Table of Contents
The Philippines recorded 16,619 phishing attacks, 255 data breaches, and 21 ransomware incidents in the first half of 2026, according to a new report by Viettel Cyber Security that reveals how artificial intelligence is fundamentally changing the cybercrime landscape. More than 19.2 million user credentials were compromised, 335 million records were exposed, and 2.6 terabytes of data were leaked across the country between January and June — numbers that dwarf the already alarming Q1 figures and confirm the Philippines phishing attacks crisis is accelerating, not stabilizing.
Key Takeaway
- Philippines phishing attacks doubled from Q1 to H1 2026: Q1 saw 7,914 phishing incidents; H1 reached 16,619 — meaning Q2 alone added nearly 9,000 attacks, the fastest quarterly acceleration on record.
- 19.2 million credentials compromised: Filipino usernames, passwords, and account details are now in criminal hands, fueling identity theft, account takeovers, and further scams.
- AI is the new attack weapon: Generative AI enables criminals to automate personalized phishing campaigns, create convincing deepfake voices and videos, and launch targeted scams using leaked personal data.
- Finance is the primary target: Coordinated attacks on financial institutions between March and April compromised approximately 99 million records — the largest single-sector breach in the report.
- Government response is strengthening but lagging: AFASA, BSP Circular 1213, and DICT initiatives are in place, but VCS warns that regulatory compliance alone is no longer enough to counter evolving AI-powered threats.
The H1 2026 Numbers: What the Data Shows
The Viettel Cyber Security (VCS) Cyber Threat Landscape Report for the Philippines, covering January through June 2026, documents a dramatic escalation across every category of cybercrime. Here is how Philippines phishing attacks and other threats compare to the Q1 2026 data we previously reported:
| Threat Category | Q1 2026 | H1 2026 (Full) | Q2 Addition |
| Phishing attacks | 7,914 | 16,619 | 8,705 |
| Data breaches | 108 | 255 | 147 |
| Ransomware incidents | 8 | 21 | 13 |
| Compromised credentials | 10.4 million | 19.2 million | 8.8 million |
| Records exposed | 624,400 accounts | 335 million records | Massive scale-up |
| Data leaked | Not reported | 2.6 terabytes | — |
The acceleration is the story. Q2 2026 alone added more Philippines phishing attacks (8,705) than the entire Q1 (7,914). Data breaches more than doubled. The scale of Philippines phishing attacks in H1 2026 means the threat is not stabilizing — it is accelerating. The 335 million records exposed represents a scale of data leakage that affects nearly every Filipino with a digital footprint — the Philippine population is approximately 115 million, meaning the exposed records outnumber the population by nearly three to one. Philippines phishing attacks are now the primary entry point for every other category of cybercrime documented in the report.
Among the most significant incidents detailed in the report were coordinated attacks on financial institutions between March and April that compromised approximately 99 million records. A separate breach affecting a public-service organization exposed another 45 million records. A third attack exfiltrated about 1.8 terabytes of confidential internal data from financial institutions after malicious software was deployed inside enterprise systems.
VCS also identified 34,650 new vulnerabilities globally during the period, including 77 high-impact cases affecting products and services widely used in the Philippines. The report emphasized that unpatched systems continue to provide critical entry points for attackers.
The AI Fraud Dimension: Why Philippines Phishing Attacks Are Getting Worse
The most alarming finding in the VCS report is not the raw numbers but the weapon behind them. Generative AI has transformed the economics and effectiveness of cybercrime in the Philippines. Here is how:
Automated personalized phishing: In the past, phishing emails were generic — “Dear customer, your account has been compromised.” In 2026, criminals use generative AI to craft personalized messages that reference the victim’s actual bank, recent transactions, and even local branch. The AI generates these at scale, sending thousands of customized lures simultaneously. This is why Philippines phishing attacks have doubled — the cost per attack has collapsed while the success rate has risen. A phishing email that took hours to craft manually can now be generated in seconds, customized for each recipient using data from previous breaches. The result is a flood of Philippines phishing attacks that are individually tailored, making them far more likely to bypass both technical filters and human suspicion.
