Maya and GCash, the Philippines’ two biggest digital wallets, have named ransomware, phishing and AI-enabled attacks as the top cyber threats facing the country’s financial sector, according to BusinessWorld Online. Executives from both fintech platforms said at a Manila cybersecurity forum covered on July 22, 2026, that they are pouring more investment into AI-driven defenses even as the same technology is used to scale attacks against them. The disclosure matters because GCash and Maya together process a large share of the Philippines’ digital payments, making the two platforms a proxy for how exposed the country’s wider financial system is to automated, AI-accelerated fraud.
What exactly did Maya and GCash executives say?
GCash Chief Risk Officer Ingrid Rose Ann Beroña told BusinessWorld Online that the e-wallet platform is leaning on a full suite of technologies to strengthen its operational resilience as financial institutions face constant attacks. “AI is part of our DNA. Everything we do is currently injected with AI, even in a lot of our business plans. We truly believe that AI is okay for us to sustain and scale our business, and to ensure that we are able to embed security into our services,” Beroña said, according to the outlet.
Maya Philippines Director of Information Security Jan Martin Encina told the publication that the company uses AI to detect anomalies and cyberthreat patterns across its systems, and that Maya is “not a company that would shy away from the use of AI because there is a massive opportunity, not just in the area of security but in the business operations.” Encina said Maya will keep increasing its investment in cyber-defense capabilities and is working with the Department of Information and Communications Technology to share threat intelligence, per BusinessWorld Online.
Why are ransomware and phishing still climbing despite heavier AI defenses?
The Maya and GCash warnings track with broader Philippine threat data. Phishing websites targeting the country jumped from 731 in 2024 to 3,824 in 2025, a 423 percent increase, according to newsbytes.ph, which cited Check Point Research. The same report found ransomware incidents nearly doubled, from 9 cases in 2024 to 17 in 2025, with the Qilin group flagged as an aggressive double-extortion actor hitting finance, retail, healthcare, manufacturing and media targets. Social media impersonation, increasingly powered by AI chatbots running investment fraud scripts, rose 37 percent over the same period, per the same source.
“Cyberattacks in the Philippines are no longer defined by technical sophistication, but by scale, automation, and deception,” Check Point senior threat intelligence analyst Ritchelle Santos said, as quoted by newsbytes.ph. That pattern mirrors what our own reporting has tracked in how AI has reached every stage of the cyberattack kill chain: attackers no longer need deep technical skill to run a convincing, high-volume campaign, they need a model and a target list. Elsewhere in Asia, the same shift toward synthetic, AI-generated social engineering has shown up in SEBI’s warning on deepfake CEO impersonation fraud reaching India’s listed companies, and our wider look at why enterprises are not ready for deepfake security threats reaches a similar conclusion: the defense gap is a readiness gap, not a technology gap.
How much are Philippine companies putting behind the defense?
Globe Telecom, the parent company of GCash operator Mynt, Inc., is allocating 56 billion pesos this year to expand AI use across its operations and enterprise services, BusinessWorld Online reported. Cybersecurity Council of the Philippines Chairman Donald Patrick L. Lim said cybersecurity has become an issue of national resilience, framing the AI investment push as a shared national priority rather than a single company’s cost of doing business, according to the outlet. Maya Philippines head of corporate affairs Kristoffer Rada, separately quoted by BusinessWorld Online, called for an industry-wide response on consumer protection, specifically around digital finance scams, rather than each platform defending its own users in isolation.
- Globe Telecom: 56 billion pesos earmarked for AI expansion across operations and enterprise services in 2026
- GCash: full suite of AI tools embedded across business and security functions
- Maya: increased cyber-defense investment plus threat intelligence sharing with the DICT
That framing echoes a point we have made repeatedly on this beat: technology spend alone does not fix a phishing problem, because the entry point is almost always a person, not a firewall. Our comparison of security awareness training against human risk management lays out why fintechs facing the volumes Maya and GCash describe need to measure and reduce human risk continuously, not run an annual training module and call it done.
What should CISOs elsewhere take from the Philippines’ experience?
The Maya and GCash disclosures are a useful data point for any CISO overseeing a consumer financial platform in a fast-growing digital economy, not just one in Southeast Asia. The core lesson is that AI cuts both ways at the same time and on the same budget cycle: fraud teams scale detection with it while the criminal side scales lure generation and impersonation with it, and neither side’s investment cancels the other out on its own. Boards should expect this arms-race framing in risk reports rather than a simple line that “AI defenses are in place.” Our broader survey of what CISOs need to know about AI in 2026 covers the governance questions this raises, from model access controls to how AI-assisted detection claims should be validated before they reach a board slide.
There is also a liability angle regulators in the region are starting to formalize. Our review of India’s 2026 cybersecurity policy and CISO liability rules shows a regional trend toward holding security leadership personally accountable for breach response and disclosure timelines, a direction the Philippines’ own national resilience framing, voiced by Lim, suggests it may follow. For CISOs at financial platforms anywhere, the practical takeaway from Manila is straightforward: treat ransomware, phishing and AI-enabled social engineering as one connected threat category with a single budget line and a single incident response plan, not three separate problems competing for the same headcount.
Frequently asked questions
What cyber threats did Maya and GCash identify as the biggest risk in the Philippines?
Maya and GCash executives told BusinessWorld Online that ransomware, phishing and AI-enabled attacks are the top cyber threats facing the Philippines financial sector. Both companies said they are increasing investment in AI-based detection while acknowledging attackers are using the same technology to scale their campaigns.
How is GCash using AI to defend against cyberattacks?
GCash Chief Risk Officer Ingrid Rose Ann Beroña said the e-wallet platform embeds AI across its business and security operations to sustain growth and protect its services. She described AI as central to the company’s approach as financial institutions face constant attacks, according to BusinessWorld Online.
How much has ransomware and phishing grown in the Philippines recently?
According to newsbytes.ph, citing Check Point Research, phishing websites targeting the Philippines rose 423 percent from 731 in 2024 to 3,824 in 2025, and ransomware incidents nearly doubled from 9 to 17 over the same period, with the Qilin group named as an aggressive actor.

Leave a Reply