On September 7, 2026, the Philippine Ports Authority discovered that the Qilin ransomware group had claimed an attack on its systems. The agency manages and regulates the country's public ports. Credential monitoring tied to its domain shows 990 exposed logins, 372 of them from infostealer logs covering 212 compromised devices, credentials that could provide an attacker with a direct route into an organization without having to exploit a software vulnerability. About two weeks earlier, researchers reported that attackers had reached a Philippine nuclear agency and taken roughly 1.2 gigabytes of reactor core-component data, fuel inventories, radiation safety documentation, and personnel records, through vulnerabilities that had gone unpatched for more than two years.

Neither incident is an outlier. They arrived on top of a first half of 2026 that was already severe, and the data describing how bad 2026 has been keeps needing to be revised upward before the year is even over.


A Severe First Half, and a Second Half That Has Not Eased

Viettel Cyber Security's H1 2026 Cyber Threat Landscape Report put numbers on the first six months for the Philippines: 19.2 million compromised credentials, 255 data breaches exposing 335 million records, 16,619 phishing attacks, 21 ransomware incidents, and 2.6 terabytes of exposed data, alongside 34,650 newly discovered vulnerabilities, 77 of them rated high-impact. Finance, hospitality, logistics, manufacturing, and energy took the brunt, including a single March-to-April incident that exposed 99 million financial records, a separate breach of 45 million public-service records, and 1.8 terabytes taken from financial institutions. These are not abstract totals. Each record is a customer, a taxpayer, or an employee whose details are now circulating somewhere an organization no longer controls.

The exposure is not confined to private companies. SOCRadar's Philippines Threat Landscape Report found that public administration accounted for 47.46 percent of Philippine dark web exposure and education another 18.31 percent, with data breaches and unauthorized access making up 68 percent of the threats it tracked there. Viettel's own conclusion was blunt: compliance alone is no longer sufficient.

That report covers January through June. Full second-half totals do not exist yet, since the year is not over. What does exist is a run of named incidents from August and September, including the two above, which show no sign of the pace easing.


Ransomware: Growing in the Philippines, Accelerating Worldwide

Philippine data. Check Point Research found that confirmed ransomware incidents against Philippine organizations nearly doubled in 2025, from 9 to 17, while source-code leaks doubled from 38 to 81 and third-party breach disclosures climbed from 8 to 29. SOCRadar's Philippines Threat Landscape Report shows who is behind the claims: Qilin accounts for roughly 14.5 percent of ransomware activity against Philippine targets and LockBit another 12 percent, while the remaining 65.1 percent is spread across many other groups. That fragmentation makes defending against ransomware as one known threat increasingly difficult.

Global context. The following figures are worldwide, not Philippine, and are included because the same groups operate in both. Black Kite's 2026 Ransomware Report found that Qilin's victim count rose from roughly 250 to 1,358 in a year, a 443 percent increase, and that ransomware activity accelerated 60 percent in the second half of its April 2025 to March 2026 reporting period compared to the first. Zscaler's 2026 ransomware research found stolen data volume up 275 percent year over year, with $328 million in extortion payments tracked on the blockchain. Two more details from those reports matter for Philippine organizations. Zscaler found that 62 percent of the victims named by ransomware groups were manager-level or above, a sign that attackers increasingly choose targets by who can authorize a payment. Black Kite found manufacturing to be the most heavily hit sector worldwide, and manufacturing is one of the sectors Viettel listed among the hardest hit in the Philippines in H1. A payout environment that profitable keeps new groups entering the market, and Qilin is the group that claimed the Philippine Ports Authority.


AI Is Turning Ordinary Scams Into Convincing Impersonation

Viettel's researchers flagged AI-enabled fraud as one of the fastest-growing threats facing Philippine organizations and individuals, pointing to deepfakes that impersonate bank employees, government officials, and relatives to pressure victims into transferring money or handing over credentials. The same report points to credential exploitation and romance, recruitment, and delivery scams as growing categories, all of which depend on convincing a person rather than defeating a system. Check Point's 2025 data adds a number: social media impersonation targeting Philippine users rose 37 percent, from 940 to 1,291 cases, driven in part by AI chatbots used to run fake investment schemes.

This category is hard to defend because it does not look like a technical attack. A deepfake voice call or an AI-run investment chat does not touch a firewall or appear in a vulnerability scan. It targets a person's judgment, which means patching, network monitoring, and endpoint protection have comparatively little to say about it.