Deepfake voice scams: The report highlights the use of AI-generated voice clones — the same threat we documented in our AI Voice Cloning Scam guide for OFWs. Criminals clone a family member’s voice from social media audio, call the victim’s family in the Philippines, and pretend the OFW relative is in trouble — requesting an urgent money transfer. AI makes these calls indistinguishable from the real person’s voice.
Social engineering at scale: The 19.2 million compromised credentials are not just used for direct account takeovers. Criminals feed this data into AI systems that analyze patterns, identify high-value targets, and generate targeted social engineering campaigns. A criminal who knows your bank, your transaction history, and your communication style can craft a scam that is extremely difficult to detect.
Combination attacks: The VCS report notes that threat actors increasingly combine stolen credentials, software vulnerabilities, and AI-enabled social engineering to maximize impact. A single attack might use a leaked password to access an account, AI-generated messages to trick the account holder into authorizing a transaction, and ransomware to prevent the bank from detecting the fraud until it is too late.
Which Industries Were Hit Hardest
The VCS report identifies finance, hospitality, logistics, manufacturing, and energy as the hardest-hit industries in the first half of 2026. Finance dominated both in frequency and severity:
| Industry | Impact | Key Finding |
| Finance | Critical | 99 million records compromised in Mar-Apr coordinated attacks; 1.8 TB data exfiltrated |
| Public services | Severe | 45 million records exposed in single breach |
| Hospitality | High | Customer data and payment credentials targeted |
| Logistics | High | Supply chain attacks using unpatched systems |
| Manufacturing | High | Ransomware targeting operational technology |
| Energy | Moderate | Infrastructure probing and vulnerability scanning |
What This Means for Filipino Professionals
The Philippines phishing attacks documented in this report are not abstract statistics. They represent real Filipinos — professionals, OFWs, students, business owners — whose personal data is now in criminal hands. Here is what the H1 2026 report means for each group:
For OFWs: The 19.2 million compromised credentials likely include yours if you use any Philippine banking or e-wallet platform. Criminals with access to your credentials can attempt account takeovers, impersonate you to your family, or use your data to craft AI-powered social engineering attacks. The deepfake voice threat is especially relevant — ensure your family knows to verify any emergency money request through a secondary channel. Read our BSP scam reimbursement guide to understand your rights if a bank’s failure leads to fraud.
For businesses: If your organization operates in finance, hospitality, logistics, or manufacturing, you are in the crosshairs. The VCS report makes clear that regulatory compliance alone is insufficient. Businesses need threat intelligence integrated into security operations, proactive vulnerability management, and employee awareness training. The 77 high-impact vulnerabilities affecting Philippine systems mean patching is not optional — it is survival.
For individual professionals: Change your passwords. Enable multi-factor authentication on every account. The 19.2 million compromised credentials are being actively traded on dark web markets. If you have not changed your banking password in the last six months, assume it is compromised. Use a password manager, enable biometric authentication where available, and never share OTPs — even if the request sounds legitimate.
The Government Response: AFASA and Beyond
The VCS report acknowledges that Philippine authorities have strengthened cybersecurity measures through two key initiatives: the Bangko Sentral ng Pilipinas‘ Anti-Financial Account Scamming Act (AFASA) and the DICT’s Trusted Assessment Providers and Cybersecurity Posture Assessment Laboratory. According to CYFIRMA’s Philippines threat analysis, the government has taken meaningful steps to strengthen cybersecurity policy, but the overall risk environment remains elevated due to legacy systems, supply-chain dependencies, and expanded online services.
AFASA, which took full effect on June 30, 2026, requires all BSP-supervised financial institutions to implement multi-factor authentication, real-time fraud management systems, and mandatory transaction freezing. The PNP has already filed over 500 cases under AFASA in its first year. However, VCS warned that regulatory compliance alone is no longer enough to counter evolving cyber threats — particularly AI-powered attacks that move faster than regulatory cycles.
