-
Battling Norrie survives match point to oust de Minaur at Montreal
-
Venezuela's political transition talks launch in Caracas
-
Venezuela's political transition talks start: AFP
-
2 killed, 13 wounded in bus blast near Syrian capital: state media
-
Real Madrid extend Vinicius deal, sign Diomande in title bid boost
-
All Blacks skipper Taylor cautiously recovering from calf strain
-
PSG sign France midfielder Akliouche from Monaco
-
UN chief denounces Russia, Ukraine for civilian deaths
-
CONMEBOL 'expresses concern regarding repeated unilateral actions' by FIFA
-
UEFA turn up the pressure on Infantino and repeat boycott threat
-
Warren coy over whether Fury-Joshua will be in UK or US
-
Rodri approves Barcelona transfer talks with Man City: Barca source to AFP
-
Taiwan blocks key bridge in drill for potential Chinese invasion
-
Venezuela unable to tally missing from cataclysmic quakes
-
Migrant children risk abuse on streets of Ceuta, aid groups warn
-
Le Court sprints to stage six Tour de France Femmes win
-
Oil price shoots up as stocks tread water
-
Doping body says Parker's positive cocaine test caused by nutritionist
-
British Grand Prix stays on MotoGP calendar until 2028
-
UEFA says boycott of World Cups stands despite FIFA backdown on private investment
-
Britain's EasyJet flies into US hands as takeover confirmed
-
Rheinmetall sales keep surging despite cancelled naval frigate project
-
Real Madrid sign Ivory Coast winger Yan Diomande
-
Pogacar teammate Del Toro gets new UAE deal after Tour podium
-
How online disinformation fuelled Ceuta migrant surge
-
Stocks tread water with earnings, tech in focus
-
Forex Expo Dubai Announces Opportunity to Win Up to 150 Grams of Gold This September 2026
-
Inevitable AI Group Raises $6M From Aleph to Launch AI-Native SaaS Companies
-
Suspected Ebola death on boat heading for DR Congo capital
-
Forlan named new Uruguay head coach
-
England selector North not 'hung up' on Stokes absence
-
UEFA chief Ceferin: 'Underdog' leader taking fight to FIFA's Infantino
-
UK Anti-Doping confirm former world champ Parker's ban lifted
-
Salah completes move to Turkey's Trabzonspor
-
French winemakers dread 'smoky taste' after wildfires
-
UK clears Paramount's takeover of Warner Bros
-
Stocks diverge with earnings, tech in focus
-
North Korea fires ballistic missile: South Korea military
-
England recall batsman Lawrence for Pakistan series
-
'Don't have to hide': Thai IDs, legal work give hope to Myanmar refugees
-
Siemens shares plunge on disappointing guidance raise
-
Stocks mixed with tech firms back under pressure
-
New Australia coach Kiss gives Japan starts to Ross, Amatosero
-
How Blundell's old school tactic ended England's 'Bazball' era
-
'Stretch our money': Romanians face highest EU inflation
-
Israel reports troop deaths as Lebanon talks underway in Rome
-
Iran says close to Hormuz plan with Oman, but reopening depends on US
-
Seeds Rybakina, Pegula, Gauff reach third round at WTA Toronto
-
Messi scores twice to set Leagues Cup record in Miami victory
-
Police raid South Korea FA in probe into World Cup coach appointment
Philippines health insurer hacked: What we know
Hackers have stolen the personal data of potentially millions of people from the Philippines's national health insurer, which has urged members to change their passwords after the "staggering" cyberattack.
The hackers have started releasing files including confidential memos from the stolen data to pressure the government into paying a $300,000 ransom.
Here is what we know so far about the attack, which was discovered by the Philippine Health Insurance Corporation (PhilHealth) on September 22:
What did the hackers steal?
PhilHealth and the government have yet to say exactly how many people have been impacted, but the insurer warned members in a notice that data such as addresses, phone numbers and insurance IDs was compromised.
As of June 30, according to its website, PhilHealth had more than 59 million direct and indirect contributors -- more than half the population of the Philippines.
PhilHealth asked members to monitor credit card transactions and change passwords, especially for financial services.
Separately, employee information was also stolen from the targeted computers.
The hackers released some of the data on the dark web, showing health memos and other information that a top government official described as confidential.
An investigation into the scale of the attack is ongoing, but the National Privacy Commission has described the amount of data stolen as "staggering".
Who are the hackers, and what do they want?
The Philippine government has referred to the attackers as the Medusa group, who have demanded $300,000 to restore access to PhilHealth computers and delete the stolen data.
MedusaLocker, first detected in late 2019, has been used to mainly target healthcare organisations and its creators took particular advantage of the emergency situation during the Covid-19 pandemic, according to a US government report.
The ransomware has been sold to criminal actors, and a US government cybersecurity advisory said its creator receives a cut of any ransom.
It was not clear if the Medusa group identified by the Philippines government is the creator of or an entity that purchased MedusaLocker.
How did they get the data?
On September 22, PhilHealth staff were unable to access a number of computers, which displayed a message saying hackers had locked the machines and encrypted the data.
The insurer shut down the affected systems to try and stop the attack from spreading, slowing or entirely shutting down some online services for days.
The government has so far not said exactly how hackers got access to the computers.
But in interviews with local media last week, senior PhilHealth official Israel Pargas said the insurer did not have an antivirus software at the time of the attack.
How has the government responded?
With a blunt 'No'. The Philippines does not pay ransom in any criminal cases, including cyberattacks, officials have said.
However, with hackers releasing more data from the stolen files, calls have grown for the government to conduct an audit of its cyber defences.
The National Privacy Commission said Saturday it has started an investigation into any potential lapses and data law violations by PhilHealth.
The NPC said its analysis of 734 GB of stolen data revealed "sensitive personal data", and warned the public that anyone who downloads this information could face criminal charges.
V.Fontes--PC