Phishing Simulation in the Philippines: A Growing Market Overview

In this blog

phishing simulation Philippines

In Short

The Philippines is one of the fastest-growing and most heavily targeted digital economies in Southeast Asia, and its threat landscape reflects that: phishing remains the leading initial-access method behind data breaches, romance scams, and business email compromise reported in the country. Two regulatory pressures are shaping how organizations respond, the Data Privacy Act of 2012 (Republic Act 10173), enforced by the National Privacy Commission (NPC), and BSP Circular No. 1213 for banks and financial institutions, which tightened authentication and fraud-monitoring rules starting in 2025. Neither framework mandates phishing simulation by name, but both create strong practical reasons for Philippine organizations to test and train employees against the attack method most often responsible for the incidents these regulators track.

Why Phishing Is the Philippines’ Biggest Cyber Risk Right Now

Independent threat intelligence research has repeatedly identified phishing as the dominant initial-access technique behind cyber campaigns targeting the Philippines, spanning government, critical infrastructure, and private-sector organizations. According to CYFIRMA’s research on the Philippine threat landscape for 2025-2026, phishing is frequently combined with abuse of jump servers, VPNs, and remote access tools to move laterally once initial access is gained, and the country is also seeing a rise in AI-assisted phishing techniques.

A particularly Philippine-relevant variant flagged in this research is the sophisticated use of romance scams, where attackers use AI-generated images, voice cloning, and deepfakes to build convincing fake profiles, often targeting individuals in sensitive roles as a pivot point into organizational systems. This overlaps directly with the deepfake video call scam techniques increasingly seen in business contexts, where a fabricated video call is used to authorize a fraudulent payment or extract credentials. The healthcare sector in the Philippines has also been highlighted as particularly exposed, with a majority of reported breaches in the sector linked to operational disruption that frequently begins with phishing against staff.

What the Data Privacy Act Expects

The Data Privacy Act of 2012 (Republic Act 10173) is the Philippines’ principal data protection law, enforced by the National Privacy Commission (NPC). It requires personal information controllers and processors to implement reasonable and appropriate organizational, physical, and technical security measures to protect personal data against accidental or unlawful destruction, alteration, disclosure, and other unauthorized processing.

The law does not name phishing simulation as a specific requirement. What it does require is a demonstrable, reasonable security posture, and because phishing is consistently the entry point behind the personal-data breaches the NPC investigates, organizations that can show ongoing phishing awareness testing and training are in a materially stronger position to demonstrate that “reasonable and appropriate” standard than organizations relying on a single onboarding-day security briefing. Organizations should confirm their specific obligations under the Data Privacy Act, including any breach-notification timelines that apply to their sector, directly with the NPC or their own legal counsel, as requirements can vary by the type and volume of personal data an organization processes.

What BSP Circular 1213 Changes for Financial Institutions

For banks and BSP-supervised financial institutions, BSP Circular No. 1213 introduced stricter requirements focused on authentication and fraud prevention, with full compliance required within one year of its June 2025 effectivity. The circular limits the use of authentication methods that can be intercepted or shared, such as SMS and email one-time passwords, pushing institutions toward stronger methods like biometric authentication and passwordless solutions such as FIDO2. It also requires high-transaction institutions to deploy real-time fraud management systems performing velocity checks, geo-location analysis, and anomaly detection, along with account-protection measures such as a mandatory pause after account information changes.

BSP Circular 1213 is primarily a technical-controls regulation and does not explicitly mandate employee phishing awareness training. That said, credential phishing remains one of the most direct ways attackers defeat even strong authentication controls, by tricking an employee or customer-facing staff member into handing over a one-time code or session token in real time. Stronger authentication technology reduces some attack paths, but it does not remove the value of testing whether staff can recognize and resist a phishing attempt in the first place, particularly for employees who handle account changes, customer support, or internal system access covered by the circular’s account-protection provisions.

Building a Phishing Simulation Program for the Philippine Market

Given the threat landscape described above, a practical phishing simulation and awareness program for a Philippine organization typically includes:

1

Running a baseline phishing simulation campaign to measure current click-through and reporting rates across departments, including customer-facing and financial-operations staff.

2

Layering in awareness content that reflects the attack types most active in the Philippines right now, including QR-code-based (quishing) and SMS-based (smishing) attacks, both of which are widely used against Philippine mobile users given the country’s high mobile-first internet usage.

