隨著犯罪分子利用 AI 擴大攻擊規模,菲律賓資安威脅激增,Viettel 報告顯示
重點速覽
- •菲律賓今年上半年有超過 1920 萬組憑證遭到入侵,較去年同期的 379 萬組約增加五倍。
- •VCS 記錄到 255 起資料外洩事件,合計曝光約 3.35 億筆紀錄與 2.6 TB 資料,另有 16,619 起釣魚攻擊與 21 起勒索軟體事件。
- •政府機構占已記錄網路攻擊的 30%,金融機構占 15%,反映犯罪活動正轉向針對管理敏感資料與關鍵服務的組織。
- •3 月至 4 月間對金融機構的協同攻擊約外洩 9900 萬筆紀錄,另一起影響公共服務組織的外洩事件則曝光 4500 萬筆紀錄。
- •網路犯罪分子愈來愈多結合釣魚、漏洞利用與 AI 社交工程,包括 deepfakes,以執行更難偵測的自動化大規模攻擊。

根據 Viettel Cyber Security(VCS)表示,菲律賓今年上半年資安威脅顯著增加,主要來自資料外洩、憑證竊取、勒索軟體事件,以及人工智慧(AI)放大的攻擊。
在菲律賓持續加速數位化採用之際,該國擁有東南亞較高的網際網路與社群媒體滲透率之一,這也擴大了企業與個人使用者面臨的攻擊面。
VCS 最新的《Cyber Threat Landscape Report》根據其 Viettel Threat Intelligence 監測平台資料指出,惡意行為者正愈來愈多地結合多種攻擊手法,並利用快速發展的 AI 技術擴大作案規模。
“(I)ncreasingly coordinated campaigns are exploiting software vulnerabilities, stolen credentials and artificial intelligence to target both critical industries and everyday users,” VCS said.
報告顯示,今年上半年有超過 1920 萬組憑證遭到入侵,較去年同期的 379 萬組大約增加五倍。
VCS 也記錄到 255 起資料外洩事件,合計曝光約 3.35 億筆紀錄與 2.6 terabytes(TB)資料。同一期間,菲律賓共遭遇 16,619 起釣魚攻擊與 21 起勒索軟體事件,其中金融、飯店、物流、製造與能源產業受影響最嚴重。
報告指出,已記錄的攻擊中有 30% 針對政府機構,15% 針對金融機構。VCS 表示,涉及這些部門的高知名度資安事件顯示,犯罪分子正轉向對管理敏感資料與關鍵服務的組織發動更協同的攻擊,並頻繁利用已知軟體漏洞。
“Among the most significant incidents, coordinated attacks against financial institutions between March and April compromised around 99 million records, while a separate breach affecting a public-service organization exposed another 45 million records,” VCS said.
“In another major attack, threat actors exfiltrated approximately 1.8 TB of confidential internal data from financial institutions after deploying malicious payloads within enterprise systems.”
VCS 指出,菲律賓金融機構目前正強化其詐欺與網路風險管理架構,以符合《Anti-Financial Account Scamming Act》。這項法律旨在打擊日益增加的金融詐騙與未經授權的帳戶存取,也反映出東南亞各地在數位銀行採用率攀升之際,對資安與消費者保護標準加強的更廣泛區域趨勢。
然而,這些努力可能仍不足以應對風險,因為網路犯罪分子現在正整合多種攻擊方式。釣魚攻擊、漏洞利用與 AI सक्षम社交工程已成為成長最快的威脅之一,使自動化、大規模攻擊活動更難被偵測。
“Rather than exploiting technical weaknesses, these campaigns increasingly target human trust. The combination of leaked personal data and generative AI enables attackers to create highly personalized scams,” VCS said, noting that such tactics include deepfakes and other forms of fraud.
“Organizations need continuous threat intelligence, and real-time monitoring to detect and contain attacks before they escalate,” the company added. “Together, these measures help organizations build a resilient cybersecurity posture for the secure and sustainable adoption of technology amid evolving global cyberthreats.”
— Bettina V. Roc