The National Privacy Commission (NPC) has revealed that the recent security breach in GCash, which resulted in numerous account holders reporting unauthorized transactions, was a result of sophisticated phishing attacks.
Privacy Commissioner John Henry Naga confirmed the findings of a thorough investigation conducted by the agency.
According to the NPC, vulnerable GCash users were targeted and manipulated through a meticulous phishing scheme. These unsuspecting users were enticed to visit online gambling websites, including Philwin and tapwin1.com, where their personal information was compromised.
The NPC’s investigation into the matter began on May 9, 2023, after receiving multiple complaints from GCash account holders regarding unauthorized transactions.
A meeting between the NPC and G-Xchange Inc. (GXI), the operator of GCash, took place on May 12, 2023. As part of the inquiry, the NPC requested additional information and evidence from GXI to independently verify that the security breach was indeed a result of a phishing attack.
GXI complied with the NPC’s request and submitted the requested information on May 19.
In response to the incident, GXI has been directed to enhance its education and awareness campaign to prevent similar occurrences in the future.
The NPC is determined to fulfill its mandate of safeguarding the rights of data subjects and protecting personal information.
Naga emphasized that the commission would utilize the full extent of its powers under the Data Privacy Act of 2012 to penalize those responsible for violating data privacy regulations.