The China Mail - Philippines health insurer hacked: What we know

USD -
AED 3.672498
AFN 68.253087
ALL 83.11189
AMD 382.193361
ANG 1.789783
AOA 916.99985
ARS 1296.395062
AUD 1.535403
AWG 1.80075
AZN 1.705074
BAM 1.671124
BBD 2.016064
BDT 121.314137
BGN 1.671124
BHD 0.376469
BIF 2977.656257
BMD 1
BND 1.280215
BOB 6.899645
BRL 5.400604
BSD 0.998505
BTN 87.326014
BWP 13.362669
BYN 3.331055
BYR 19600
BZD 2.005639
CAD 1.381345
CDF 2895.000142
CHF 0.80684
CLF 0.024576
CLP 964.102833
CNY 7.182097
CNH 7.18821
COP 4046.91
CRC 504.549921
CUC 1
CUP 26.5
CVE 94.215406
CZK 20.90895
DJF 177.810057
DKK 6.377302
DOP 61.460247
DZD 129.567223
EGP 48.264095
ERN 15
ETB 140.628786
EUR 0.854415
FJD 2.255898
FKP 0.737781
GBP 0.73775
GEL 2.689909
GGP 0.737781
GHS 10.833511
GIP 0.737781
GMD 72.501722
GNF 8657.239287
GTQ 7.658393
GYD 208.817875
HKD 7.82526
HNL 26.13748
HRK 6.436502
HTG 130.653223
HUF 337.623501
IDR 16203
ILS 3.38481
IMP 0.737781
INR 87.513498
IQD 1307.984791
IRR 42112.500758
ISK 122.349518
JEP 0.737781
JMD 159.772718
JOD 0.708995
JPY 147.402497
KES 128.999851
KGS 87.378795
KHR 3999.658222
KMF 420.496617
KPW 900.000002
KRW 1388.629879
KWD 0.30547
KYD 0.832059
KZT 540.872389
LAK 21611.483744
LBP 89415.132225
LKR 300.542573
LRD 200.196522
LSL 17.559106
LTL 2.95274
LVL 0.60489
LYD 5.400094
MAD 8.995172
MDL 16.64972
MGA 4442.260862
MKD 52.578289
MMK 2099.537865
MNT 3596.792519
MOP 8.046653
MRU 39.940189
MUR 45.640147
MVR 15.40998
MWK 1731.362413
MXN 18.723725
MYR 4.215014
MZN 63.902594
NAD 17.559106
NGN 1529.190073
NIO 36.741146
NOK 10.18954
NPR 139.721451
NZD 1.6859
OMR 0.384218
PAB 0.998505
PEN 3.559106
PGK 4.154313
PHP 57.06101
PKR 283.287734
PLN 3.638942
PYG 7312.342462
QAR 3.640364
RON 4.327099
RSD 100.123895
RUB 79.692505
RWF 1445.80681
SAR 3.752502
SBD 8.223773
SCR 14.949545
SDG 600.500052
SEK 9.554045
SGD 1.282855
SHP 0.785843
SLE 23.301031
SLL 20969.49797
SOS 570.598539
SRD 37.56003
STD 20697.981008
STN 20.933909
SVC 8.736703
SYP 13001.821653
SZL 17.553723
THB 32.43996
TJS 9.310975
TMT 3.51
TND 2.918187
TOP 2.342102
TRY 40.90224
TTD 6.774896
TWD 30.003969
TZS 2608.535974
UAH 41.211005
UGX 3554.492246
UYU 39.945316
UZS 12562.908532
VES 135.47035
VND 26270
VUV 119.143454
WST 2.766276
XAF 560.479344
XAG 0.026373
XAU 0.0003
XCD 2.70255
XCG 1.799547
XDR 0.697056
XOF 560.479344
XPF 101.901141
YER 240.274983
ZAR 17.589925
ZMK 9001.198309
ZMW 23.140086
ZWL 321.999592
  • RBGPF

    2.8400

    75.92

    +3.74%

  • CMSD

    0.0505

    23.34

    +0.22%

  • SCS

    -0.0500

    16.15

    -0.31%

  • BCC

    -0.6300

    85.99

    -0.73%

  • NGG

    -0.1300

    71.43

    -0.18%

  • RIO

    0.2000

    61.24

    +0.33%

  • RYCEF

    -0.2100

    14.71

    -1.43%

  • CMSC

    0.0300

    23.12

    +0.13%

  • RELX

    0.2700

    47.96

    +0.56%

  • GSK

    0.5581

    39.36

    +1.42%

  • BCE

    0.2400

    25.61

    +0.94%

  • JRI

    0.0835

    13.36

    +0.62%

  • AZN

    0.7000

    79.17

    +0.88%

  • BP

    0.1892

    34.33

    +0.55%

  • BTI

    -0.2700

    57.15

    -0.47%

  • VOD

    0.0300

    11.67

    +0.26%

Philippines health insurer hacked: What we know
Philippines health insurer hacked: What we know / Photo: © AFP

Philippines health insurer hacked: What we know

Hackers have stolen the personal data of potentially millions of people from the Philippines's national health insurer, which has urged members to change their passwords after the "staggering" cyberattack.

Text size:

The hackers have started releasing files including confidential memos from the stolen data to pressure the government into paying a $300,000 ransom.

Here is what we know so far about the attack, which was discovered by the Philippine Health Insurance Corporation (PhilHealth) on September 22:

What did the hackers steal?

PhilHealth and the government have yet to say exactly how many people have been impacted, but the insurer warned members in a notice that data such as addresses, phone numbers and insurance IDs was compromised.

As of June 30, according to its website, PhilHealth had more than 59 million direct and indirect contributors -- more than half the population of the Philippines.

PhilHealth asked members to monitor credit card transactions and change passwords, especially for financial services.

Separately, employee information was also stolen from the targeted computers.

The hackers released some of the data on the dark web, showing health memos and other information that a top government official described as confidential.

An investigation into the scale of the attack is ongoing, but the National Privacy Commission has described the amount of data stolen as "staggering".

Who are the hackers, and what do they want?

The Philippine government has referred to the attackers as the Medusa group, who have demanded $300,000 to restore access to PhilHealth computers and delete the stolen data.

MedusaLocker, first detected in late 2019, has been used to mainly target healthcare organisations and its creators took particular advantage of the emergency situation during the Covid-19 pandemic, according to a US government report.

The ransomware has been sold to criminal actors, and a US government cybersecurity advisory said its creator receives a cut of any ransom.

It was not clear if the Medusa group identified by the Philippines government is the creator of or an entity that purchased MedusaLocker.

How did they get the data?

On September 22, PhilHealth staff were unable to access a number of computers, which displayed a message saying hackers had locked the machines and encrypted the data.

The insurer shut down the affected systems to try and stop the attack from spreading, slowing or entirely shutting down some online services for days.

The government has so far not said exactly how hackers got access to the computers.

But in interviews with local media last week, senior PhilHealth official Israel Pargas said the insurer did not have an antivirus software at the time of the attack.

How has the government responded?

With a blunt 'No'. The Philippines does not pay ransom in any criminal cases, including cyberattacks, officials have said.

However, with hackers releasing more data from the stolen files, calls have grown for the government to conduct an audit of its cyber defences.

The National Privacy Commission said Saturday it has started an investigation into any potential lapses and data law violations by PhilHealth.

The NPC said its analysis of 734 GB of stolen data revealed "sensitive personal data", and warned the public that anyone who downloads this information could face criminal charges.

H.Ng--ThChM