Identity: PH’s giant cybersecurity blind spot

Technology
6 Sep 2026 • 12:07 AM MYT
The Manila Times
The Manila Times

One of the longest-running English broadsheets in the Philippines

Identity: PH’s giant cybersecurity blind spot

THE PHILIPPINES has one of the region’s stricter breach-disclosure regimes on paper. Under the Data Privacy Act, personal information controllers must notify the National Privacy Commission within 72 hours of discovering a breach likely to cause serious harm, then submit a full report within five days.

In 2026, we see that obligation being tested. More than 19 million credentials were compromised in the Philippines in the first half, across 255 data breach incidents that exposed roughly 335 million records and 2.6 terabytes of data. Finance, logistics, manufacturing, hospitality and energy were among the affected sectors.

Two incidents stood out. Coordinated attacks on financial institutions between March and April compromised around 99 million records, while a separate breach at a public-service organization exposed another 45 million. None of this is only a problem for banks or IT departments. For years, businesses assumed the main danger was a stolen password, a leaked database, or someone guessing or buying their way in.

That assumption has since changed. Interpol’s latest Asia and South Pacific Cyberthreat Assessment found that over half of the 18 member countries surveyed now report cybercrime accounting for over 30 percent of all recorded crime, with phishing and social engineering the most widespread and financially damaging methods. Instead of passwords, cybercriminals are stealing identity itself.

When a login is no longer proof of a person

Most businesses already ask staff and customers for a second step at login, such as a text message code, in addition to a password. That helps, but only so far. Once someone is logged in, most systems trust that session for hours or even days without checking again. Criminals have worked out that stealing an already-logged-in session gets them past that second check entirely. Add in the habit of reusing the same password across several apps, and one leaked login can open several doors at once.

This matters for any business. A compromised staff email account, a supplier portal, or a customer’s account with an online retailer or lender all share the same weakness. Once someone is in, most systems have little way of confirming they still are who they say. As more everyday transactions, from payroll to customer service, move through logins rather than face-to-face contact, that weak point becomes a bigger part of the business.

Spending is starting to shift in response. Earlier this year, IDC predicted total security spending across Asia-Pacific, excluding Japan, would reach US$39.5 billion, growing at a 10-percent compound annual rate through 2029, with identity-focused tools among the fastest-growing categories.

Businesses have spent heavily on firewalls and antivirus protection for years; that remains necessary, but it doesn’t answer the question that matters most now: Is the person or system asking for access actually who they claim to be?

Three practical checks are worth making for all types of business.

First, find out how long an employee, supplier or customer stays “logged in” before being asked to prove their identity again, since that window is what session theft exploits. Second, add an extra verification step before anyone can move money, change bank details or access sensitive customer records, not only at the initial login. Third, apply the same oversight to any chatbot, AI assistant or automated tool with system access as you would to a new staff member. We should not treat it as a lower-risk exception.

A double-edged tool for both sides

AI complicates the picture further by making convincing impersonation cheaper and easier to pull off, whether that’s a fake voice note from a “boss” asking for an urgent transfer or a doctored video call. Interpol recorded a 600-percent rise in deepfake-related discussion on cybercriminal forums and Telegram channels used by Southeast Asian threat actors. Deepfake-enabled fraud is becoming a routine business risk.

At the same time, AI is helping the defensive side, spotting unusual activity and flagging suspicious logins faster than manual monitoring ever could. Both are true at once, which makes this a difficult year to plan around. Deloitte’s 2026 study of more than 660 executives worldwide found 81-percent confident they can deploy and manage AI at scale today, yet 75 percent admit their organization must change how it operates within 12 to 18 months. Many Philippine businesses face the same gap. They adopt AI tools faster than they update the rules needed to manage the risks those tools bring.

None of this looks the same across every market either. Mature markets with established rules and larger budgets are further along in tightening up who gets access to what. Fast-digitizing markets like the Philippines, Vietnam and Indonesia are often taking on new digital services and new threats at the same time, with less capacity to manage either.

Interpol notes these readiness gaps create openings that better-resourced markets have already begun to close. For any business operating across more than one Southeast Asian market, that unevenness is a risk in itself.

An approach that works in a well-regulated hub cannot be copied into a market still building its basic digital infrastructure, and a lighter-touch approach suited to an early-stage market will leave gaps if applied in a more digitized market facing better-resourced attackers.

The pattern across the Philippines’ breach data, the region’s spending and its uneven AI readiness is the same. The danger has shifted from stolen passwords to stolen identity faster than most businesses have adjusted.

Narrowing that gap doesn’t require a large IT department. It requires treating “who is really on the other end of this login” as a question worth asking again and again.

Gary Gardiner is the regional Solutions & Services director for APAC at Exclusive Networks, a global cybersecurity and cloud technology distributor that connects technology vendors with resellers, integrators and other channel partners. It provides cybersecurity solutions, technical support, training and professional services across markets worldwide, including the Asia-Pacific region.

View Original Article
Newswav Malaysia Best News App

Newswav is an online content aggregator and obtains its content from different online sources. The content in the app do not belong to Newswav nor do they reflect the opinions of Newswav and its staff. Your use of this app indicates your understanding and acceptance of this information.

Newswav Sdn. Bhd. (201701008480 (1222645-M)) 2026 All Rights Reserved