philippine Sea dispute. DICT Secretary Ivan Uy described these as part of a global cyber arms race. Advanced Persistent Threats have repeatedly attempted to infiltrate government systems, though Philippine cyber defenses have held firm so far.
What is the supply chain cybersecurity crisis in the Philippines?
BlueVoyant’s 6th annual report found that 100% of surveyed organizations in the Philippines experienced cybersecurity incidents linked to supply chain vulnerabilities. This means every company was negatively impacted by a security weakness in a vendor, supplier, or partner. Supply chain attacks exploit the fact that your security is only as strong as your weakest vendor — making vendor risk management essential for every Philippine business.
This article is for informational purposes only and does not constitute legal, cybersecurity, or professional advice. Cybersecurity threat data is based on reported incidents and may not reflect the full scope of unreported incidents. Always consult qualified cybersecurity professionals and refer to official NPC communications for current regulatory requirements.





