Trivia Medusa X PhilHealth -- Stolen PhilHealth Data Has Been Released

Cee Jay

๐Ÿงฟ ๐•พ๐–”๐–š๐–‘ ๐•ฎ๐–†๐–‘๐–Ž๐–‡๐–—๐–Š ๐Ÿงฟ
Contributor
Joined
Feb 22, 2015
Posts
14,591
Solutions
2,186
Reaction
25,968
Points
8,274
๐Œ๐ž๐๐ฎ๐ฌ๐š ๐‡๐š๐œ๐ค๐ž๐ซ๐ฌ ๐‘๐ž๐ฅ๐ž๐š๐ฌ๐ž ๐’๐ญ๐จ๐ฅ๐ž๐ง ๐๐ก๐ข๐ฅ๐‡๐ž๐š๐ฅ๐ญ๐ก ๐ƒ๐š๐ญ๐š


The state health insurer โ€œdid not subscribe to anti-virus and security software since May, thatโ€™s why they were hรครงked,โ€ Sen. Grace Poe said. โ€œI donโ€™t think it is really an excuse for any government agency not to have security in their databases.โ€
image.png

๐ป๐‘Ž๐‘๐‘˜๐‘’๐‘Ÿ๐‘  โ„Ž๐‘Ž๐‘ฃ๐‘’ ๐‘ ๐‘ก๐‘Ž๐‘Ÿ๐‘ก๐‘’๐‘‘ ๐‘’๐‘ฅ๐‘๐‘œ๐‘ ๐‘–๐‘›๐‘” ๐‘ ๐‘œ๐‘š๐‘’ ๐‘œ๐‘“ ๐‘กโ„Ž๐‘’ ๐‘‘๐‘Ž๐‘ก๐‘Ž ๐‘Ÿ๐‘’๐‘ก๐‘Ÿ๐‘–๐‘’๐‘ฃ๐‘’๐‘‘ ๐‘“๐‘Ÿ๐‘œ๐‘š ๐‘Ÿ๐‘Ž๐‘›๐‘ ๐‘œ๐‘š๐‘ค๐‘Ž๐‘Ÿ๐‘’ ๐‘Ž๐‘ก๐‘ก๐‘Ž๐‘๐‘˜ ๐‘Ž๐‘”๐‘Ž๐‘–๐‘›๐‘ ๐‘ก ๐‘กโ„Ž๐‘’ ๐‘ƒโ„Ž๐‘–๐‘™๐‘–๐‘๐‘๐‘–๐‘›๐‘’ ๐ป๐‘’๐‘Ž๐‘™๐‘กโ„Ž ๐ผ๐‘›๐‘ ๐‘ข๐‘Ÿ๐‘Ž๐‘›๐‘๐‘’ ๐ถ๐‘œ๐‘Ÿ๐‘. ๐‘Ž๐‘“๐‘ก๐‘’๐‘Ÿ ๐‘Ž ๐‘Ÿ๐‘Ž๐‘›๐‘ ๐‘œ๐‘š ๐‘œ๐‘“ $300,000 ๐‘ก๐‘œ ๐‘ข๐‘›๐‘™๐‘œ๐‘๐‘˜ ๐‘กโ„Ž๐‘’ ๐‘‘๐‘Ž๐‘ก๐‘Ž ๐‘ค๐‘Ž๐‘  ๐‘›๐‘œ๐‘ก ๐‘๐‘Ž๐‘–๐‘‘.

Filipinos should brace for a barrage of online scams in the coming days after hรครงkers who stole data from state-run Philippine Health Insurance Corp. (PhilHealth) have leaked membersโ€™ information to online โ€“ and possibly criminal โ€“ groups.

Reports coming from dark web informants showed that documents stolen from PhilHealth were publicized in online marketplaces like Telegram starting Thursday, Oct. 5.

Deep Web Konek, a group dedicated to publishing activities in the dark web, shared a screenshot showing large packets of files containing alleged information on PhilHealth members.

As such, the group warned that PhilHealth members should be vigilant in the coming days. Data uploaded on the dark web are usually exploited by criminal groups involved in digital fraud ranging from messaging scams to identity theft.

Another report indicated that PhilHealth files in online marketplaces contain documents compressed in 160 folders. In total, these files amount to 600 GB of data.

๐—ง๐—ต๐—ฒ ๐—ฃ๐—ต๐—ถ๐—น๐—ถ๐—ฝ๐—ฝ๐—ถ๐—ป๐—ฒ ๐—ฆ๐—ง๐—”๐—ฅ reached out to the Department of Information and Communications Technology (DICT) for comment, but received no response.

Earlier, PhilHealth admitted that it has yet to determine the number of records taken by Medusa, but expressed belief that sensitive information were included in the ransomware attack.

