ADVERTISEMENT

Hacker behind PSA data leak different from PhilHealth ransomware group — DICT

Published Oct 12, 2023 12:59 pm

The Department of Information and Communications Technology (DICT) confirmed on Thursday, Oct. 12 that the "suspects" responsible for the attack on the Philippine Statistics Authority (PSA) database are different from those who targeted the Philippine Health Insurance Corporation (PhilHealth).

"That one, I can confirm that it's different. The one in PhilHealth is with the Medusa," Department of Information and Communications Technology (DICT) newly appointed spokesperson, Assistant Secretary Renato "Aboy" Paraiso said during a press conference.

He added that, unlike the "sophisticated" and international group Medusa, the hackers behind PSA are local and amateurs.

"You're seeing right now is isolated [case]," Paraiso added.

IMG_3370.jpeg
Department of Information and Communications Technology (DICT) newly appointed spokesperson, Assistant Secretary Renato "Aboy" Paraiso during a press conference on Thursday, Oct. 12, 2023. (Sonny Daanoy)

However, PSA assured the public that the integrity of the national ID (Identification) and civil registry systems remained uncompromised.

READ:

https://mb.com.ph/2023/10/11/psa-probes-data-leak-national-id-civil-registry-unaffected-1

"The PSA strongly condemns this activity, and we will be working with all law enforcement agencies to apprehend the perpetrators," PSA said in a statement on Oct. 11.

RELATED STORY:

https://mb.com.ph/2023/10/12/psa-data-breach-highlights-urgency-to-provide-dict-confi-funds-to-fight-cybercrimes-gatchalian

DICT extends assistance to PhilHealth

In a statement on Oct. 12, DICT pledged to continue to assist PhilHealth and "improve its cybersecurity posture following a recent ransomware attack."

"The DICT, in coordination with PhilHealth, is still conducting a thorough investigation to determine the extent, kind, and number of data assets that were exposed to the surface and dark web," DICT said in a post.

Moreover, the country's ICT department suggested precautions for the public.

DICT urged the public to "change passwords and use strong and unique passwords that do not use personal circumstances like birthdays or names of next of kin; enable multi-factor authorization in your accounts; refrain from sharing personal information online; look out for phishing emails and do not click any link sent through a text message; and use different passwords for your various online accounts."

Furthermore, DICT asked the public to refrain from sharing suspicious links containing exfiltrated PhilHealth data.

"These may contain malware, and those found guilty of circulating said data could risk facing imprisonment or fines under the Data Privacy Act of 2012. The DICT urges the public to report the presence of the leaked data to relevant authorities such as the DICT, National Privacy Commission, and law enforcement agencies," DICT noted.

Following the hacking incident, DICT recommended that PhilHealth should enhance its cybersecurity measures.

These include ensuring PhilHealth's 100 percent compliance with the recommendations forwarded by the DICT's National Computer Emergency Response Team and upgrading PhilHealth's Information Security Incident Response Team into a Computer Emergency Response Team to adhere to international standards and capabilities.

Related Tags

Philippine Statistics Authority Department of Information and Communications Technology PhilHealth Hackers
ADVERTISEMENT
.most-popular .layout-ratio{ padding-bottom: 79.13%; } @media (min-width: 768px) and (max-width: 1024px) { .widget-title { font-size: 15px !important; } }

{{ articles_filter_1561_widget.title }}

.most-popular .layout-ratio{ padding-bottom: 79.13%; } @media (min-width: 768px) and (max-width: 1024px) { .widget-title { font-size: 15px !important; } }

{{ articles_filter_1562_widget.title }}

.most-popular .layout-ratio{ padding-bottom: 79.13%; } @media (min-width: 768px) and (max-width: 1024px) { .widget-title { font-size: 15px !important; } }

