Ransomware claims more than double in Phl

Public ransomware claims against Philippine organizations more than doubled in 2026 as cybercriminals increasingly turned to AI-enabled deception, social media impersonation and stolen credentials, according to a new report from Check Point Software Technologies.
The company’s 2026 Philippines Threat Landscape Report, covering January to August, recorded 31 public ransomware claims, already higher than the 26 cases logged across 2024 and 2025 combined.
Fifteen ransomware groups posted claims involving Philippine targets this year, with Qilin accounting for 29 percent of cases.
Government agencies recorded the highest overall attack volume with 72 incidents, while financial institutions faced the highest concentration of severe attacks involving ransomware, data breaches and leaks.
Check Point also tracked 24,875 data exposure cases, with nearly 44 percent linked to malware quietly harvesting credentials from infected devices.
Exposed payment card data accounted for almost 24 percent of cases, while employee credentials leaked through third-party platforms made up about 10 percent.
Phishing remained persistent, with 2,386 alerts recorded during the period.
Attackers increasingly moved away from schemes focused on intercepting one-time passwords and instead used fake rewards, loyalty programs and similar lures to obtain personal and payment information.
Social media impersonation also surged, with 1,194 alerts logged. Of these, 972 involved companies and 222 targeted executives.
Facebook accounted for about four out of five impersonation cases, while TikTok was frequently used in executive impersonation.
The report said artificial intelligence is being used mainly to strengthen deception rather than directly breach networks.
Deepfake videos, cloned voices and AI-generated content are increasingly being used in romance scams, investment fraud and malware distribution.
For 2027, Check Point urged organizations to focus on high-impact assets, strengthen identity protection, secure internet-facing systems, tighten oversight of suppliers and govern enterprise use of AI.
The company said the Philippines’ cyber threat environment is being driven less by entirely new attack methods and more by easier access to proven tools, stolen credentials and AI-assisted social engineering.