These data include name, address, birthday, ***, mobile number and identification number.

PhilHealth has committed to notify members whose personal information was deemed compromised. The state-run insurer also asked contributors to take precautions right away, including monitoring their credit reports for unauthorized activities.

PhilHealth also said members should place a fraud alert on their credit reports. Contributors are also advised to change their passwords in all digital accounts, particularly in financial platforms, and keep an eye on phishing emails and smishing texts.

In a text message to reporters, the National Privacy Commission (NPC) said it is looking into the liability of PhilHealth in the data breach.

โ€œAs for PhilHealthโ€™s liability, we are currently assessing whether negligence was involved on its part before making any definitive statements, but in addition to negligence we are also looking if there is concealment and possible imposition of administrative fines,โ€ the NPC said.



๐•ฐ๐–๐–•๐–‘๐–†๐–“๐–†๐–™๐–Ž๐–”๐–“ ๐–†๐–™ ๐•ญ๐–š๐–‰๐–Œ๐–Š๐–™ ๐•ณ๐–Š๐–†๐–—๐–Ž๐–“๐–Œ

While the Senate has not yet initiated an investigation on the hรครงking of PhilHealth, officials of the state-run insurer should be made to explain the cyber security breach when they defend before lawmakers their proposed budget for 2024, Sen. Grace Poe said on Thursday.

Although Congress is on recess, several Senate subcommittees continue to conduct hearings on the 2024 proposed budgets of various government agencies.

โ€œEven if it is not investigated (by the Senate), I think it is necessary that we ask the hรครงking incident during the budget hearing,โ€ Poe said during the โ€œKapihan sa Manila Bayโ€ forum on Wednesday, Oct. 4.

Cyberhรครงkers demanded $300,000 or approximately P16 million after the Medusa ransomware infected the systems of PhilHealth on Sept. 22, according to the DICT.

Poe cited reports that the hรครงkers may have taken advantage of the expiration of PhilHealthโ€™s anti-virus security software last May to carry out their plan.

โ€œThey did not subscribe to anti-virus and security software since May, thatโ€™s why they were hรครงked. I donโ€™t think it is really an excuse for any government agency not to have security in their databases,โ€ she said.

Poe said that even if PhilHealth did not have enough budget for a cyber security software, its officials should have used their revolving funds, or emergency procurement, which is allowed under the law. She said that unlike in the past, hiring of IT experts has now become necessary.

โ€œOne of the bills that I filed is that as part of the E-government Act with the digitalization of government agencies into one portal, all important agencies, government and critical establishments of private sector like media, telcos, etc. should have cyber security employees on duty all the time to thwart or address cyber attacks.โ€

Poe said agencies should have IT experts handling cyber security plan to ensure at least minimum IT compliance with cyber security regulations.

โ€œWhy was it (cyber security subscription) not prioritized? They let it lapse and didnโ€™t pay the subscription. I am sure they have an IT manager there. They should be summoned, their database was not affected, but other information were stolen,โ€ Poe said.

Sen. Bong Go, for his part, has reiterated his call for PhilHealth as well as other government agencies to bolster their cybersecurity defenses.

Go said the protection of data and the continuity of services, especially for the underprivileged, should be of utmost priority.

โ€œFirst of all, we should not be complacent. Every detail of information is important and every second of delay in services can spell big problem for our countrymen in need,โ€ Go said.

Go, chairman of the committee on health, urged PhilHealth to take immediate and stringent measures.

โ€œWe should have preventive measures so this kind of incident wonโ€™t be repeated. We must strengthen our cybersecurity,โ€ he said.

The senator also stressed the importance of ensuring that PhilHealthโ€™s services remain uninterrupted, especially for the poor.

โ€œItโ€™s not only PhilHealth thatโ€™s in danger here, but its members as well,โ€ he said. He explained any investigation would need much input from the DICT and the National Privacy Commission (NPC).




โ๐‡๐จ๐ฅ๐ ๐๐ก๐ข๐ฅ๐‡๐ž๐š๐ฅ๐ญ๐ก ๐€๐œ๐œ๐จ๐ฎ๐ง๐ญ๐š๐›๐ฅ๐žโž

Meanwhile, information and communications technology professionals have urged the government to hold the PhilHealth accountable for the cyber attack on its system.

The Computer Professionalsโ€™ Union (CPU) said the recent statements of PhilHealth and DICT highlighted the governmentโ€™s lack of initiative to protect and secure sensitive and personal information.

โ€œThe fact that PhilHealth and the DICT initially downplayed the severity of the Medusa ransomware breach on its systems, especially its impacts on the people, speaks volumes about how the government treats peopleโ€™s personally-identifiable information,โ€ the group said in a statement.

