Qilin ransomware group claims data breach against Cagayan Appliance Center; second alleged Philippine target this week

MANILA, Philippines — The ransomware group Qilin has allegedly published internal files belonging to Cagayan Appliance Center on its leak portal on the dark web, signaling what appears to be the group’s second attack on a Philippine company in the same week. A screenshot of Qilin’s leak site circulating among cybersecurity observers shows a listing titled “Cagayan Appliance Center” accompanied by a file browser containing folders related to payroll records, inventory datasets, archived documents, and what appear to be internal company files. The group claims to have extracted more than 430 gigabytes of data during the intrusion. While the breach has not yet been confirmed publicly by the company, the structure and volume of the files displayed in the leak suggest a potentially significant compromise of proprietary and employee information. Several files visible include documents labeled with payroll, inventory, and system update tags, data typically stored only on internal networks. The claim follows a recent incident in which Qilin posted data allegedly belonging to AMH Philippines, a firm operating in the construction and engineering sector. That leak was indexed on December 7. Qilin is among the fastest-rising actors in the ransomware landscape this year. Experts note a surge in activity after the shutdowns of other ransomware-as-a-service groups, which may have displaced operators and affiliates and accelerated Qilin’s expansion. The group is known for double-extortion tactics, where attackers not only encrypt company systems but also threaten to publish stolen data to pressure organizations into paying. There is currently no public statement from Cagayan Appliance Center regarding the breach, whether law enforcement has been notified, or if the company has engaged with the attackers. The Philippine cybersecurity sector has increased alerts in recent months as more local companies — especially regional retail, logistics, and professional services firms — become targets of global ransomware operations.

Other contents

New Home For Deep Web Konek

New Home For Deep Web Konek

Alleged NTC Data Breach Claimed by DeathNote Hackers

Alleged NTC Data Breach Claimed by DeathNote Hackers

House of Representatives Website Defaced, Attackers Post Anti-Corruption Message

House of Representatives Website Defaced, Attackers Post Anti-Corruption Message

Philippine Army Fitness System Breach Exposed by DeathNote Hackers Member “Klammer”

Philippine Army Fitness System Breach Exposed by DeathNote Hackers Member “Klammer”

Senate Website Hit by Second Apparent Defacement, Threat Actor SentinelX Claims Responsibility

Senate Website Hit by Second Apparent Defacement, Threat Actor SentinelX Claims Responsibility

Viva Communications Allegedly Suffers Data Breach, 10GB of Internal Documents Claimed Leaked

Viva Communications Allegedly Suffers Data Breach, 10GB of Internal Documents Claimed Leaked

Philippine Government Joins Have I Been Pwned to Strengthen Cybersecurity Monitoring

Philippine Government Joins Have I Been Pwned to Strengthen Cybersecurity Monitoring

Nearly 1M DepEd Records Allegedly Exposed in Training Platform Breach, Claimed by NullSec Philippines

Nearly 1M DepEd Records Allegedly Exposed in Training Platform Breach, Claimed by NullSec Philippines

Philippine Drug Enforcement Agency Data Breached; Threat Actor Issues 48-Hour Ultimatum

Philippine Drug Enforcement Agency Data Breached; Threat Actor Issues 48-Hour Ultimatum

Alleged 13-Million Philippine Data Leak Emerges, Retail and Payment Ecosystem Under Investigation

Alleged 13-Million Philippine Data Leak Emerges, Retail and Payment Ecosystem Under Investigation