The Fort Worth Press - Philippines health insurer hacked: What we know

USD -
AED 3.673042
AFN 67.000368
ALL 93.103989
AMD 388.250403
ANG 1.803449
AOA 912.000367
ARS 998.514239
AUD 1.547161
AWG 1.795
AZN 1.70397
BAM 1.850279
BBD 2.020472
BDT 119.580334
BGN 1.852849
BHD 0.376902
BIF 2898.5
BMD 1
BND 1.341507
BOB 6.914723
BRL 5.796904
BSD 1.000634
BTN 84.073433
BWP 13.679968
BYN 3.274772
BYR 19600
BZD 2.017086
CAD 1.40779
CDF 2865.000362
CHF 0.886704
CLF 0.035534
CLP 980.503912
CNY 7.232504
CNH 7.23455
COP 4442.25
CRC 509.261887
CUC 1
CUP 26.5
CVE 104.850394
CZK 23.936304
DJF 177.720393
DKK 7.070475
DOP 60.403884
DZD 133.36178
EGP 49.356804
ERN 15
ETB 122.000358
EUR 0.94797
FJD 2.27595
FKP 0.789317
GBP 0.791875
GEL 2.73504
GGP 0.789317
GHS 15.95039
GIP 0.789317
GMD 71.000355
GNF 8630.000355
GTQ 7.728257
GYD 209.258103
HKD 7.78573
HNL 25.12504
HRK 7.133259
HTG 131.547827
HUF 386.85904
IDR 15900
ILS 3.749604
IMP 0.789317
INR 84.44345
IQD 1310.5
IRR 42092.503816
ISK 137.550386
JEP 0.789317
JMD 158.916965
JOD 0.709104
JPY 154.17704
KES 129.503801
KGS 86.503799
KHR 4050.00035
KMF 466.575039
KPW 899.999621
KRW 1395.970383
KWD 0.30752
KYD 0.833948
KZT 497.28482
LAK 21953.000349
LBP 89550.000349
LKR 292.337966
LRD 184.000348
LSL 18.220381
LTL 2.95274
LVL 0.60489
LYD 4.875039
MAD 10.013504
MDL 18.182248
MGA 4665.000347
MKD 58.285952
MMK 3247.960992
MNT 3397.999946
MOP 8.023973
MRU 39.960379
MUR 47.210378
MVR 15.450378
MWK 1736.000345
MXN 20.347039
MYR 4.470504
MZN 63.903729
NAD 18.220377
NGN 1665.000344
NIO 36.765039
NOK 11.080704
NPR 134.517795
NZD 1.70461
OMR 0.385025
PAB 1.000643
PEN 3.803039
PGK 4.01975
PHP 58.726038
PKR 277.703701
PLN 4.091755
PYG 7807.725419
QAR 3.640604
RON 4.717904
RSD 110.903038
RUB 100.051477
RWF 1369
SAR 3.755981
SBD 8.390419
SCR 14.705038
SDG 601.503676
SEK 10.96796
SGD 1.341675
SHP 0.789317
SLE 22.603667
SLL 20969.504736
SOS 571.503662
SRD 35.315504
STD 20697.981008
SVC 8.755664
SYP 2512.529858
SZL 18.220369
THB 34.816504
TJS 10.667159
TMT 3.51
TND 3.157504
TOP 2.342104
TRY 34.438704
TTD 6.794573
TWD 32.504504
TZS 2660.000335
UAH 41.333087
UGX 3672.554232
UYU 42.941477
UZS 12835.000334
VES 45.450217
VND 25390
VUV 118.722009
WST 2.791591
XAF 620.560244
XAG 0.033031
XAU 0.00039
XCD 2.70255
XDR 0.753817
XOF 619.503595
XPF 113.550363
YER 249.875037
ZAR 18.207037
ZMK 9001.203587
ZMW 27.473463
ZWL 321.999592
  • RBGPF

    1.6500

    61.84

    +2.67%

  • CMSC

    -0.0300

    24.52

    -0.12%

  • RYCEF

    0.0100

    6.8

    +0.15%

  • NGG

    0.1750

    62.545

    +0.28%

  • GSK

    -0.6259

    33.375

    -1.88%

  • RELX

    -1.5200

    44.43

    -3.42%

  • AZN

    -1.5200

    63.52

    -2.39%

  • VOD

    0.0750

    8.755

    +0.86%

  • RIO

    0.5900

    61.02

    +0.97%

  • BP

    -0.1300

    28.92

    -0.45%

  • CMSD

    0.0022

    24.36

    +0.01%

  • BTI

    0.9190

    36.409

    +2.52%

  • SCS

    0.0400

    13.31

    +0.3%

  • BCE

    0.0850

    26.925

    +0.32%

  • BCC

    -0.0640

    140.286

    -0.05%

  • JRI

    -0.0365

    13.04

    -0.28%

Philippines health insurer hacked: What we know
Philippines health insurer hacked: What we know / Photo: © AFP

Philippines health insurer hacked: What we know

Hackers have stolen the personal data of potentially millions of people from the Philippines's national health insurer, which has urged members to change their passwords after the "staggering" cyberattack.

Text size:

The hackers have started releasing files including confidential memos from the stolen data to pressure the government into paying a $300,000 ransom.

Here is what we know so far about the attack, which was discovered by the Philippine Health Insurance Corporation (PhilHealth) on September 22:

What did the hackers steal?

PhilHealth and the government have yet to say exactly how many people have been impacted, but the insurer warned members in a notice that data such as addresses, phone numbers and insurance IDs was compromised.

As of June 30, according to its website, PhilHealth had more than 59 million direct and indirect contributors -- more than half the population of the Philippines.

PhilHealth asked members to monitor credit card transactions and change passwords, especially for financial services.

Separately, employee information was also stolen from the targeted computers.

The hackers released some of the data on the dark web, showing health memos and other information that a top government official described as confidential.

An investigation into the scale of the attack is ongoing, but the National Privacy Commission has described the amount of data stolen as "staggering".

Who are the hackers, and what do they want?

The Philippine government has referred to the attackers as the Medusa group, who have demanded $300,000 to restore access to PhilHealth computers and delete the stolen data.

MedusaLocker, first detected in late 2019, has been used to mainly target healthcare organisations and its creators took particular advantage of the emergency situation during the Covid-19 pandemic, according to a US government report.

The ransomware has been sold to criminal actors, and a US government cybersecurity advisory said its creator receives a cut of any ransom.

It was not clear if the Medusa group identified by the Philippines government is the creator of or an entity that purchased MedusaLocker.

How did they get the data?

On September 22, PhilHealth staff were unable to access a number of computers, which displayed a message saying hackers had locked the machines and encrypted the data.

The insurer shut down the affected systems to try and stop the attack from spreading, slowing or entirely shutting down some online services for days.

The government has so far not said exactly how hackers got access to the computers.

But in interviews with local media last week, senior PhilHealth official Israel Pargas said the insurer did not have an antivirus software at the time of the attack.

How has the government responded?

With a blunt 'No'. The Philippines does not pay ransom in any criminal cases, including cyberattacks, officials have said.

However, with hackers releasing more data from the stolen files, calls have grown for the government to conduct an audit of its cyber defences.

The National Privacy Commission said Saturday it has started an investigation into any potential lapses and data law violations by PhilHealth.

The NPC said its analysis of 734 GB of stolen data revealed "sensitive personal data", and warned the public that anyone who downloads this information could face criminal charges.

S.Jordan--TFWP