• Home  
  • AI-Driven Cyberattacks Expose 19.2 Million Philippine Credentials in H1 2026
- AI - Enterprise Technology - News

AI-Driven Cyberattacks Expose 19.2 Million Philippine Credentials in H1 2026

Cybercriminal activity in the Philippines reached a new level in the first half of 2026, with attackers increasingly using artificial intelligence (AI), stolen credentials, and software vulnerabilities to execute large-scale cyberattacks. According to the latest Cyber Threat Landscape Report from Viettel Cyber Security (VCS), more than 19.2 million credentials were compromised in the Philippines from […]

Cybercriminal activity in the Philippines reached a new level in the first half of 2026, with attackers increasingly using artificial intelligence (AI), stolen credentials, and software vulnerabilities to execute large-scale cyberattacks.

According to the latest Cyber Threat Landscape Report from Viettel Cyber Security (VCS), more than 19.2 million credentials were compromised in the Philippines from January to June 2026. The cybersecurity firm also recorded 255 data breach incidents, exposing approximately 335 million records and 2.6 terabytes of data.

The findings highlight a rapidly evolving cybersecurity environment where threat actors are combining traditional hacking techniques with AI-powered tools to increase the speed, scale, and effectiveness of attacks.

Data breaches target critical sectors

Data breach incidents in the Philippines by sector during the first half of 2026, highlighting industries most targeted by cybercriminals.

VCS reported several major cyber incidents affecting financial institutions, public services, and other organizations managing sensitive information.

Between March and April 2026, coordinated attacks against financial institutions compromised around 99 million records, while another public-service breach exposed approximately 45 million records.

In a separate incident, attackers reportedly extracted about 1.8 terabytes of confidential internal data from financial organizations after deploying malicious payloads inside enterprise systems.

Many of these attacks were linked to the exploitation of known software vulnerabilities. VCS identified 77 high-impact vulnerabilities affecting products and services widely used in the Philippines, emphasizing the importance of timely patching and continuous security monitoring.

AI makes phishing and scams more convincing

One of the biggest shifts in the threat landscape is the growing use of AI for social engineering attacks.

VCS recorded 16,619 phishing attempts nationwide, including fake messages designed to trick users into clicking malicious links or revealing sensitive information.

With the help of generative AI, cybercriminals can now create highly personalized scams using leaked personal data. Attackers are also using AI-generated deepfake voices and videos to impersonate bank employees, government officials, or even family members.

These advanced impersonation tactics are designed to convince victims to share one-time passwords (OTPs), approve fraudulent transactions, or provide access to accounts.

Organizations need proactive cybersecurity strategies

While regulatory initiatives such as the Bangko Sentral ng Pilipinas’ Anti-Financial Account Scamming Act (AFASA) and cybersecurity programs from the Department of Information and Communications Technology (DICT) are strengthening defenses, VCS emphasized that compliance alone is no longer enough.

Organizations need continuous threat intelligence, real-time monitoring, vulnerability management, and employee cybersecurity awareness to detect and respond to attacks faster.

AI becomes a double-edged sword in cybersecurity

The report shows that AI is now being used by both defenders and attackers. Cybercriminals are leveraging AI to automate phishing campaigns, generate realistic fake content, and improve social engineering operations.

As AI-powered threats become more sophisticated, businesses and individuals must adopt stronger security practices to protect sensitive data and digital identities.

VCS advises users to remain cautious of unsolicited messages, calls, or requests for OTPs and verify suspicious communications through official channels.

For organizations, the cybersecurity firm recommends integrating threat intelligence into security operations, continuously assessing vulnerabilities, and preparing employees against emerging AI-driven threats.

Email Us

For inquiries, press releases, and partnership request, get in touch with us at: info.aitimes.ph@gmail.com.

Contact: 0956-344-3286

AI Times  @2026. All Rights Reserved.