Some 335 million records were exposed in Philippine data breaches in the first half of 2026 — and 19.2 million account credentials were stolen outright — according to the latest threat-landscape report from Viettel Cyber Security, the security arm of Vietnamese telecommunications group Viettel.
The report, which covers January to June 2026, is the hardest set of numbers yet on how much Filipino data is leaking, and it lands with a warning: generative AI is making the scams built on that stolen data much harder to spot.
The numbers behind the H1 2026 breach wave
| Indicator | H1 2026 figure |
|---|
| Data breach incidents | 255 |
| Records exposed | ~335 million |
| Account credentials compromised | 19.2 million |
| Phishing attacks recorded | 16,619 |
| Ransomware incidents | 21 |
| Sensitive data leaked | 2.6 TB |
| New software vulnerabilities identified | 34,650 (77 high-impact for PH users) |
The figures were first reported by Newsbytes.PH and have kept circulating through local outlets since, a sign of how unusual it is for the Philippines to get breach data at this level of detail. Finance and logistics were among the hardest-hit sectors.
Banks lost 99 million records in coordinated attacks
The single most alarming line in the report involves financial institutions: coordinated attacks in March and April compromised about 99 million records from banks, and roughly 1.8 terabytes of confidential financial data were stolen over the period. A separate breach at a public-service organization exposed another 45 million records.
For scale, the Philippines has around 110 million people. Even allowing for duplicate records across incidents, the numbers suggest most Filipinos with any digital footprint — a bank account, an e-wallet, an online shopping profile — should assume some of their data has been exposed this year.
AI is making the follow-up scams more convincing
Stolen records are rarely the end goal; they are raw material for fraud. The report warns that criminals now use generative AI to sharpen impersonation schemes, including deepfake voices and videos that pose as bank personnel or government officials to trick victims into handing over one-time passwords (OTPs — the six-digit codes apps send to confirm it is really you). Romance scams, fake job offers, and delivery fraud are all rising on the same fuel.
That warning matches what Philippine authorities are seeing on their end. The Anti-Money Laundering Council has started using AI to screen suspicious transactions from banks and e-wallets, while regulators lean on the Anti-Financial Account Scamming Act (AFASA) to force faster fraud response from financial institutions.
How to protect your accounts
The report's advice for consumers is blunt: treat unsolicited calls and messages claiming to be from a bank or government agency as hostile until proven otherwise, never share an OTP, and verify any request through official channels before acting. A few practical steps for Filipino users:
The H1 2026 numbers will not be the peak — the report expects AI-driven fraud to keep climbing into next year. The cheapest defense is still the oldest one: assume your data is already out there, and make the follow-up scam fail anyway.