The China Mail - Philippines health insurer hacked: What we know

USD -
AED 3.673042
AFN 65.503991
ALL 82.250403
AMD 381.770403
ANG 1.790403
AOA 917.000367
ARS 1440.198104
AUD 1.502404
AWG 1.8
AZN 1.70397
BAM 1.668223
BBD 2.014603
BDT 122.238002
BGN 1.66581
BHD 0.375335
BIF 2965
BMD 1
BND 1.291806
BOB 6.911523
BRL 5.419704
BSD 1.000264
BTN 90.4571
BWP 13.253269
BYN 2.948763
BYR 19600
BZD 2.011703
CAD 1.37805
CDF 2240.000362
CHF 0.795992
CLF 0.023203
CLP 910.250396
CNY 7.054504
CNH 7.05355
COP 3803.5
CRC 500.345448
CUC 1
CUP 26.5
CVE 94.27504
CZK 20.669104
DJF 177.720393
DKK 6.361804
DOP 63.850393
DZD 129.69404
EGP 47.313439
ERN 15
ETB 155.22504
EUR 0.851404
FJD 2.26525
FKP 0.744826
GBP 0.747831
GEL 2.703861
GGP 0.744826
GHS 11.48504
GIP 0.744826
GMD 73.000355
GNF 8691.000355
GTQ 7.661306
GYD 209.264835
HKD 7.77985
HNL 26.203838
HRK 6.417704
HTG 131.108249
HUF 327.990388
IDR 16633.75
ILS 3.222795
IMP 0.744826
INR 90.552404
IQD 1310
IRR 42122.503816
ISK 126.403814
JEP 0.744826
JMD 160.152168
JOD 0.70904
JPY 155.75604
KES 128.903801
KGS 87.450384
KHR 4006.00035
KMF 419.503794
KPW 899.99623
KRW 1474.980383
KWD 0.306704
KYD 0.833596
KZT 521.66941
LAK 21680.000349
LBP 89550.000349
LKR 309.078037
LRD 177.025039
LSL 16.880381
LTL 2.95274
LVL 0.60489
LYD 5.420381
MAD 9.19125
MDL 16.909049
MGA 4510.000347
MKD 52.398791
MMK 2100.268185
MNT 3547.376613
MOP 8.020795
MRU 39.740379
MUR 45.903741
MVR 15.403739
MWK 1736.503736
MXN 18.014404
MYR 4.097304
MZN 63.910377
NAD 16.880377
NGN 1452.570377
NIO 36.775039
NOK 10.137304
NPR 144.731702
NZD 1.72295
OMR 0.382805
PAB 1.000264
PEN 3.603708
PGK 4.259204
PHP 59.115038
PKR 280.225038
PLN 3.59745
PYG 6718.782652
QAR 3.641104
RON 4.335904
RSD 99.975303
RUB 79.673577
RWF 1451
SAR 3.75231
SBD 8.176752
SCR 14.958069
SDG 601.503676
SEK 9.269904
SGD 1.292038
SHP 0.750259
SLE 24.125038
SLL 20969.503664
SOS 571.503662
SRD 38.548038
STD 20697.981008
STN 21.25
SVC 8.752207
SYP 11058.380716
SZL 16.880369
THB 31.520369
TJS 9.192334
TMT 3.51
TND 2.916038
TOP 2.40776
TRY 42.696104
TTD 6.787844
TWD 31.335104
TZS 2470.000335
UAH 42.263496
UGX 3555.146134
UYU 39.25315
UZS 12002.503617
VES 267.43975
VND 26306
VUV 121.486164
WST 2.783946
XAF 559.50409
XAG 0.016138
XAU 0.000232
XCD 2.70255
XCG 1.802728
XDR 0.695185
XOF 558.000332
XPF 102.075037
YER 238.503589
ZAR 16.875405
ZMK 9001.203584
ZMW 23.081057
ZWL 321.999592
  • SCS

    0.0200

    16.14

    +0.12%

  • RBGPF

    0.0000

    81.17

    0%

  • BCC

    0.2500

    76.51

    +0.33%

  • BTI

    -1.2700

    57.1

    -2.22%

  • VOD

    0.0500

    12.59

    +0.4%

  • GSK

    -0.0700

    48.81

    -0.14%

  • NGG

    0.2400

    74.93

    +0.32%

  • RIO

    -1.0800

    75.66

    -1.43%

  • RYCEF

    -0.2500

    14.6

    -1.71%

  • CMSC

    -0.1300

    23.3

    -0.56%

  • RELX

    0.1000

    40.38

    +0.25%

  • BCE

    0.3100

    23.71

    +1.31%

  • JRI

    -0.0200

    13.7

    -0.15%

  • AZN

    -0.4600

    89.83

    -0.51%

  • CMSD

    -0.1500

    23.25

    -0.65%

  • BP

    -0.2700

    35.26

    -0.77%

Philippines health insurer hacked: What we know
Philippines health insurer hacked: What we know / Photo: © AFP

Philippines health insurer hacked: What we know

Hackers have stolen the personal data of potentially millions of people from the Philippines's national health insurer, which has urged members to change their passwords after the "staggering" cyberattack.

Text size:

The hackers have started releasing files including confidential memos from the stolen data to pressure the government into paying a $300,000 ransom.

Here is what we know so far about the attack, which was discovered by the Philippine Health Insurance Corporation (PhilHealth) on September 22:

What did the hackers steal?

PhilHealth and the government have yet to say exactly how many people have been impacted, but the insurer warned members in a notice that data such as addresses, phone numbers and insurance IDs was compromised.

As of June 30, according to its website, PhilHealth had more than 59 million direct and indirect contributors -- more than half the population of the Philippines.

PhilHealth asked members to monitor credit card transactions and change passwords, especially for financial services.

Separately, employee information was also stolen from the targeted computers.

The hackers released some of the data on the dark web, showing health memos and other information that a top government official described as confidential.

An investigation into the scale of the attack is ongoing, but the National Privacy Commission has described the amount of data stolen as "staggering".

Who are the hackers, and what do they want?

The Philippine government has referred to the attackers as the Medusa group, who have demanded $300,000 to restore access to PhilHealth computers and delete the stolen data.

MedusaLocker, first detected in late 2019, has been used to mainly target healthcare organisations and its creators took particular advantage of the emergency situation during the Covid-19 pandemic, according to a US government report.

The ransomware has been sold to criminal actors, and a US government cybersecurity advisory said its creator receives a cut of any ransom.

It was not clear if the Medusa group identified by the Philippines government is the creator of or an entity that purchased MedusaLocker.

How did they get the data?

On September 22, PhilHealth staff were unable to access a number of computers, which displayed a message saying hackers had locked the machines and encrypted the data.

The insurer shut down the affected systems to try and stop the attack from spreading, slowing or entirely shutting down some online services for days.

The government has so far not said exactly how hackers got access to the computers.

But in interviews with local media last week, senior PhilHealth official Israel Pargas said the insurer did not have an antivirus software at the time of the attack.

How has the government responded?

With a blunt 'No'. The Philippines does not pay ransom in any criminal cases, including cyberattacks, officials have said.

However, with hackers releasing more data from the stolen files, calls have grown for the government to conduct an audit of its cyber defences.

The National Privacy Commission said Saturday it has started an investigation into any potential lapses and data law violations by PhilHealth.

The NPC said its analysis of 734 GB of stolen data revealed "sensitive personal data", and warned the public that anyone who downloads this information could face criminal charges.

H.Ng--ThChM