Filipinos faced 16,619 phishing attacks in the first half of 2026 as cybercriminals stepped up efforts to steal passwords, bank details, and other personal information using fake messages and artificial intelligence (AI).
A new Cyber Threat Landscape Report from Viettel Cyber Security (VCS) found that phishing remains one of the most common ways criminals trick people into giving away sensitive information. Many scams started with fake emails, text messages, or social media posts claiming that a bank account had been locked or that urgent action was needed.
However, VCS warned that phishing attacks are becoming much harder to detect because cybercriminals are now combining stolen personal information with generative AI (GenAI) to make scams appear more convincing.
The report found that more than 19.2 million user credentials, including usernames and passwords, were compromised in the Philippines from January to June 2026. During the same period, VCS recorded 255 data breaches that exposed about 335 million records and 2.6 terabytes of data.
These stolen records give cybercriminals enough information to create personalized phishing messages that look legitimate.
The report said scammers are also using AI to generate fake voices and videos that can impersonate bank employees, government officials, or even family members. Victims are then persuaded to share one-time passwords (OTPs), transfer money, or approve fraudulent transactions.
Aside from phishing, cybercriminals are also expanding into romance scams, fake job offers, and delivery scams that rely on leaked personal information to gain victims’ trust.
The report also highlighted a series of major cyber incidents affecting organizations that handle sensitive information. Between March and April, coordinated attacks on financial institutions exposed about 99 million records, while a separate breach involving a public-service organization leaked another 45 million records. In another attack, hackers stole around 1.8 terabytes of confidential data from financial institutions after installing malicious software inside their systems.
Many of these attacks took advantage of software vulnerabilities that had not yet been fixed. Viettel Threat Intelligence identified 77 high-risk vulnerabilities affecting products and services widely used in the Philippines.
While the Bangko Sentral ng Pilipinas (BSP) has strengthened anti-scam measures through the Anti-Financial Account Scamming Act (AFASA), and the Department of Information and Communications Technology (DICT) continues cybersecurity programs for government agencies, VCS said compliance alone is no longer enough.
The company said organizations should strengthen security monitoring, promptly fix software vulnerabilities, and train employees to recognize phishing attempts.
For individuals, VCS advises never sharing OTPs or personal information through unsolicited calls, emails, or text messages, even if they appear to come from banks or government agencies. Instead, people should verify requests by contacting the organization through its official website, hotline, or mobile app before taking any action.
