More than 19.2 million account credentials in the Philippines were compromised in the first half of 2026 as cybercriminals expanded their use of phishing, ransomware, software exploits and artificial intelligence, according to a report from Viettel Cyber Security (VCS).
The company’s Cyber Threat Landscape Report recorded 16,619 phishing attacks and 21 ransomware incidents in the country from January to June. Finance, hospitality, logistics, manufacturing and energy were among the sectors most affected.
Viettel Threat Intelligence, VCS’s cyberthreat monitoring platform, also tracked 255 data breach incidents that reportedly exposed about 335 million records and 2.6 terabytes of data.
Coordinated attacks against financial institutions between March and April compromised about 99 million records, the report said. A separate breach involving a public-service organization exposed another 45 million records.
In another incident, attackers allegedly obtained about 1.8 terabytes of confidential internal data from financial institutions after deploying malicious software within enterprise systems.
The report also identified 34,650 newly disclosed software vulnerabilities during the six-month period. Of these, 77 were classified as high-impact vulnerabilities affecting products and services used in the Philippines.
VCS said unpatched systems continued to serve as entry points for attacks, with cybercriminals increasingly combining software exploits with stolen credentials, phishing and social-engineering techniques.

(Source: Viettel Threat Intelligence)
Phishing remained one of the most widespread threats, including fake “your account is locked, click here” messages designed to obtain login details or financial information.
The report warned, however, that generative AI is making fraudulent messages and impersonation schemes more convincing. Attackers can use leaked personal information to create deepfake voices or videos impersonating bank personnel, government officials or relatives.
These schemes are designed to persuade victims to disclose one-time passwords or approve unauthorized transactions. VCS also reported increasing use of compromised data in romance scams, fake recruitment offers and delivery-related fraud.
The report said AI is already being used as an operational tool by cybercriminals to automate phishing, produce realistic impersonations and personalize scams at scale. Espionage-linked groups were also observed targeting public services, healthcare organizations and technology companies.
The findings come as financial institutions implement security requirements under the Anti-Financial Account Scamming Act, while the Department of Information and Communications Technology expands programs such as the DICT Trusted Assessment Providers initiative and the Cybersecurity Posture Assessment Laboratory.
VCS said regulatory compliance should be supported by continuous threat monitoring, vulnerability management and employee security training.
For consumers, the cybersecurity company advised verifying unsolicited calls and messages through official channels, particularly when callers claiming to represent banks or government agencies ask for passwords or one-time PINs.