{{ articles_filter_1563_widget.title }}

{{ articles_filter_1564_widget.title }}

.mb-article-details { position: relative; } .mb-article-details .article-body-preview, .mb-article-details .article-body-summary{ font-size: 17px; line-height: 30px; font-family: "Libre Caslon Text", serif; color: #000; } .mb-article-details .article-body-preview iframe , .mb-article-details .article-body-summary iframe{ width: 100%; margin: auto; } .read-more-background { background: linear-gradient(180deg, color(display-p3 1.000 1.000 1.000 / 0) 13.75%, color(display-p3 1.000 1.000 1.000 / 0.8) 30.79%, color(display-p3 1.000 1.000 1.000) 72.5%); position: absolute; height: 200px; width: 100%; bottom: 0; display: flex; justify-content: center; align-items: center; padding: 0; } .read-more-background a{ color: #000; } .read-more-btn { padding: 17px 45px; font-family: Inter; font-weight: 700; font-size: 18px; line-height: 16px; text-align: center; vertical-align: middle; border: 1px solid black; background-color: white; } .hidden { display: none; }
function initializeAllSwipers() { // Get all hidden inputs with cms_article_id document.querySelectorAll('[id^="cms_article_id_"]').forEach(function (input) { const cmsArticleId = input.value; const articleSelector = '#article-' + cmsArticleId + ' .body_images'; const swiperElement = document.querySelector(articleSelector); if (swiperElement && !swiperElement.classList.contains('swiper-initialized')) { new Swiper(articleSelector, { loop: true, pagination: false, navigation: { nextEl: '#article-' + cmsArticleId + ' .swiper-button-next', prevEl: '#article-' + cmsArticleId + ' .swiper-button-prev', }, }); } }); } setTimeout(initializeAllSwipers, 3000); const intersectionObserver = new IntersectionObserver( (entries) => { entries.forEach((entry) => { if (entry.isIntersecting) { const newUrl = entry.target.getAttribute("data-url"); if (newUrl) { history.pushState(null, null, newUrl); let article = entry.target; // Extract metadata const author = article.querySelector('.author-section').textContent.replace('By', '').trim(); const section = article.querySelector('.section-info ').textContent.replace(' ', ' '); const title = article.querySelector('.article-title h1').textContent; // Parse URL for Chartbeat path format const parsedUrl = new URL(newUrl, window.location.origin); const cleanUrl = parsedUrl.host + parsedUrl.pathname; // Update Chartbeat configuration if (typeof window._sf_async_config !== 'undefined') { window._sf_async_config.path = cleanUrl; window._sf_async_config.sections = section; window._sf_async_config.authors = author; } // Track virtual page view with Chartbeat if (typeof pSUPERFLY !== 'undefined' && typeof pSUPERFLY.virtualPage === 'function') { try { pSUPERFLY.virtualPage({ path: cleanUrl, title: title, sections: section, authors: author }); } catch (error) { console.error('ping error', error); } } // Optional: Update document title if (title && title !== document.title) { document.title = title; } } } }); }, { threshold: 0.1 } ); function showArticleBody(button) { const article = button.closest("article"); const summary = article.querySelector(".article-body-summary"); const body = article.querySelector(".article-body-preview"); const readMoreSection = article.querySelector(".read-more-background"); // Hide summary and read-more section summary.style.display = "none"; readMoreSection.style.display = "none"; // Show the full article body body.classList.remove("hidden"); } document.addEventListener("DOMContentLoaded", () => { let loadCount = 0; // Track how many times articles are loaded const offset = [1, 2, 3, 4, 5, 6, 7, 8, 9, 10]; // Offset values const currentUrl = window.location.pathname.substring(1); let isLoading = false; // Prevent multiple calls if (!currentUrl) { console.log("Current URL is invalid."); return; } const sentinel = document.getElementById("load-more-sentinel"); if (!sentinel) { console.log("Sentinel element not found."); return; } function isSentinelVisible() { const rect = sentinel.getBoundingClientRect(); return ( rect.top < window.innerHeight && rect.bottom >= 0 ); } function onScroll() { if (isLoading) return; if (isSentinelVisible()) { if (loadCount >= offset.length) { console.log("Maximum load attempts reached."); window.removeEventListener("scroll", onScroll); return; } isLoading = true; const currentOffset = offset[loadCount]; window.loadMoreItems().then(() => { let article = document.querySelector('#widget_1690 > div:nth-last-of-type(2) article'); intersectionObserver.observe(article) loadCount++; }).catch(error => { console.error("Error loading more items:", error); }).finally(() => { isLoading = false; }); } } window.addEventListener("scroll", onScroll); });

Sign up by email to receive news.