Zürcher Nachrichten - Philippines health insurer hacked: What we know

EUR -
AED 3.763231
AFN 72.850006
ALL 97.694547
AMD 406.591622
ANG 1.84648
AOA 934.411543
ARS 1062.248328
AUD 1.664135
AWG 1.846795
AZN 1.736231
BAM 1.944988
BBD 2.068662
BDT 124.974053
BGN 1.954509
BHD 0.386211
BIF 3030.759153
BMD 1.024574
BND 1.40122
BOB 7.0792
BRL 6.26107
BSD 1.024584
BTN 88.173729
BWP 14.419966
BYN 3.352923
BYR 20081.658581
BZD 2.05802
CAD 1.476032
CDF 2940.528185
CHF 0.939099
CLF 0.037458
CLP 1033.593404
CNY 7.5129
CNH 7.539234
COP 4443.773917
CRC 517.165471
CUC 1.024574
CUP 27.151222
CVE 109.657025
CZK 25.089775
DJF 182.450011
DKK 7.46088
DOP 62.895278
DZD 139.378051
EGP 51.808018
ERN 15.368616
ETB 128.564054
FJD 2.395608
FKP 0.811444
GBP 0.83802
GEL 2.894432
GGP 0.811444
GHS 15.112172
GIP 0.811444
GMD 73.254945
GNF 8858.66843
GTQ 7.905974
GYD 214.355142
HKD 7.977808
HNL 26.056189
HRK 7.349176
HTG 133.845103
HUF 413.40964
IDR 16661.731633
ILS 3.778979
IMP 0.811444
INR 88.250231
IQD 1342.143853
IRR 43121.77089
ISK 144.720915
JEP 0.811444
JMD 160.646968
JOD 0.726732
JPY 161.820224
KES 132.610938
KGS 89.137705
KHR 4141.301968
KMF 489.797505
KPW 922.116403
KRW 1509.945982
KWD 0.31608
KYD 0.85382
KZT 540.716391
LAK 22355.472053
LBP 91748.23774
LKR 301.786793
LRD 191.589916
LSL 19.470574
LTL 3.025301
LVL 0.619755
LYD 5.064047
MAD 10.296712
MDL 19.149046
MGA 4851.409942
MKD 61.552087
MMK 3327.777741
MNT 3481.503737
MOP 8.216069
MRU 40.886712
MUR 47.981137
MVR 15.776551
MWK 1776.562849
MXN 21.18114
MYR 4.607001
MZN 65.473182
NAD 19.472275
NGN 1580.344618
NIO 37.700424
NOK 11.728093
NPR 141.077083
NZD 1.843045
OMR 0.394431
PAB 1.024584
PEN 3.85507
PGK 4.107228
PHP 60.070287
PKR 285.3184
PLN 4.267248
PYG 8044.906728
QAR 3.734938
RON 4.974688
RSD 117.087295
RUB 104.775483
RWF 1425.188693
SAR 3.845993
SBD 8.646813
SCR 14.606998
SDG 615.768956
SEK 11.494957
SGD 1.40566
SHP 0.811444
SLE 23.308477
SLL 21484.816349
SOS 585.490987
SRD 35.967637
STD 21206.621833
SVC 8.964081
SYP 2574.27421
SZL 19.468296
THB 35.526607
TJS 11.177835
TMT 3.58601
TND 3.288519
TOP 2.399654
TRY 36.284048
TTD 6.954881
TWD 33.860651
TZS 2564.985173
UAH 43.324992
UGX 3788.237078
USD 1.024574
UYU 44.731991
UZS 13274.402282
VES 55.101523
VND 25993.452969
VUV 121.639527
WST 2.830681
XAF 652.381368
XAG 0.033719
XAU 0.000381
XCD 2.768964
XDR 0.788976
XOF 652.340208
XPF 119.331742
YER 255.374896
ZAR 19.596524
ZMK 9222.397022
ZMW 28.302875
ZWL 329.912544
  • RBGPF

    -2.6900

    59.31

    -4.54%

  • CMSC

    0.0100

    23.11

    +0.04%

  • JRI

    -0.1000

    12.12

    -0.83%

  • BCC

    -2.3500

    115.05

    -2.04%

  • RIO

    0.4500

    59.08

    +0.76%

  • SCS

    -0.3100

    10.99

    -2.82%

  • NGG

    -1.6450

    56.335

    -2.92%

  • BCE

    -0.4700

    23.16

    -2.03%

  • RELX

    -0.3050

    46.465

    -0.66%

  • GSK

    -0.4900

    33.26

    -1.47%

  • CMSD

    -0.1300

    23.27

    -0.56%

  • AZN

    0.7650

    67.345

    +1.14%

  • RYCEF

    0.0200

    7.22

    +0.28%

  • VOD

    -0.1100

    8.1

    -1.36%

  • BP

    0.2100

    31.33

    +0.67%

  • BTI

    -0.6100

    36.13

    -1.69%

Philippines health insurer hacked: What we know
Philippines health insurer hacked: What we know / Photo: JAM STA ROSA - AFP

Philippines health insurer hacked: What we know

Hackers have stolen the personal data of potentially millions of people from the Philippines's national health insurer, which has urged members to change their passwords after the "staggering" cyberattack.

Text size:

The hackers have started releasing files including confidential memos from the stolen data to pressure the government into paying a $300,000 ransom.

Here is what we know so far about the attack, which was discovered by the Philippine Health Insurance Corporation (PhilHealth) on September 22:

What did the hackers steal?

PhilHealth and the government have yet to say exactly how many people have been impacted, but the insurer warned members in a notice that data such as addresses, phone numbers and insurance IDs was compromised.

As of June 30, according to its website, PhilHealth had more than 59 million direct and indirect contributors -- more than half the population of the Philippines.

PhilHealth asked members to monitor credit card transactions and change passwords, especially for financial services.

Separately, employee information was also stolen from the targeted computers.

The hackers released some of the data on the dark web, showing health memos and other information that a top government official described as confidential.

An investigation into the scale of the attack is ongoing, but the National Privacy Commission has described the amount of data stolen as "staggering".

Who are the hackers, and what do they want?

The Philippine government has referred to the attackers as the Medusa group, who have demanded $300,000 to restore access to PhilHealth computers and delete the stolen data.

MedusaLocker, first detected in late 2019, has been used to mainly target healthcare organisations and its creators took particular advantage of the emergency situation during the Covid-19 pandemic, according to a US government report.

The ransomware has been sold to criminal actors, and a US government cybersecurity advisory said its creator receives a cut of any ransom.

It was not clear if the Medusa group identified by the Philippines government is the creator of or an entity that purchased MedusaLocker.

How did they get the data?

On September 22, PhilHealth staff were unable to access a number of computers, which displayed a message saying hackers had locked the machines and encrypted the data.

The insurer shut down the affected systems to try and stop the attack from spreading, slowing or entirely shutting down some online services for days.

The government has so far not said exactly how hackers got access to the computers.

But in interviews with local media last week, senior PhilHealth official Israel Pargas said the insurer did not have an antivirus software at the time of the attack.

How has the government responded?

With a blunt 'No'. The Philippines does not pay ransom in any criminal cases, including cyberattacks, officials have said.

However, with hackers releasing more data from the stolen files, calls have grown for the government to conduct an audit of its cyber defences.

The National Privacy Commission said Saturday it has started an investigation into any potential lapses and data law violations by PhilHealth.

The NPC said its analysis of 734 GB of stolen data revealed "sensitive personal data", and warned the public that anyone who downloads this information could face criminal charges.

W.Vogt--NZN