Philippines Faces Surge in Cyberthreats as Criminals Leverage AI to Scale Attacks, Viettel Report Shows
Key Takeaways
- •Over 19.2 million credentials were compromised in the Philippines during the first half of the year, marking a roughly fivefold increase from 3.79 million in the same period last year.
- •VCS documented 255 data breach incidents that exposed approximately 335 million records and 2.6 terabytes of data, alongside 16,619 phishing attacks and 21 ransomware incidents.
- •Government entities absorbed 30% of recorded cyberattacks while financial institutions accounted for 15%, reflecting a criminal shift toward coordinated operations against organizations managing sensitive data and critical services.
- •Coordinated attacks on financial institutions between March and April compromised around 99 million records, and a separate breach of a public-service organization exposed 45 million records.
- •Cybercriminals are increasingly integrating phishing, vulnerability exploitation, and AI-enabled social engineering—including deepfakes—to conduct automated, large-scale campaigns that are more difficult to detect.

The Philippines experienced a significant rise in cyberthreats during the first half of the year, driven primarily by data breaches, credential theft, ransomware incidents, and attacks amplified by artificial intelligence (AI), according to Viettel Cyber Security (VCS).
The findings come as the country continues to accelerate its digital adoption, with one of Southeast Asia's highest internet and social media penetration rates — a factor that broadens the attack surface for both organizations and individual users.
The company's latest Cyber Threat Landscape Report, drawing on data from its Viettel Threat Intelligence monitoring platform, revealed that malicious actors are increasingly combining multiple attack techniques and harnessing rapidly advancing AI technologies to expand the scale of their operations.
"(I)ncreasingly coordinated campaigns are exploiting software vulnerabilities, stolen credentials and artificial intelligence to target both critical industries and everyday users," VCS said.
The report documented that more than 19.2 million credentials were compromised in the first half of the year — a roughly fivefold increase from just 3.79 million during the same period a year earlier.
VCS also recorded 255 data breach incidents that collectively exposed approximately 335 million records and 2.6 terabytes (TB) of data. During the same period, some 16,619 phishing attacks and 21 ransomware incidents targeted organizations in the country, with the finance, hospitality, logistics, manufacturing, and energy sectors among the most heavily affected.
According to the report, 30% of the recorded attacks were directed at government entities, while 15% targeted financial institutions. VCS noted that high-profile cyber incidents involving these sectors indicate criminals are pivoting toward more coordinated operations against organizations that manage sensitive data and critical services, frequently exploiting known software vulnerabilities.
"Among the most significant incidents, coordinated attacks against financial institutions between March and April compromised around 99 million records, while a separate breach affecting a public-service organization exposed another 45 million records," VCS said.
"In another major attack, threat actors exfiltrated approximately 1.8 TB of confidential internal data from financial institutions after deploying malicious payloads within enterprise systems."
Philippine financial institutions are currently strengthening their fraud and cyber risk management frameworks to comply with the Anti-Financial Account Scamming Act, VCS noted. The law, enacted to combat the rising tide of financial scams and unauthorized account access, reflects a broader regional push across Southeast Asia to tighten cybersecurity and consumer protection standards as digital banking adoption surges.
However, these efforts may prove insufficient, as cybercriminals are now integrating multiple attack methods. Phishing, vulnerability exploitation, and AI-enabled social engineering have emerged as among the fastest-growing threats, enabling automated, large-scale campaigns that are increasingly difficult to detect.
"Rather than exploiting technical weaknesses, these campaigns increasingly target human trust. The combination of leaked personal data and generative AI enables attackers to create highly personalized scams," VCS said, noting that such tactics include deepfakes and other forms of fraud.
"Organizations need continuous threat intelligence, and real-time monitoring to detect and contain attacks before they escalate," the company added. "Together, these measures help organizations build a resilient cybersecurity posture for the secure and sustainable adoption of technology amid evolving global cyberthreats."
— Bettina V. Roc