The DICT’s initiatives, including the eGovPH platform and the Cybersecurity Posture Assessment Laboratory, represent infrastructure-level responses. The government has also committed PHP 2.6 billion to AI projects by 2028, some of which will support cybersecurity capabilities. But the gap between threat capability and defensive capability is widening, not narrowing.
For more on the government’s cybersecurity response, see our coverage of the NPC cybersecurity incidents doubling to 345 cases and the AI Kill Switch Act.
What You Should Do Right Now: 5 Essential Steps
- Change your banking and e-wallet passwords immediately. With 19.2 million credentials compromised, assume yours is among them. Use a unique, strong password for each financial account. A password manager like Bitwarden (free, open-source) or 1Password (paid, premium) can generate and store unique passwords for every account, eliminating the risk of credential reuse across platforms.
- Enable biometric authentication. If your bank supports fingerprint or facial recognition login, enable it now. SMS OTPs are no longer sufficient against AI-powered phishing. Under BSP Circular 1213, banks are required to move away from SMS OTPs for high-risk transactions — but if your bank has not yet made the switch, you should still enable biometric authentication in the bank’s mobile app wherever it is offered. This is your strongest defense against Philippines phishing attacks that target OTP interception.
- Educate your family about deepfake voice scams. Agree on a code word or secondary verification method for any emergency money request. AI can clone voices — it cannot clone your family’s knowledge of a shared secret. If someone calls claiming to be your OFW relative in distress and asking for money, verify through a different channel: call them back on their known number, send a text message, or ask a question only the real person would know. The deepfake voice scam is the most emotionally manipulative of the AI-powered threats, and it preys on the trust between OFWs and their families.
- Patch your systems. If you run a business, the 77 high-impact vulnerabilities affecting Philippine systems are your problem. Update all software, especially in finance, hospitality, and logistics. The VCS report identified 34,650 new vulnerabilities globally, with 77 specifically affecting products and services widely used in the Philippines. Unpatched systems are the entry point that criminals exploit after credentials are stolen — closing that gap is as important as changing passwords.
- Monitor your accounts for unusual activity. Set up transaction alerts on every banking and e-wallet app. Report any unauthorized transaction within 72 hours to maximize recovery chances under AFASA. The BSP’s Consumer Complaints Resolution Office can adjudicate claims up to ₱10 million — a process that takes months, not years. If your bank failed to implement the required fraud-prevention measures by the June 30, 2026 deadline, the bank is liable for your losses. Read our BSP scam reimbursement guide to understand your full rights under the law.
Frequently Asked Questions
How many Philippines phishing attacks happened in H1 2026?
The Philippines recorded 16,619 phishing attacks in the first half of 2026, according to Viettel Cyber Security. This doubled from 7,914 in Q1 to 16,619 by mid-year, meaning Q2 added 8,705 attacks — the fastest quarterly acceleration on record.
What is causing the surge in Philippines phishing attacks?
The primary driver is generative AI. Criminals use AI to automate personalized phishing campaigns, create convincing deepfake voices and videos, and launch targeted scams using the 19.2 million compromised credentials circulating on dark web markets. AI has collapsed the cost per attack while increasing the success rate.
Which industries are most targeted in the Philippines?
Finance is the primary target, with coordinated attacks on financial institutions between March and April compromising approximately 99 million records. Other heavily targeted industries include hospitality, logistics, manufacturing, and energy.
What should I do if my data was compromised?
Change your passwords immediately, enable multi-factor authentication, monitor your accounts for unusual activity, and report any unauthorized transactions to your bank within 72 hours. Under AFASA, banks that failed to meet the June 30, 2026 security deadline may be required to reimburse you for fraud resulting from their non-compliance. See our BSP scam reimbursement guide for details.
Is the Philippine government doing enough about cybersecurity?
The government has strengthened measures through AFASA, BSP Circular 1213, and DICT initiatives. However, Viettel Cyber Security warned that regulatory compliance alone is no longer enough to counter AI-powered threats. The gap between threat capability and defensive capability is widening.
This article is based on the Viettel Cyber Security Cyber Threat Landscape Report for the Philippines H1 2026 and other publicly available sources. The author and publisher disclaim any liability for actions taken based on this information.







