The Philippine Health Insurance Corporation detected a Medusa ransomware attack on Sept. 22, 2023, and took its website, member portal and electronic claims system offline. The group demanded $300,000, about 17 million pesos, for decryption and deletion. Government officials said the Philippines does not pay ransom in any criminal case and would not start. On Oct. 5 and 6, Medusa published the data: about 650 gigabytes compressed, 734 gigabytes extracted, by the National Privacy Commission’s analysis.
PhilHealth’s antivirus licence had expired on April 15, 2023. It had not been renewed because of procurement rules, a senior vice president said. The agency ran unprotected for five months.
Zero, Then 13 Million, Then 42 Million
In early October the insurer said only application servers and about 72 employee workstations had been hit and the member database was intact. On Oct. 13 the privacy commission opened a lookup service after confirming at least a million senior citizens’ identification records in the dump. On Oct. 18 and 19 PhilHealth’s data protection officer said about 13 million people were affected and the figure could reach 20 million. In July 2024 a commission director told a House hearing that 181 million records had been dumped, 42 million unique after de-duplication.
The corpus records at 26-0425 that a breach count is a process rather than a fact. This one ran over nine months from an assurance that the member database was untouched to a figure of more than a third of the national population. The published data included names, addresses, birth dates, identification numbers, photographs, contribution records, employee files, internal memos and, by later reporting, hospital and illness records.
A State Insurer Nobody Can Leave
PhilHealth membership is mandatory. The people in the dump did not choose the insurer, cannot switch and cannot ask for their records to be deleted. The privacy commission warned that resharing the leaked data was itself an offence carrying up to 20 years. A regulator’s finding of negligence against senior officials and a fine reported at about 4.6 billion pesos surfaced in late 2024 through a broadcaster and an opinion column; no decision document was found, and the file carries that outcome as reported rather than established.
Compiled from PhilHealth’s public notice, the National Privacy Commission’s statements, Philstar and other Philippine reporting, and later hearing coverage, listed below. Each count is given with its date and source. The reported 2024 fine rests on secondary sources only and is flagged as unconfirmed. Graded high on the incident facts. Corrections: corrections@forensicpost.com.
- PhilHealth hacked: What we knowPhilstar
- PhilHealth: 13 million members affected by data breachPhilstar
- PhilHealth hack potentially exposes 42 million peopleInsurance Business Asia
- PhilHealth ransomware: no antivirusThe Register
- Press Statement on Alleged PhilHealth Data BreachNational Privacy Commission