Berliner Boersenzeitung - Philippines health insurer hacked: What we know

EUR -
AED 4.196038
AFN 72.548266
ALL 93.983395
AMD 420.540936
ANG 2.045637
AOA 1048.866897
ARS 1669.851565
AUD 1.634419
AWG 2.056602
AZN 1.937156
BAM 1.951303
BBD 2.302094
BDT 140.416379
BGN 1.931927
BHD 0.430687
BIF 3410.531826
BMD 1.142557
BND 1.478193
BOB 7.897798
BRL 5.893083
BSD 1.142966
BTN 108.149745
BWP 15.512249
BYN 3.198029
BYR 22394.111824
BZD 2.298802
CAD 1.618202
CDF 2587.890714
CHF 0.924254
CLF 0.026315
CLP 1035.670747
CNY 7.740597
CNH 7.744546
COP 3936.165048
CRC 518.504991
CUC 1.142557
CUP 30.277753
CVE 110.685176
CZK 24.193414
DJF 203.055222
DKK 7.474488
DOP 66.610129
DZD 152.572485
EGP 56.826086
ERN 17.138351
ETB 184.276095
FJD 2.572241
FKP 0.863424
GBP 0.862613
GEL 3.027925
GGP 0.863424
GHS 12.830875
GIP 0.863424
GMD 83.406596
GNF 10028.78277
GTQ 8.715912
GYD 239.108921
HKD 8.957165
HNL 30.577527
HRK 7.533906
HTG 149.305892
HUF 352.232526
IDR 20500.89533
ILS 3.394936
IMP 0.863424
INR 108.201093
IQD 1497.349029
IRR 1571015.497997
ISK 144.00803
JEP 0.863424
JMD 180.603759
JOD 0.810112
JPY 184.584622
KES 147.86949
KGS 99.916444
KHR 4589.422662
KMF 490.726322
KPW 1028.301453
KRW 1759.417407
KWD 0.352661
KYD 0.952505
KZT 557.096049
LAK 25242.822342
LBP 102355.89823
LKR 382.189161
LRD 208.030548
LSL 18.780117
LTL 3.373673
LVL 0.691121
LYD 7.320609
MAD 10.655342
MDL 20.099676
MGA 4820.889196
MKD 61.629429
MMK 2399.275404
MNT 4089.475215
MOP 9.229529
MRU 45.702668
MUR 54.625306
MVR 17.66368
MWK 1983.478116
MXN 19.844495
MYR 4.7383
MZN 73.010218
NAD 18.780117
NGN 1561.486923
NIO 42.063056
NOK 11.086445
NPR 173.039193
NZD 2.002045
OMR 0.439314
PAB 1.142966
PEN 3.867586
PGK 5.092264
PHP 69.845651
PKR 317.897734
PLN 4.272876
PYG 6967.940842
QAR 4.166797
RON 5.237023
RSD 117.403487
RUB 84.835971
RWF 1674.041801
SAR 4.288919
SBD 9.210634
SCR 15.177226
SDG 686.108535
SEK 10.997611
SGD 1.478177
SHP 0.853034
SLE 28.278464
SLL 23958.847447
SOS 653.194569
SRD 42.766474
STD 23648.617409
STN 24.443664
SVC 10.000951
SYP 126.289192
SZL 18.775727
THB 37.670571
TJS 10.601367
TMT 3.998949
TND 3.379611
TOP 2.751003
TRY 53.095781
TTD 7.751136
TWD 36.221446
TZS 3002.904112
UAH 51.405724
UGX 4172.38382
USD 1.142557
UYU 45.704664
UZS 13698.428946
VES 693.112226
VND 30072.093021
VUV 135.22422
WST 3.144083
XAF 654.448679
XAG 0.01764
XAU 0.000273
XCD 3.087817
XCG 2.059952
XDR 0.813147
XOF 653.542317
XPF 119.331742
YER 272.615194
ZAR 18.751967
ZMK 10284.383366
ZMW 20.259308
ZWL 367.9028
  • RBGPF

    0.3600

    61.5

    +0.59%

  • CMSC

    -0.2100

    22.16

    -0.95%

  • CMSD

    -0.2100

    22.08

    -0.95%

  • BCE

    -0.6300

    22.65

    -2.78%

  • NGG

    1.5300

    80.97

    +1.89%

  • RELX

    -0.3500

    30.83

    -1.14%

  • VOD

    -0.1800

    14.12

    -1.27%

  • GSK

    0.0700

    50.74

    +0.14%

  • RYCEF

    0.1900

    18.45

    +1.03%

  • AZN

    1.5000

    176.43

    +0.85%

  • RIO

    -0.7200

    99.36

    -0.72%

  • JRI

    -0.0200

    12.65

    -0.16%

  • BTI

    -0.0100

    58.9

    -0.02%

  • BCC

    -2.1200

    72.54

    -2.92%

  • BP

    0.6800

    39.78

    +1.71%

Philippines health insurer hacked: What we know
Philippines health insurer hacked: What we know / Photo: JAM STA ROSA - AFP

Philippines health insurer hacked: What we know

Hackers have stolen the personal data of potentially millions of people from the Philippines's national health insurer, which has urged members to change their passwords after the "staggering" cyberattack.

Text size:

The hackers have started releasing files including confidential memos from the stolen data to pressure the government into paying a $300,000 ransom.

Here is what we know so far about the attack, which was discovered by the Philippine Health Insurance Corporation (PhilHealth) on September 22:

What did the hackers steal?

PhilHealth and the government have yet to say exactly how many people have been impacted, but the insurer warned members in a notice that data such as addresses, phone numbers and insurance IDs was compromised.

As of June 30, according to its website, PhilHealth had more than 59 million direct and indirect contributors -- more than half the population of the Philippines.

PhilHealth asked members to monitor credit card transactions and change passwords, especially for financial services.

Separately, employee information was also stolen from the targeted computers.

The hackers released some of the data on the dark web, showing health memos and other information that a top government official described as confidential.

An investigation into the scale of the attack is ongoing, but the National Privacy Commission has described the amount of data stolen as "staggering".

Who are the hackers, and what do they want?

The Philippine government has referred to the attackers as the Medusa group, who have demanded $300,000 to restore access to PhilHealth computers and delete the stolen data.

MedusaLocker, first detected in late 2019, has been used to mainly target healthcare organisations and its creators took particular advantage of the emergency situation during the Covid-19 pandemic, according to a US government report.

The ransomware has been sold to criminal actors, and a US government cybersecurity advisory said its creator receives a cut of any ransom.

It was not clear if the Medusa group identified by the Philippines government is the creator of or an entity that purchased MedusaLocker.

How did they get the data?

On September 22, PhilHealth staff were unable to access a number of computers, which displayed a message saying hackers had locked the machines and encrypted the data.

The insurer shut down the affected systems to try and stop the attack from spreading, slowing or entirely shutting down some online services for days.

The government has so far not said exactly how hackers got access to the computers.

But in interviews with local media last week, senior PhilHealth official Israel Pargas said the insurer did not have an antivirus software at the time of the attack.

How has the government responded?

With a blunt 'No'. The Philippines does not pay ransom in any criminal cases, including cyberattacks, officials have said.

However, with hackers releasing more data from the stolen files, calls have grown for the government to conduct an audit of its cyber defences.

The National Privacy Commission said Saturday it has started an investigation into any potential lapses and data law violations by PhilHealth.

The NPC said its analysis of 734 GB of stolen data revealed "sensitive personal data", and warned the public that anyone who downloads this information could face criminal charges.

(K.Müller--BBZ)