Cybersecurity Incidents in the Philippines Nearly Doubled, Official NPC Data Shows

MANILA, Philippines — Reported cybersecurity incidents in the Philippines nearly doubled between 2019 and 2025, according to data released by the National Privacy Commission (NPC), highlighting a steady increase in cyber-related incidents reported to the agency over the seven-year period. The dataset covers incidents involving hacking, phishing, ransomware, data breaches, and other cybersecurity-related events, and classifies each incident according to its primary cause. https://iili.io/CwFHoOb.jpg The figures were obtained by the Deep Web Konek (DWK) Team through a Freedom of Information (FOI) request submitted to the National Privacy Commission in December 2025. The request sought information on reported cybersecurity incidents from 2019 to 2025, including the types of incidents, annual incident counts, affected organizations, estimates of individuals affected, and the operational and financial impacts where available. While the NPC approved the request and released aggregated statistical data, it declined to disclose the identities of affected organizations, citing confidentiality and security obligations. According to the released figures, reported cybersecurity incidents increased from 183 cases in 2019 to 345 cases in 2025, representing an overall increase of nearly 89 percent. Reports rose to 232 in 2020 and 245 in 2021 before declining to 207 in 2022. The decrease, however, proved temporary, with incidents climbing to 283 in 2023, 343 in 2024, and 345 in 2025, the highest annual total recorded during the seven-year period. The data shows a sustained upward trend in reported cybersecurity incidents, particularly from 2023 onward. Among the recorded causes, Human Error consistently accounted for the largest share of reported cybersecurity incidents. Cases attributed to human error increased from 78 incidents in 2019 to 126 incidents in 2025, making it the leading category throughout the reporting period. The figures indicate that accidental mistakes, operational errors, misconfigurations, and other user-related factors continue to play a role in cybersecurity incidents reported to the Commission. Incidents classified under Malicious Attack also increased considerably during the same period. Cases rose from 73 incidents in 2019 to 149 incidents in 2025 despite a temporary decline in 2022. This category includes incidents involving hacking, phishing, ransomware, and other malicious cyber activities targeting organizations. Together, Human Error and Malicious Attack accounted for the majority of reported cybersecurity incidents throughout the seven-year dataset. The data also indicates that cybersecurity incidents are becoming more complex, with an increasing number of cases involving multiple contributing factors. Incidents attributed to both Malicious Attack and Human Error increased from no recorded cases in 2019 to 51 incidents in 2024 before slightly declining to 41 incidents in 2025. Likewise, incidents involving Malicious Attack and System Glitch, as well as System Glitch and Human Error, gradually increased over the reporting period, suggesting that many incidents resulted from a combination of technical vulnerabilities and human factors rather than a single cause. In contrast, incidents attributed solely to System Glitch remained comparatively low and generally declined throughout the reporting period. Reported system glitch incidents fell from 26 cases in 2019 to 10 cases in 2025, indicating that standalone technical failures accounted for a relatively small proportion of reported cybersecurity incidents compared with those involving human error or malicious activity. While the released data does not identify specific organizations, it provides an official year-by-year statistical overview of cybersecurity incidents reported to the National Privacy Commission between 2019 and 2025. The aggregated figures offer insight into overall cybersecurity incident trends and their primary causes, providing one of the few official snapshots of the country's reported cybersecurity landscape over the seven-year period.

Other contents

New Home For Deep Web Konek

New Home For Deep Web Konek

Cybersecurity Incidents in the Philippines Nearly Doubled, Official NPC Data Shows

Cybersecurity Incidents in the Philippines Nearly Doubled, Official NPC Data Shows

Alleged Data Breach Targets DENR's Mines and Geosciences Bureau

Alleged Data Breach Targets DENR's Mines and Geosciences Bureau

Alleged NTC Data Breach Claimed by DeathNote Hackers

Alleged NTC Data Breach Claimed by DeathNote Hackers

House of Representatives Website Defaced, Attackers Post Anti-Corruption Message

House of Representatives Website Defaced, Attackers Post Anti-Corruption Message

Philippine Army Fitness System Breach Exposed by DeathNote Hackers Member “Klammer”

Philippine Army Fitness System Breach Exposed by DeathNote Hackers Member “Klammer”

Senate Website Hit by Second Apparent Defacement, Threat Actor SentinelX Claims Responsibility

Senate Website Hit by Second Apparent Defacement, Threat Actor SentinelX Claims Responsibility

Viva Communications Allegedly Suffers Data Breach, 10GB of Internal Documents Claimed Leaked

Viva Communications Allegedly Suffers Data Breach, 10GB of Internal Documents Claimed Leaked

Philippine Government Joins Have I Been Pwned to Strengthen Cybersecurity Monitoring

Philippine Government Joins Have I Been Pwned to Strengthen Cybersecurity Monitoring

Nearly 1M DepEd Records Allegedly Exposed in Training Platform Breach, Claimed by NullSec Philippines

Nearly 1M DepEd Records Allegedly Exposed in Training Platform Breach, Claimed by NullSec Philippines