Phishing Has Industrialized, and Smishing Is Doing Most of the Work

Check Point's data shows phishing sites targeting Philippine users jumped 423 percent in a single year, from 731 to 3,824, a figure the researchers described as evidence that "cyberattacks in the Philippines are no longer defined by technical sophistication, but by scale, automation, and deception." SOCRadar's data adds a detail worth sitting with: 62.1 percent of phishing sites targeting Philippine users were running on HTTPS, meaning the padlock icon millions of Filipinos were taught to look for as a sign of safety offers no protection at all against a huge share of current phishing activity. Smishing, phishing delivered over SMS rather than email, remains the dominant delivery channel, which tracks with how much everyday transacting in the Philippines, from bank alerts to delivery notifications, already happens over text.

Put together with Viettel's 16,619 recorded phishing attacks in H1 alone, the picture is consistent across every source: phishing in the Philippines is not a seasonal spike tied to a particular scam campaign. It is sustained, high-volume, and increasingly indistinguishable from legitimate communication at the point a user actually sees it.


Some Attackers Are Patient, and That Changes the Defense

Not every incident in this data is financially motivated. CYFIRMA's Philippines threat overview names Earth Estries and FamousSparrow, both assessed as China-linked groups, among the actors active against Philippine targets. In the nuclear agency case, researchers at hunt.io found Chinese-language code comments and folder names on the attacker's infrastructure, while cautioning that language alone is not proof of nation-state attribution, since it is also one of the easiest indicators to plant.

Attribution aside, the practical point holds in any single case: the attacker on the other end may be better resourced, more patient, and more interested in staying inside a network undetected than a typical ransomware affiliate chasing a quick payout. In the nuclear agency case, the way in was a pair of flaws, one in ownCloud disclosed in November 2023 and one in a WordPress plugin patched in August 2024, that were still open when attackers arrived.


Different Threats, One Pattern

Ransomware, AI-driven fraud, phishing, and patient state-linked intrusion look like four separate problems, and most security budgets treat them that way. Read side by side, the incidents in this article describe something simpler. The Ports Authority case involves exposed credentials. The nuclear agency case involves flaws that had a public fix for years. Phishing and AI impersonation succeed by reaching a person who has legitimate access. Third-party breaches work because a trusted vendor holds that access instead.

In each case the attacker did not need a novel technique. They needed a door that was already open, and the data suggests those doors are being found faster than they are being closed. That is why scale and automation, in Check Point's words, now matter more than sophistication.


What Organizations Need to Prioritize Going Into 2027

The exposure behind these incidents existed before the attacker arrived: unpatched vulnerabilities, exposed credentials, overlooked third-party access, and attack paths nobody had tested from an adversary's perspective. Organizations planning 2027 budgets against last year's threat model are already behind, and the planning itself should start from a different question. Instead of asking which threat category to buy protection against, ask what an attacker could reach today, and fix the shortest path first.

Five priorities follow from the data. Patch known vulnerabilities on a schedule that assumes attackers are already looking, because the nuclear agency breach ran through a flaw that was public for years. Treat credentials as an attack surface: with 19.2 million compromised credentials recorded in H1 alone, and infostealer-sourced logins tied to the Ports Authority's domain, unique passwords, multi-factor authentication, and monitoring for exposed logins are baseline controls, not extras. Assume the next ransomware group targeting you has no track record yet, since a defense built around a short list of known actors does not hold against a fragmented field. Train people for impersonation, not just email, because AI-driven fraud is aimed at judgment rather than systems, and "look for the padlock" now teaches people to trust the wrong sites. And treat third-party access as its own risk: Check Point's jump in third-party breach disclosures, from 8 to 29, is a reminder that an organization is only as secure as the vendor with the weakest controls.

Compliance checklists and periodic automated scans are not enough on their own to understand that kind of exposure. Secuna Pentest addresses it through manual, scoped penetration testing across web applications, mobile apps, APIs, networks, and cloud infrastructure, finding the unpatched flaws and exposed access points that external attackers are already looking for. Going into 2027, the organizations in the best position will be the ones that tested their own exposure before a ransomware group, a state-linked actor, or an AI-generated phone call did it for them.

To learn more, reach out to our team at [email protected] or explore our services at secuna.io.


Sources: Philippine Ports Authority Data Breach, Breachsense · Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency, Dark Reading · Over 335M Records Breached as Cyber Attacks Rise in the Philippines in H1 2026, Technobaboy · Phishing Sites in PH Jump 423% in 2025, Newsbytes.ph · Philippines Threat Landscape Report 2026, SOCRadar · 2026 Ransomware Report, Black Kite · New Zscaler Report Reveals AI-Assisted Attackers Move to Massive Data Theft, Executive Targeting, and Millions in Extortion Payments, Zscaler · Philippines Threat Overview, CYFIRMA