The voice of the ASEAN people

INSIDE·ASEAN

Connecting ASEAN with the World

Philippines

Ransomware Attacks in the Philippines: A Shift in Tactics

Recent reports indicate a significant rise in ransomware incidents, with identity theft becoming a primary entry point for attackers.

By Paolo Mercado26 July 20263 min read
Ransomware Attacks in the Philippines: A Shift in Tactics

A recent report by Sophos highlights a troubling shift in the landscape of ransomware attacks, revealing that four out of five incidents now begin with compromised identities rather than direct server breaches. This finding, part of the seventh annual State of Ransomware report, suggests that organizations must reconsider their cybersecurity strategies, as merely addressing technical vulnerabilities is no longer sufficient.

According to the report, which surveyed over 2,000 IT and cybersecurity leaders globally, the most common entry points for ransomware have shifted towards malicious emails and phishing attempts, accounting for 26 percent and 24 percent of attacks, respectively. In contrast, exploited software vulnerabilities have decreased significantly, from 32 percent to 18 percent over the past year. Although the Philippines was not included in this global survey, local data corroborates these trends. The Check Point Philippine Threat Landscape Report 2025 noted that ransomware incidents in the country nearly doubled from nine in 2024 to 17 in 2025, while phishing websites surged by an alarming 423 percent.

Ritchelle Santos, a senior cyber threat intelligence analyst at Check Point, noted that identity and trust, along with mobile channels, have emerged as the new battleground in cybersecurity. This aligns with the Sophos report, which indicates that two-thirds of ransomware victims experienced the ransomware incident and their most significant identity attack as a singular event.

“Identity, trust, and mobile channels have emerged as the new battleground.”Ritchelle Santos, senior cyber threat intelligence analyst at Check Point

Ross McKerchar, Chief Information Security Officer at Sophos, explained that attackers are experimenting with artificial intelligence to steal valuable assets at a pace beyond what they could manage before. The report suggests that organizations can no longer rely solely on traditional defenses, such as patching vulnerabilities, to protect against these evolving threats.

Despite the grim landscape, there is a glimmer of hope. The median ransom demand has decreased to $698,000, a drop of 65 percent over two years, while the median payment stands at $769,000. This indicates that victims are becoming more adept at negotiating with attackers. Furthermore, the report highlights an increase in the use of backup-based recovery methods, rising to 66 percent of cases, suggesting that organizations are investing in robust offline backups rather than solely relying on ransom payments for data recovery.

“Attackers are experimenting with artificial intelligence to steal valuable assets at a pace beyond what they could manage before.”Ross McKerchar, Chief Information Security Officer at Sophos

However, the psychological toll on IT and cybersecurity teams remains a pressing concern. The report reveals that 99 percent of organizations whose data were encrypted said the attack directly affected their IT or cybersecurity teams, with many experiencing heightened anxiety and pressure from leadership. Notably, over 20 percent of these organizations replaced their team leadership following an attack.

For businesses in the Philippines, the implications of these findings are clear. Organizations are advised to conduct thorough audits of all accounts with access to sensitive systems, ensure that multi-factor authentication (MFA) is comprehensive, and rigorously test backup systems before a crisis occurs. Firewalls continue to play a crucial role, as 61 percent of victims had their firewalls detect the attack prior to ransomware deployment, leading to significantly better outcomes.

As the landscape of ransomware evolves, it is imperative for organizations in the Philippines to adopt a proactive and comprehensive approach to cybersecurity, recognizing that the human element—such as the decision-making of employees—plays a critical role in safeguarding against these threats.