Zürcher Nachrichten - Philippines health insurer hacked: What we know

EUR -
AED 4.356256
AFN 77.102519
ALL 96.729833
AMD 453.280378
ANG 2.123363
AOA 1087.730931
ARS 1716.407515
AUD 1.703027
AWG 2.138096
AZN 2.01145
BAM 1.957011
BBD 2.40819
BDT 146.110377
BGN 1.992042
BHD 0.449378
BIF 3542.291098
BMD 1.186184
BND 1.514237
BOB 8.262111
BRL 6.235172
BSD 1.19564
BTN 109.797916
BWP 15.644677
BYN 3.405506
BYR 23249.200887
BZD 2.404687
CAD 1.615618
CDF 2686.705937
CHF 0.916565
CLF 0.026028
CLP 1027.744898
CNY 8.246052
CNH 8.251497
COP 4352.992561
CRC 592.066225
CUC 1.186184
CUP 31.433869
CVE 110.333247
CZK 24.330941
DJF 212.911697
DKK 7.467917
DOP 75.276563
DZD 154.566608
EGP 55.909475
ERN 17.792756
ETB 185.73929
FJD 2.61512
FKP 0.866428
GBP 0.866359
GEL 3.196822
GGP 0.866428
GHS 13.098102
GIP 0.866428
GMD 86.591171
GNF 10491.489553
GTQ 9.170673
GYD 250.144728
HKD 9.263715
HNL 31.558521
HRK 7.534519
HTG 156.476789
HUF 381.053191
IDR 19896.452606
ILS 3.665789
IMP 0.866428
INR 108.766523
IQD 1566.368884
IRR 49967.989338
ISK 145.081737
JEP 0.866428
JMD 187.365896
JOD 0.841039
JPY 183.859615
KES 154.365483
KGS 103.731752
KHR 4807.973992
KMF 492.265869
KPW 1067.565349
KRW 1720.932795
KWD 0.364064
KYD 0.996416
KZT 601.341962
LAK 25730.915962
LBP 107070.628969
LKR 369.758716
LRD 215.513307
LSL 18.984543
LTL 3.502492
LVL 0.71751
LYD 7.502641
MAD 10.845709
MDL 20.110439
MGA 5343.305123
MKD 61.678151
MMK 2491.375458
MNT 4230.383521
MOP 9.614947
MRU 47.706509
MUR 53.888177
MVR 18.338709
MWK 2073.282437
MXN 20.709403
MYR 4.675926
MZN 75.630943
NAD 18.984543
NGN 1644.620269
NIO 43.997215
NOK 11.444004
NPR 175.676666
NZD 1.96843
OMR 0.458323
PAB 1.19564
PEN 3.997573
PGK 5.118166
PHP 69.884035
PKR 334.513515
PLN 4.213639
PYG 8008.953971
QAR 4.359296
RON 5.100467
RSD 117.472663
RUB 90.549444
RWF 1744.479055
SAR 4.450194
SBD 9.550693
SCR 17.214648
SDG 713.492182
SEK 10.570575
SGD 1.508244
SHP 0.889945
SLE 28.853899
SLL 24873.67862
SOS 683.322672
SRD 45.134883
STD 24551.608082
STN 24.515164
SVC 10.461471
SYP 13118.687676
SZL 18.978739
THB 37.242691
TJS 11.161404
TMT 4.151643
TND 3.435325
TOP 2.856045
TRY 51.596109
TTD 8.118021
TWD 37.48105
TZS 3078.804407
UAH 51.245698
UGX 4274.644098
USD 1.186184
UYU 46.3987
UZS 14617.04143
VES 410.350069
VND 30769.605664
VUV 140.90849
WST 3.215484
XAF 656.362996
XAG 0.014208
XAU 0.000248
XCD 3.205721
XCG 2.154833
XDR 0.816305
XOF 656.362996
XPF 119.331742
YER 282.697194
ZAR 19.196652
ZMK 10677.081704
ZMW 23.464514
ZWL 381.950673
  • SCS

    0.0200

    16.14

    +0.12%

  • RBGPF

    1.3800

    83.78

    +1.65%

  • BCC

    0.5100

    80.81

    +0.63%

  • RELX

    -0.3700

    35.8

    -1.03%

  • CMSC

    0.0500

    23.76

    +0.21%

  • BCE

    0.3700

    25.86

    +1.43%

  • NGG

    0.2000

    85.27

    +0.23%

  • CMSD

    -0.0400

    24.05

    -0.17%

  • RYCEF

    -0.4300

    16

    -2.69%

  • JRI

    0.1400

    13.08

    +1.07%

  • VOD

    -0.0600

    14.65

    -0.41%

  • RIO

    -4.1000

    91.03

    -4.5%

  • AZN

    0.1800

    92.77

    +0.19%

  • BTI

    0.4600

    60.68

    +0.76%

  • GSK

    0.9400

    51.6

    +1.82%

  • BP

    -0.1600

    37.88

    -0.42%

Philippines health insurer hacked: What we know
Philippines health insurer hacked: What we know / Photo: JAM STA ROSA - AFP

Philippines health insurer hacked: What we know

Hackers have stolen the personal data of potentially millions of people from the Philippines's national health insurer, which has urged members to change their passwords after the "staggering" cyberattack.

Text size:

The hackers have started releasing files including confidential memos from the stolen data to pressure the government into paying a $300,000 ransom.

Here is what we know so far about the attack, which was discovered by the Philippine Health Insurance Corporation (PhilHealth) on September 22:

What did the hackers steal?

PhilHealth and the government have yet to say exactly how many people have been impacted, but the insurer warned members in a notice that data such as addresses, phone numbers and insurance IDs was compromised.

As of June 30, according to its website, PhilHealth had more than 59 million direct and indirect contributors -- more than half the population of the Philippines.

PhilHealth asked members to monitor credit card transactions and change passwords, especially for financial services.

Separately, employee information was also stolen from the targeted computers.

The hackers released some of the data on the dark web, showing health memos and other information that a top government official described as confidential.

An investigation into the scale of the attack is ongoing, but the National Privacy Commission has described the amount of data stolen as "staggering".

Who are the hackers, and what do they want?

The Philippine government has referred to the attackers as the Medusa group, who have demanded $300,000 to restore access to PhilHealth computers and delete the stolen data.

MedusaLocker, first detected in late 2019, has been used to mainly target healthcare organisations and its creators took particular advantage of the emergency situation during the Covid-19 pandemic, according to a US government report.

The ransomware has been sold to criminal actors, and a US government cybersecurity advisory said its creator receives a cut of any ransom.

It was not clear if the Medusa group identified by the Philippines government is the creator of or an entity that purchased MedusaLocker.

How did they get the data?

On September 22, PhilHealth staff were unable to access a number of computers, which displayed a message saying hackers had locked the machines and encrypted the data.

The insurer shut down the affected systems to try and stop the attack from spreading, slowing or entirely shutting down some online services for days.

The government has so far not said exactly how hackers got access to the computers.

But in interviews with local media last week, senior PhilHealth official Israel Pargas said the insurer did not have an antivirus software at the time of the attack.

How has the government responded?

With a blunt 'No'. The Philippines does not pay ransom in any criminal cases, including cyberattacks, officials have said.

However, with hackers releasing more data from the stolen files, calls have grown for the government to conduct an audit of its cyber defences.

The National Privacy Commission said Saturday it has started an investigation into any potential lapses and data law violations by PhilHealth.

The NPC said its analysis of 734 GB of stolen data revealed "sensitive personal data", and warned the public that anyone who downloads this information could face criminal charges.

W.Vogt--NZN