MANILA, 26 AUG 2026 — A report from Viettel Cyber Security puts some very large numbers on the first half of 2026 in the Philippines. It counts 335 million exposed records, 19.2 million compromised account credentials, 16,619 phishing attacks, 21 ransomware incidents and 255 separate data breach events between January and June.

The credential figure alone is up more than fivefold from 3.79 million in the same period a year earlier. Those numbers count different things, and only one of them comes close to counting people.

What the report is counting

These figures count four different things — credentials, records, incidents and people — and they are routinely collapsed into one another. Separating them changes what the report says.

Credentials are username and password pairs, generally observed for sale or circulating in criminal marketplaces. Records are rows in a breached dataset. Incidents are events. People are people, and the report does not count them.

Getting this wrong produces alarming nonsense. The Philippines has a population of roughly 115 million. A headline treating 335 million exposed records as 335 million victims implies every Filipino was breached three times over in six months, which is not what happened and not what the report says.

19.2mCredentials compromised, H1
3.79mSame period, 2025
255Breach incidents tracked
335m recordsAcross those incidents, 2.6TB

Records are not people, and the gap is large

A single individual generates many rows. One customer of one bank appears in the account table, the transaction log, the address history, the marketing list and the support ticket archive, and a full dump captures every one.

Multiply that across the several organisations any adult deals with, add the historical rows that retention policy never removed, and 335 million records across a country of 115 million people is not a startling number. It is roughly what a few large dumps look like.

For an individual, the credential figure is the most useful one, because it maps closely to a person and a service. Even so, one person with a dozen accounts is a dozen credentials, making 19.2 million an upper bound on the number of people affected rather than a count of them.

Two incidents are close to half the total

The distribution matters more than the sum, and this is where the report is most informative.

Coordinated attacks on financial institutions between March and April account for around 99 million records. A separate breach at a public-service organisation accounts for another 45 million. Together those two clusters are roughly 144 million of the 335 million total, or about 43 per cent, from two events out of 255.

This distribution changes what the total means. If the breaches were spread evenly across 255 incidents, the problem would be diffuse and would call for broad hygiene improvements. Instead the total is dominated by two events, which points to a small number of large custodians holding concentrated data, where one failure moves the national statistic.

For a policymaker, the implication is uncomfortable but useful. Modestly improving the security of 255 organisations would barely move this figure, while substantially improving it at the two or three largest data holders would.

A fivefold rise, and what else could produce it

Credential compromise rising from 3.79 million to 19.2 million in a year is a fivefold increase, and it deserves a moment of scepticism before it is repeated as a measure of criminal activity.

These counts come from monitoring criminal marketplaces, leak sites and infostealer logs. What they measure is how much stolen material a particular vendor observed, which depends on that vendor's collection capability as well as on the theft itself. A firm that expanded its sources, or improved its ability to attribute a credential to a country, will record a rise that reflects better instrumentation rather than more crime.

This does not mean the increase is unreal. Infostealer malware did industrialise over this period, and credential theft is up across the region. It means a fivefold figure from a single vendor is one measurement rather than a national statistic. The direction is well supported; the magnitude is specific to the firm doing the counting. Our earlier reading of a different vendor's APAC mid-year data has the same limitation.

The AI-assisted claim needs unpacking

The framing around this report is that criminals are using artificial intelligence to scale their attacks. That is almost certainly true and it is also the least measurable statement in the whole document.

Nobody inspecting a phishing email can tell whether a model wrote it. What can be observed are proxies, such as campaigns in fluent local languages that lack the usual grammatical tells, volumes that would previously have needed more people, and individually tailored lures at a scale beyond manual research.

Those proxies are real and they matter, particularly here. English proficiency in the Philippines meant that clumsy translation was never much of a filter to begin with, so the country loses less protection from fluent generated text than a market where bad Tagalog or bad Bahasa was the giveaway. The defensive habit of telling staff to watch for awkward phrasing was already weak locally and is now finished.

What none of this supports is a number. When 16,619 phishing attacks are reported alongside a statement about AI, the count is of attacks observed, not of attacks generated by a model, and no current method separates the two.

The sector list is doing the real work

Finance, hospitality, logistics, manufacturing and energy are named as the most affected sectors, and that combination is more revealing than the totals.

Finance is the obvious target and needs no explanation. The other four have something in common: they are operationally intense, they run large numbers of low-privilege accounts across shifts and contractors, and their security budgets are historically a fraction of what a bank spends.

Hospitality and logistics in particular hold rich identity data — passport details, addresses, itineraries, delivery patterns — while running on thin margins that do not fund a mature security function. They are attractive precisely because the ratio of data value to defensive investment is favourable to an attacker.

Against that backdrop, 21 ransomware incidents is a low number — an observation rather than a cause for celebration. Ransomware is loud and gets counted. Credential theft is quiet, and 19.2 million of it went alongside those 21 events.

What it means from here

For readers in the region the practical consequence is about reuse rather than about the Philippines specifically. A credential stolen from a hotel booking system is worth very little on its own and a great deal if the same password opens an email account, and that is the mechanism converting a bulk statistic into an individual problem.

For organisations, the key finding is the concentration. If your business holds identity data for millions of customers, you are not one of 255 comparable incidents in a national tally. You are a potential 99 million-record line item, and the difference between those two positions is entirely about how much data you have chosen to keep.

The number worth asking for internally is not the security budget. It is how many rows the production database still holds for customers who stopped being customers years ago, because that is the part of the exposure that no control removes and no attacker has to work for.