3

Extending simulation coverage to staff involved in account changes, wire transfers, or customer verification, given BSP Circular 1213’s focus on these workflows for regulated institutions.

4

Documenting testing and training activity on an ongoing basis to support the “reasonable and appropriate” security-measures standard under the Data Privacy Act.

5

Retesting regularly rather than running a single annual session, since attacker techniques, particularly AI-assisted and deepfake-enabled phishing, are evolving quickly in this market.

PhishCare’s phishing simulation platform supports this kind of ongoing testing, letting organizations run realistic phishing campaigns, track employee response behavior, and generate reporting that can help document security awareness efforts for internal governance or regulatory review. As with any market, no simulation platform by itself satisfies Data Privacy Act or BSP compliance obligations, those determinations should be made with qualified legal and compliance counsel familiar with Philippine requirements.

phishing simulation Philippines

A Note on Language and Templates

PhishCare does not currently offer Filipino-language (Tagalog) phishing simulation templates. Campaigns are run in the languages PhishCare currently supports, which does not include Filipino-language templates at this time. For organizations testing a workforce where English is not the first or most commonly used language day-to-day, this is worth factoring into your evaluation, since a simulation is generally most effective when it closely resembles the language an employee would actually see in a real attack. We would rather be upfront about this limitation than have it surface as a surprise later.

Final Thoughts

The Philippines combines a fast-growing digital economy with a threat landscape where phishing is consistently the starting point for the country’s most damaging incidents, from data breaches to fraud against financial institutions. Neither the Data Privacy Act nor BSP Circular 1213 mandates phishing simulation outright, but both point in the same direction: organizations that can demonstrate ongoing, documented employee testing are better positioned against the attack method actually driving incidents in this market, and better positioned to meet the “reasonable security measures” standard regulators expect.

FAQ

Does Philippine law require phishing simulation testing?

No specific Philippine law names phishing simulation as a mandatory requirement. However, the Data Privacy Act’s requirement for “reasonable and appropriate” security measures, and BSP Circular 1213’s fraud-prevention focus for financial institutions, both create strong practical reasons to test and train employees against phishing, since it is the leading cause of the incidents these frameworks are designed to prevent.

What is BSP Circular 1213?

It is a Bangko Sentral ng Pilipinas regulation that tightened authentication and fraud-monitoring requirements for banks and financial institutions, limiting interceptable authentication methods like SMS OTPs and requiring real-time fraud management systems. Full compliance was required within one year of its June 2025 effectivity.

Who enforces the Data Privacy Act in the Philippines?

The National Privacy Commission (NPC) is the Philippines’ data protection authority responsible for enforcing the Data Privacy Act of 2012 (Republic Act 10173).

Does PhishCare offer Filipino-language phishing simulation templates?

Not currently. PhishCare does not offer Filipino (Tagalog)-language templates at this time. This is worth considering if your workforce primarily communicates in Filipino rather than English day-to-day.

Why is phishing such a significant risk in the Philippines specifically?

Independent threat research has identified phishing as the primary initial-access method behind major cyber campaigns targeting the Philippines, including state-linked espionage activity and financially motivated fraud, with romance scams and AI-assisted phishing techniques an increasingly prominent variant in this market.

How often should Philippine organizations run phishing simulations?

There is no legally mandated frequency. Many organizations run an initial baseline test followed by ongoing campaigns (commonly quarterly or more often), building a documented pattern of testing that supports both Data Privacy Act “reasonable measures” expectations and, for regulated financial institutions, BSP compliance documentation.

Content Reviewed By

Mohammed Nawaz Sajjad, Sr. Security Analyst at PhishCare
Mohammed Nawaz Sajjad
Sr. Security Analyst at CyberSapiens | Phishing Simulation | Ethical Hacker | Bug Hunter | Red Team

Nawaz is a practising security analyst specializing in phishing simulation campaigns, employee awareness assessments, red team exercises, and ethical hacking.

He leads phishing simulation deployments at PhishCare, a product developed by CyberSapiens, with hands-on experience evaluating and deploying phishing simulation tools across organizations in multiple industries and regions globally.

View LinkedIn Profile

See How PhishCare Can Help

See how PhishCare’s phishing simulation platform can help your organization test and train employees against the phishing techniques currently driving incidents in the Philippines.