iTnews Asia
  • Home
  • News
  • Security

Phillippine Statistics Authority suffers data breach

Phillippine Statistics Authority suffers data breach

Even as government deals with ransomware attack on PhilHealth.

By Abbinaya Kuzhanthaivel on Oct 11, 2023 9:00PM

The Philippine Statistics Authority (PSA) is the next to suffer a data breach amid rising cybersecurity concerns in the country stemming from the Medusa ransomware attack on the Philippine Health Insurance Corporation (PhilHealth).

PSA filed a breach notification to the National Privacy Commission (NPC) soon after blurred photos of IDs and large volumes of data allegedly pilfered from a PSA database surfaced online in a social media post.

PhilHealth and PSA had earlier in 2021 formalised a joint undertaking on data sharing of death information records. The agreement enabled PhilHealth to provide PSA with electronic lists of identified members and their dependents which would then be matched with the latter’s death records.

While PSA is assessing what personal data may have been compromised, an initial review showed the breach may be limited to its community-based monitoring system that collects and processes data for local government planning.

The Philippine Identification System (PhilSys) and the civil registration system have not been affected, PSA said in a statement.

“The agency is taking additional preventive and containment measures to ensure the security and integrity of all systems and databases that it manages, including shutting down and isolating the system known to have been affected,” it added.

PSA is coordinating with NPC, DICT and the Anti-Cybercrime Group of the Philippine National Police (PNP) to probe the matter.

The stat board has warned the public that social media posts with the alleged sample data could include links that contain malware that cybercriminals and bad actors may use to perpetuate other illicit acts.

Philippines Department of Information and Communications Technology (DICT) Secretary Ivan John Uy said the attack was a data breach and did not involve "ransomware" like the Medusa on PhilHealth.

Rising concerns

The NPC earlier this week said it discovered over 700 gigabytes (GB) extracted from a data dump claimed to be from the Medusa hacker group. Hackers had started circulating illegally obtained PhilHealth's data from the workstations of PhilHealth employees.

The commission had called for individuals who had their personal data stolen in the Medusa attack on PhilHealth to file a complaint and "if proven can claim damages".

The insurer advised its members to change the passwords of their online accounts, enable multi-factor authentication, and avoid responding to suspicious calls and text messages.

De La Salle University incident

In another incident, De La Salle University in Manila, Philippines also experienced a cyber attack on October 9 that affected its on-premise applications.

The university said student records and cloud-hosted applications remained intact.

“A number of steps have been taken as preventive measures. These include taking network systems offline to prevent further exposure, restricting the use of DLSU-issued computers and laptops, and requiring the activation of additional security features on the Google workspace accounts,” it added.

DLSU has tapped a global cybersecurity company to investigate the incident and restore its network systems.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
© iTnews Asia
Tags:
de la salle university national privacy commission philhealth philippine national police philippine statistics authority philsys security

Related Articles

  • Your organisation’s physical security can be a gateway for cybercriminals
  • The best way to outsmart your threat actors is to think like one
  • How cybercriminals are exploiting LLMs to harm your business
  • Is identity now the next parameter of cybersecurity breaches?
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Your organisation’s physical security can be a gateway for cybercriminals

Your organisation’s physical security can be a gateway for cybercriminals

Malaysia's Maxis Berhad investigates claims on alleged data breach

Malaysia's Maxis Berhad investigates claims on alleged data breach

DBS plans US$58 million investment to improve technology resilience

DBS plans US$58 million investment to improve technology resilience

Philippines Maxicare, Jollibee Foods Corporation hit by data breach

Philippines Maxicare, Jollibee Foods Corporation hit by data breach

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.