Safeware Glasswall APAC Partner
Book a demo

Explore

What is CDRZero TrustThe detection gapCapabilitiesUse cases

Products

ProductsIntegrationFile support

Compliance

Control alignmentAPAC regulatory landscape
Country guidesSingaporeAustraliaJapanSouth KoreaIndiaIndonesiaMalaysiaThailandVietnamPhilippinesTaiwanNew ZealandMongolia

More

Trust & certificationsInsightsPartnersAboutDocumentation Book a demo

Language

EnglishBahasa Indonesia日本語한국어Bahasa MelayuไทยTiếng Việt简体中文繁體中文

File-borne breach events · Southeast Asia

Philippines: documented file-borne breach events

The Philippine privacy regulator publishes resolutions that name the mechanism, and two of them document files: malicious Excel attachments that opened a cruise operator's network, and a credential harvesting file mailed to 387 recipients.

Overview

What the record shows

The National Privacy Commission publishes breach resolutions in unusual detail, and that cuts both ways for this record. Most of the country's famous incidents are documented as something other than file-borne: the commission's own resolutions attribute them to web application compromise, payment page skimming and, in one case, an employee who sold his credentials. Those are excluded here on the regulator's own evidence rather than on our assumption.

Two resolutions do document files. The Costa Crociere case records malicious Excel attachments opened by employees as the start of the intrusion, which is as clean a file-borne finding as any regulator in the region has published. The PowerVision case documents the other direction of travel, a compromised mailbox used to send a credential harvesting file to hundreds of recipients, and it is recorded here with that distinction stated plainly.

Documented events

File-borne incidents in Philippines

Most recent first. Every entry cites the public record it is drawn from.

  1. Email attachmentMedium impact

    PowerVision EAP, Inc.: Compromised mailbox mailed a credential harvesting file to 387 recipients

    PowerVision's administrative mailbox was compromised on 20 May 2021 and used to send credential harvesting emails to 387 recipients from the company's own address. The company deactivated the account and imposed multi-factor authentication across all email accounts four days later. The commission found insufficient grounds for a notification exemption and ordered notification plus the missing breach report details.

    The documented vector. Audio file that prompted the recipient to enter their Outlook email address and password. The commission's order records that the company's administrative mailbox was reached by password cracking, not by a file, and was then used to send emails containing an audio file that would require the person accessing it to input the Outlook email and password. The file-borne element of this event is that outbound wave, and this entry does not claim otherwise about the initial compromise.

    How this class of vector is removed

    This class of vector is instructive from the receiving side: the 387 recipients were sent a file from a genuine, trusted sender address, so sender reputation offered them nothing. Rebuilding every inbound attachment to its format's known good specification strips the active content a harvesting file depends on, regardless of who the message appears to come from, and the relay applies policy outcomes to the message itself.

    Content Disarm and ReconstructionEmail CDR RelayGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine

    • services

    Source: National Privacy Commission

  2. Email attachmentHigh impact

    Costa Crociere S.p.A. (AIDA Cruises): Malicious Excel attachments opened the intrusion that exposed 74,000 Filipino data subjects

    After the Excel attachments were opened on 21 December 2020, the attacker exfiltrated roughly 1.1 terabytes of data and deployed DoppelPaymer ransomware, detected on 25 December. About 74,000 Filipino data subjects, guests, employees and crew, had names, dates of birth, passport numbers, nationality and trip data exposed. The commission denied the operator's request for exemption from individual notification, ordered notification and the overdue full breach report, and required it to show cause against contempt proceedings.

    The documented vector. Malicious Excel documents carrying SDBot remote access tooling. The National Privacy Commission's resolution records that the event began via multiple malicious Excel documents, sent by email, containing SDBot remote access tooling, which were opened by employees at AIDA. The attacker then pivoted from the AIDA network into the Costa network before deploying ransomware.

    How this class of vector is removed

    This class of vector, a spreadsheet carrying remote access tooling into an organisation by email, is removed by deterministic CDR rebuild: the workbook is reconstructed to its format's known good specification, so embedded active content does not survive into the file the employee opens, and macro intelligence inspects that active content for the policy decision. The Email CDR Relay places the rebuild on inbound mail, ahead of any verdict on whether the particular tooling is known.

    Content Disarm and ReconstructionMacro intelligenceEmail CDR RelayGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine

    • travel

    Source: National Privacy Commission

Scope

How to read this page

Every event on this page meets three tests before it is published. It is documented by reliable public sources: a regulator, an official inquiry, the affected organisation's own disclosure, or reputable press with named confirmation, and each entry links to those sources. The initial access or payload delivery travelled as a file, as the public record states it. An email is itself a file, so malicious code in a message and deceptive-hyperlink phishing carried by a message both count; credential attacks and pure network exploits are excluded. And the prevention analysis is conditional: where we say a capability removes a class of vector, that is a statement about how the control treats that class of content, not a claim about what any organisation ran, and not a judgement on the people who dealt with the incident.

This page is a working reference, not an incident report or legal advice. Details reflect the public record on the review date and organisations named here are cited from that record alone.

Elsewhere in the region

Other APAC territories

Files cross your boundary every day