More than 216,000 accounts linked to the Philippines were leaked from April to June 2026, bringing the country’s total number of compromised user accounts to 155.6 million since 2004, according to a cybersecurity company.
The latest figure was lower than the 624,400 leaked accounts recorded by the Philippines in the first quarter of 2026, based on Surfshark’s previous data release. Despite the quarterly decline, the company said breach numbers remain above 2025 levels.
READ: Philippines records 624,400 leaked accounts in Q1 2026 as cyberattacks surge globally
Surfshark said the Philippines ranked second in Southeast Asia in terms of compromised user accounts since 2004.
The cybersecurity company reported that 57.6 million unique email addresses from the Philippines have been breached, while 78.2 million passwords were leaked alongside Filipino accounts. These leaked passwords put 50% of breached users at risk of account takeover, according to Surfshark.
The company also noted that, statistically, the average Filipino has been affected by a data breach at least once.
Globally, 102 million accounts were breached in the second quarter of 2026. The United States accounted for 29% of all leaked accounts from April to June, followed by France, Poland, Brazil, and the United Kingdom.
Surfshark’s quarterly data showed a 51% decrease in leaked accounts compared with the previous quarter. However, the company reported that the number of breached accounts during the first half of 2026 increased by 16% compared with the second half of 2025.
Surfshark Chief Security Officer Tomas Stamulis said the decline in recent breach figures should not give users a false sense of security.
“While breach volumes may appear slightly lower compared to the start of the year, they remain way above 2025 levels. We are also seeing attackers shift their focus toward easier targets, particularly public-sector and government institutions that often lack sufficiently robust cybersecurity defenses,” Stamulis said.
He added that stolen information can continue to pose risks even years after a breach.
“Lower numbers should not lull people into a false sense of security. A drop in recent exposure does not mean the threat has passed, because stolen data usually does not expire,” Stamulis said.
Stamulis said information obtained from previous breaches can remain in circulation for a long time and may later be used in fraud schemes, account takeovers, identity abuse, scams, and financial theft.
The cybersecurity firm’s data also highlighted a regional shift in global breaches, with Europe surpassing North America in the number of breached accounts during the previous quarter for the first time since 2020.
In Q2 2026, one in three breached accounts worldwide came from Europe, while 7.9% originated from Asia. Nearly 26% of breached accounts had unknown origins.
To stay safe online and limit exposure, Stamulis advised users to treat personal information as sensitive by default and only disclose it when necessary.
“As a general rule, treat all your personal information as sensitive by default and disclose it only when absolutely required,” he said.
He also advised users to share real personal details only when there is a genuine, necessary reason, such as completing official or legally required forms. For other situations, he recommended limiting exposure by using an alias, a secondary email address, or an email-masking service.