โ€œNow PhilHealth is stating that โ€˜onlyโ€™ employeesโ€™ personal information have been affected, although it admitted that it is possible that the breached computers could also have information on PhilHealthโ€™s members, which as of 2021 numbering 94 million or more than 80 percent of the countryโ€™s population,โ€ the group said.

PhilHealth officials initially downplayed the breach by saying its main servers were secure after the attack.

One report also quoted an official as saying that the threat to release stolen information was only a bluff.

The DICT later confirmed that some information, primarily those on employees, were compromised in the incident.

PhilHealth issued a public advisory hours before the deadline set by the hรครงkers expired.

The CPU said the PhilHealth data breach is just the latest in a series of incidents that highlight governmentโ€™s ineptitude in handling peopleโ€™s personal information.

It recalled the leak of information on police applicants and members early this year as well as the so-called โ€œComeleakโ€ in 2016.



๐•ญ๐–Š๐–‘๐–†๐–™๐–Š๐–‰ ๐•ฌ๐–‘๐–Š๐–—๐–™

Infrawatch PH decried PhilHealthโ€™s belated move to alert the public and demanded that it cooperate with investigators.

โ€œThis critical issue demands immediate and transparent action from all parties involved. No urgent public notices can replace comprehensive action,โ€ said Terry Ridon, Infrawatch PH convenor and former party-list congressman.

โ€œThe notice from PhilHealth is insufficient. It leaves the public in the dark about the full extent of the breach and fails to outline a clear action plan for resolving the issue,โ€ Ridon said.

โ€œAttributing the failure to renew antivirus software to new government procurement rules is not just an excuse; itโ€™s a dereliction of duty,โ€ Ridon said.

โ€œThe PhilHealth breach raises serious questions about the security of other government databases. If a database as extensive as PhilHealthโ€™s can be compromised, it casts doubt on the security measures in place for other government systems,โ€ Ridon pointed out.

Data protection groups have offered to help PhilHealth ease the impact of the cyber attack.

The National Association of Data Protection Officers of the Philippines (NADPOP) and the Philippine Computer Emergency Response Team (PH-CERT) made the offer in a joint statement.

โ€œIf PhilHealth needs unbiased third-party support, we have volunteers who are ready to assist in digital forensics and in the data management breach of the agency,โ€ the groups said.

NADPOP and PH-CERT said they are bringing to the table a third-party perspective on the matter, and that they are willing to coordinate with the DICT and the NPC, which are investigating the data breach.

PH-CERT president Angel Averia Jr. said it is safe to assume that PhilHealth has compromised sensitive data and left them exposed to criminal groups.

NADPOP president Sam Jacoba warned that the PhilHealth data leak could be worse than the one that hit the Commission on Elections in 2016.

Jacoba said all workers are enrolled in PhilHealth as mandated under Republic Act No. 11223 or the Universal Health Care Act, unlike in Comelec, which only has data on registered voters.

As of 2022, PhilHealth maintains a network of 59.03 million members made up of 35.31 million direct contributors and 23.72 million indirect contributors.

Preliminary investigation from the NPC showed that the ransomware attack exposed the IDs and photos of some PhilHealth members.

PhilHealth admitted as well that the data breach has leaked the mobile numbers of affected contributors.


๐—ฆ๐—ข๐—จ๐—ฅ๐—–๐—˜: You do not have permission to view the full content of this post. Log in or register now.
 
Last edited:
May link kayo ng telegram channel? Try ko manilip ng info
hahaha baka may makita kang tumatalon don hahah
 
  • Haha
Reactions: KLB

Attachments

Last edited:
ay ano na naman ito mga marites talaga sa katanghaliang tapat...

alam mo soul diko na naman natapos dahil sumakit mga mata ko, kala ko nagka sore eyes ako kababasa ng red fonts na ito grabe ,,,teka parang uulan isilong ko muna nga mga sinampay ko sa taas
parang nagbabasa tuloy ng "purge" vibes sa intense color ng font haha
 
ay ano na naman ito mga marites talaga sa katanghaliang tapat...
1696569567094.png

alam mo soul diko na naman natapos dahil sumakit mga mata ko, kala ko nagka sore eyes ako kababasa ng red fonts na ito grabe ,,,teka parang uulan isilong ko muna nga mga sinampay ko sa taas
Ang sama nyong dalawa! Hahahahaha
 

Attachments

ay ano na naman ito mga marites talaga sa katanghaliang tapat...

alam mo soul diko na naman natapos dahil sumakit mga mata ko, kala ko nagka sore eyes ako kababasa ng red fonts na ito grabe ,,,teka parang uulan isilong ko muna nga mga sinampay ko sa taas
parang nagbabasa tuloy ng "purge" vibes sa intense color ng font haha
sakit nga eh hahaha
 

Similar threads

Back
Top