The Department of Information and Communications Technology (DICT) is successfully restored the functionality of the Philippine Health Insurance Corporation (PhilHealth) servers, which fell victim to a ransomware attack during the weekend.
PHILHEALTH UPDATES:
- PhilHealth Targeted by Ransomware Attack
- PhilHealth Shuts Down Systems Temporarily After Website Hack
- Hackers of PhilHealth Demand $300,000 Ransom, Says DICT
- PhilHealth Firmly Refuses to Pay ‘Ransom’ Following Cyber Attack
According to a statement posted on their social media page on Thursday, the DICT, specifically its Cybersecurity Bureau, responded proactively to the incident.
As of September 25, 2023, access to PhilHealth’s web services is limited to their IP addresses, and a thorough security scan is currently underway. The DICT fully committed to restoring PhilHealth’s systems and ensuring the protection of government systems against cyber threats.

Over the weekend, the Medusa ransomware took control of PhilHealth’s servers, demanding a ransom of $300,000 about PHP16 million . As of now, the official PhilHealth website is accessible to the public.
