Cyberattackers have compromised multiple organizations in the Philippines, including a nuclear agency, by exploiting old and unpatched vulnerabilities in their systems. The breach highlights the growing threat landscape in the region, where cyberattacks are increasingly used as a tool for espionage and political influence.
The attackers initially gained access to the organizations’ networks through an ownCloud server hosted in Amsterdam. Researchers from Hunt.io discovered the server, which was being used by the attackers to store stolen data and host offensive tools. The server contained 1,310 files totaling nearly 1.2 GB of data, including reactor databases, personnel records, and credential stores. At least two of the victims were identified as a nuclear agency in the Philippines and a marine engineering and shipbuilding company serving the Philippine Navy.
The coding comments and folder names on the server suggest that a Chinese-speaking threat actor was behind the attacks. However, Hunt.io did not attribute the attacks to any specific group. The researchers noted that the attackers used three popular open-source offensive frameworks, but there is no indication that they were used to attack the targeted organizations.
One of the vulnerabilities exploited by the attackers was a known issue in ownCloud’s pre-signed URL mechanism, which allows an attacker to bypass authentication and access data on servers. This vulnerability, tracked as CVE-2023-49105, was disclosed in November 2023 but remained unpatched on internet-facing systems belonging to highly sensitive organizations.
The breach is particularly concerning because it highlights the growing threat of cyberattacks in the Philippines. According to a report from Viettel Security, breach incidents in the region have nearly tripled in the first half of 2026 compared to the same period in 2025. Government agencies are increasingly being targeted, with 18% of incidents affecting them.
The attacks also underscore the importance of patching and inventorying internet-facing collaboration software, such as ownCloud and WordPress sites. Security teams should configure hardware with minimum permission and secure defaults, change signing keys, and implement multifactor authentication and strong passwords on administrative accounts. In this case, the attackers exploited known vulnerabilities in combination with weak configurations to gain access to sensitive systems.
As tensions between China and countries claiming territory in the South China Sea continue to rise, the use of cyberattacks for espionage and political influence is likely to increase. Organizations in the region must prioritize cybersecurity measures to protect themselves against these threats.
Source: Dark Reading — 2026-09-02