Desk live·
ForensicPost
Insurance/Public sector/File 23-0922

PhilHealth’s Antivirus Licence Had Lapsed Five Months Before Medusa Encrypted It

The Philippine state health insurer was hit on Sept. 22, 2023, and refused a $300,000 demand. The leak that followed ran to about 730 gigabytes. The member count went from zero to 13 million to, by a regulator’s 2024 estimate, 42 million unique records.

Constructed geometry · not a chart of case data
JurisdictionPhilippinesPasigthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetPhilHealth
ActorMedusa
D. Kennedy11 min readConfidence: high5 sources reviewed

The Philippine Health Insurance Corporation detected a Medusa ransomware attack on Sept. 22, 2023, and took its website, member portal and electronic claims system offline. The group demanded $300,000, about 17 million pesos, for decryption and deletion. Government officials said the Philippines does not pay ransom in any criminal case and would not start. On Oct. 5 and 6, Medusa published the data: about 650 gigabytes compressed, 734 gigabytes extracted, by the National Privacy Commission’s analysis.

PhilHealth’s antivirus licence had expired on April 15, 2023. It had not been renewed because of procurement rules, a senior vice president said. The agency ran unprotected for five months.

Zero, Then 13 Million, Then 42 Million

In early October the insurer said only application servers and about 72 employee workstations had been hit and the member database was intact. On Oct. 13 the privacy commission opened a lookup service after confirming at least a million senior citizens’ identification records in the dump. On Oct. 18 and 19 PhilHealth’s data protection officer said about 13 million people were affected and the figure could reach 20 million. In July 2024 a commission director told a House hearing that 181 million records had been dumped, 42 million unique after de-duplication.

The corpus records at 26-0425 that a breach count is a process rather than a fact. This one ran over nine months from an assurance that the member database was untouched to a figure of more than a third of the national population. The published data included names, addresses, birth dates, identification numbers, photographs, contribution records, employee files, internal memos and, by later reporting, hospital and illness records.

A State Insurer Nobody Can Leave

PhilHealth membership is mandatory. The people in the dump did not choose the insurer, cannot switch and cannot ask for their records to be deleted. The privacy commission warned that resharing the leaked data was itself an offence carrying up to 20 years. A regulator’s finding of negligence against senior officials and a fine reported at about 4.6 billion pesos surfaced in late 2024 through a broadcaster and an opinion column; no decision document was found, and the file carries that outcome as reported rather than established.

How we reported this

Compiled from PhilHealth’s public notice, the National Privacy Commission’s statements, Philstar and other Philippine reporting, and later hearing coverage, listed below. Each count is given with its date and source. The reported 2024 fine rests on secondary sources only and is flagged as unconfirmed. Graded high on the incident facts. Corrections: corrections@forensicpost.com.

Sources
  1. PhilHealth hacked: What we knowPhilstar
  2. PhilHealth: 13 million members affected by data breachPhilstar
  3. PhilHealth hack potentially exposes 42 million peopleInsurance Business Asia
  4. PhilHealth ransomware: no antivirusThe Register
  5. Press Statement on Alleged PhilHealth Data BreachNational Privacy Commission
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary