Check Point Software Releases 2026 Philippines Threat Landscape Report: Ransomware Claims More Than Double &Amp; Cyber Criminals Scale Up Deception Tactics
New report reveals over 24,000 data exposure incidents, surging social media impersonation and a major shift towards AI-powered scams targeting Philippine organisations
MANILA, October 6, 2026 — Check Point Software Technologies Ltd. (NASDAQ: CHKP), a leading global cyber security solutions provider, has released its Exposure Management Research 2026 Philippines Threat Landscape Report. Analysing cyber activity from January through August 2026, the report highlights a sharp rise in high-impact cyber attacks, doubling public ransomware claims and exposing widespread credential and identity risks.
While government agencies saw the highest overall volume of attacks (72 incidents), primarily driven by public-facing website defacements and information-system disruptions, financial institutions faced the highest concentration of severe threats, with over half of their recorded incidents involving ransomware, data breaches, or leaks.
Key Findings from the 2026 Report:
- Ransomware Claims More Than Double: Public ransomware threats against Philippine organisations reached 31 by August 2026, surpassing the 26 cases recorded across all of 2024 and 2025 combined. Fifteen distinct groups posted local claims this year, compared to 12 in all of 2025, with 10 groups appearing in the local dataset for the first time. Qilin remained the most active group locally, raising its claims from 23% in 2025 to driving 29% of claims in 2026. Eight new sectors, including government, business services and critical infrastructures, were newly represented in 2026, after recording none during the same period in 2025.
- Shift in Phishing Tactics: While phishing volume remained steady at 2,386 alerts, attackers pivoted away from previously prevalent model of intercepting single-use text codes (OTPs). Instead, they are using fake reward points and loyalty program updates to trick users into handing over personal information and payment card details, peaking with 518 alerts in January, and tapering off with a low in May of 117 alerts, possibly due to the enforcement of BSP Circular No.1213.
- Massive Data Exposure Volumes: Check Point tracked 24,875 data exposure cases. Nearly 44% of these came from hidden malware quietly scraping credentials from infected devices, with customer passwords and credit card data making up the vast majority of leaked information. Almost 24% was from exposed payment card data while 10% was from employee credentials leaked through third-party platforms, elevating the risks caused by credential theft, weak access controls and exposed supply chain.
- Social Media Impersonation Surges: The widespread use of social media in the Philippines has created a significant digital environment for both legitimate engagement and adversarial activity. Threat actors commonly mimic company executives and official brand accounts to exploit established trust and increase the credibility of fraudulent communications. Check Point logged 1,194 impersonation alerts, including 972 involving company impersonation (81.4%) and 222 involving executive impersonation (18.6%). Facebook accounted for four out of five cases and TikTok was heavily used to impersonate executives.
- AI Used for Deception, Not Hacking: Cybercriminals are leveraging AI for social engineering rather than breaking directly into technical networks. Deepfake videos, cloned voices, and AI application are being heavily used to drive romance scams, investment fraud, for malware distribution.
Recommended Security Priorities for Organisations in 2027
To stay ahead of these evolving threat landscape, Check Point advises Philippine and regional enterprises focus on five key security priorities:
- Prioritise Business Impact: Focus defence resources on high-consequence assets rather than low-impact website defacements.
- Harden Identity Protections: Implement phishing-resistant multi-factor authentication (MFA) and monitor active user sessions continuously while converting threat intelligence into operational decisions.
- Audit Internet-Facing Systems: Secure vulnerable remote-access tools to close entry points before attackers exploit them.
- trengthen Third-Party Oversight : Continuously monitor supplier access, credentials and integrations to identify emerging risks and respond quickly.
- Govern Enterprise AI: Secure corporate tools against automated agents and unauthorised generative AI applications.
Whilst these findings from Check Point Exposure Management was derived through telemetry from monitored Philippine organizations, and intelligence collected from open-source, deep web, and dark web environments, and activity publicly claimed by threat actors, it was reported that cyber threats in the Philippines were driven less by new attack methods than by easier access. This easy access to proven tools, stolen credentials and AI-enabled deception, with identity and trust abuse underpinning attacks from phishing to ransomware led to an escalated cyberattack onslaught in the Philippines.
While high-volume incidents dominated the landscape, the findings show that organizations must prioritize threats by potential business impact, while strengthening identity, supplier access and exposure management. Only organisations which prioritise a prevention-first approach to exposure management—continuously identifying, prioritizing and remediating the exposures most likely to lead to consequential attacks before threat actors can exploit them, will be able to maintain the strongest defence in this new AI-era.