The China Mail - Philippines health insurer hacked: What we know

USD -
AED 3.673028
AFN 71.999738
ALL 87.274775
AMD 390.940193
ANG 1.80229
AOA 912.000387
ARS 1137.970101
AUD 1.565349
AWG 1.8
AZN 1.704736
BAM 1.720686
BBD 2.017877
BDT 121.428069
BGN 1.721593
BHD 0.376901
BIF 2930
BMD 1
BND 1.312071
BOB 6.906563
BRL 5.808198
BSD 0.999437
BTN 85.314611
BWP 13.77569
BYN 3.270808
BYR 19600
BZD 2.007496
CAD 1.384165
CDF 2877.000155
CHF 0.81849
CLF 0.025203
CLP 967.160244
CNY 7.300902
CNH 7.30369
COP 4310
CRC 502.269848
CUC 1
CUP 26.5
CVE 97.398863
CZK 22.038604
DJF 177.719867
DKK 6.56557
DOP 60.50261
DZD 132.565985
EGP 51.126903
ERN 15
ETB 133.023649
EUR 0.879325
FJD 2.283695
FKP 0.752659
GBP 0.753835
GEL 2.73998
GGP 0.752659
GHS 15.559986
GIP 0.752659
GMD 71.49558
GNF 8655.50116
GTQ 7.698128
GYD 209.656701
HKD 7.76252
HNL 25.908819
HRK 6.612098
HTG 130.419482
HUF 359.104997
IDR 16862.9
ILS 3.68395
IMP 0.752659
INR 85.3775
IQD 1310
IRR 42125.000166
ISK 127.589825
JEP 0.752659
JMD 157.965583
JOD 0.709303
JPY 142.17103
KES 129.498782
KGS 87.233498
KHR 4014.999894
KMF 433.489626
KPW 899.999997
KRW 1418.390422
KWD 0.30663
KYD 0.832893
KZT 523.173564
LAK 21630.000202
LBP 89600.000147
LKR 298.915224
LRD 199.974974
LSL 18.856894
LTL 2.95274
LVL 0.60489
LYD 5.470035
MAD 9.274983
MDL 17.289555
MGA 4552.892736
MKD 54.091003
MMK 2099.344606
MNT 3566.297198
MOP 7.990393
MRU 39.435529
MUR 45.089881
MVR 15.404613
MWK 1735.99973
MXN 19.72174
MYR 4.4075
MZN 63.905028
NAD 18.856894
NGN 1604.703383
NIO 36.775056
NOK 10.481075
NPR 136.503202
NZD 1.685133
OMR 0.384998
PAB 0.999437
PEN 3.763008
PGK 4.133235
PHP 56.712501
PKR 280.585566
PLN 3.762405
PYG 7999.894426
QAR 3.640595
RON 4.3781
RSD 103.137317
RUB 82.174309
RWF 1415
SAR 3.752237
SBD 8.368347
SCR 14.241693
SDG 600.500338
SEK 9.63369
SGD 1.310745
SHP 0.785843
SLE 22.774982
SLL 20969.483762
SOS 571.501393
SRD 37.149757
STD 20697.981008
SVC 8.745073
SYP 13001.855093
SZL 18.820132
THB 33.34705
TJS 10.733754
TMT 3.5
TND 2.987989
TOP 2.342097
TRY 38.12382
TTD 6.781391
TWD 32.524004
TZS 2687.499532
UAH 41.417687
UGX 3663.55798
UYU 41.913007
UZS 12986.521678
VES 80.85863
VND 25870
VUV 120.966432
WST 2.777003
XAF 577.111964
XAG 0.03066
XAU 0.000301
XCD 2.70255
XDR 0.717698
XOF 574.999952
XPF 102.774989
YER 245.2496
ZAR 18.839673
ZMK 9001.195457
ZMW 28.458439
ZWL 321.999592
  • CMSD

    0.0400

    21.96

    +0.18%

  • NGG

    0.6300

    72.11

    +0.87%

  • BCC

    0.7800

    93.47

    +0.83%

  • GSK

    0.5600

    35.93

    +1.56%

  • CMSC

    0.0400

    21.82

    +0.18%

  • JRI

    0.1600

    12.4

    +1.29%

  • BTI

    0.5400

    42.37

    +1.27%

  • SCS

    0.0500

    9.76

    +0.51%

  • AZN

    0.5400

    67.59

    +0.8%

  • RIO

    1.0100

    58.17

    +1.74%

  • RELX

    1.0000

    52.2

    +1.92%

  • RBGPF

    63.5900

    63.59

    +100%

  • BCE

    0.4200

    22.04

    +1.91%

  • RYCEF

    -0.1400

    9.36

    -1.5%

  • VOD

    0.1350

    9.305

    +1.45%

  • BP

    0.6600

    28.32

    +2.33%

Philippines health insurer hacked: What we know
Philippines health insurer hacked: What we know / Photo: © AFP

Philippines health insurer hacked: What we know

Hackers have stolen the personal data of potentially millions of people from the Philippines's national health insurer, which has urged members to change their passwords after the "staggering" cyberattack.

Text size:

The hackers have started releasing files including confidential memos from the stolen data to pressure the government into paying a $300,000 ransom.

Here is what we know so far about the attack, which was discovered by the Philippine Health Insurance Corporation (PhilHealth) on September 22:

What did the hackers steal?

PhilHealth and the government have yet to say exactly how many people have been impacted, but the insurer warned members in a notice that data such as addresses, phone numbers and insurance IDs was compromised.

As of June 30, according to its website, PhilHealth had more than 59 million direct and indirect contributors -- more than half the population of the Philippines.

PhilHealth asked members to monitor credit card transactions and change passwords, especially for financial services.

Separately, employee information was also stolen from the targeted computers.

The hackers released some of the data on the dark web, showing health memos and other information that a top government official described as confidential.

An investigation into the scale of the attack is ongoing, but the National Privacy Commission has described the amount of data stolen as "staggering".

Who are the hackers, and what do they want?

The Philippine government has referred to the attackers as the Medusa group, who have demanded $300,000 to restore access to PhilHealth computers and delete the stolen data.

MedusaLocker, first detected in late 2019, has been used to mainly target healthcare organisations and its creators took particular advantage of the emergency situation during the Covid-19 pandemic, according to a US government report.

The ransomware has been sold to criminal actors, and a US government cybersecurity advisory said its creator receives a cut of any ransom.

It was not clear if the Medusa group identified by the Philippines government is the creator of or an entity that purchased MedusaLocker.

How did they get the data?

On September 22, PhilHealth staff were unable to access a number of computers, which displayed a message saying hackers had locked the machines and encrypted the data.

The insurer shut down the affected systems to try and stop the attack from spreading, slowing or entirely shutting down some online services for days.

The government has so far not said exactly how hackers got access to the computers.

But in interviews with local media last week, senior PhilHealth official Israel Pargas said the insurer did not have an antivirus software at the time of the attack.

How has the government responded?

With a blunt 'No'. The Philippines does not pay ransom in any criminal cases, including cyberattacks, officials have said.

However, with hackers releasing more data from the stolen files, calls have grown for the government to conduct an audit of its cyber defences.

The National Privacy Commission said Saturday it has started an investigation into any potential lapses and data law violations by PhilHealth.

The NPC said its analysis of 734 GB of stolen data revealed "sensitive personal data", and warned the public that anyone who downloads this information could face criminal charges.

H.Ng--ThChM