CSIDB logo
Threat actor

Anonymous Philippines

Attribution profile

Type
Activist
Location
Philippines
Known incidents
2 incidents
First seen
2015-01-31
Last seen
2024-06-16
Updated
2026-08-01 08:13
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known as Anonymous Philippines, also operating under the alias ph1ns, is based in the Philippines. The group has been active since at least 2015, conducting operations that are publicly attributed to the Anonymous collective. Its activities are primarily conducted under the banner of hacktivism, with public statements framing actions as protests against perceived government shortcomings. No public indication ties the actor to a state sponsor or a formal criminal organization.

The actor’s observed targets are Philippine government institutions, including agencies such as the Maritime Industry Authority, the Department of Science and Technology, and the Philippine National Police. In addition to core agencies, the actor has defaced websites associated with territorial sovereignty debates and online freedom advocacy. Strategic objectives demonstrated in the incidents include the disruption of services through website defacement and the exfiltration of sensitive personal and potentially financial data. The 2024 breach of the Maritime Industry Authority relied on an unrestricted file upload vulnerability to gain initial access and extract approximately twenty gigabytes of data. No specific malware families or custom tooling are described in the reporting; the actor’s methodology appears to focus on exploiting web application flaws. The defacement campaigns involve altering website content to deliver political messages demanding accountability and justice.

Attribution to Anonymous Philippines is supported by the group’s use of its name in public messages and by security researchers linking the ph1ns handle to prior government breaches. The actor has not been linked to any state‑backed program or criminal consortium in open sources. Two representative operations illustrate the actor’s pattern: the 2015 defacement of roughly twenty Philippine government websites to protest the president’s response to the Mamasapano clash, and the 2024 intrusion into the Maritime Industry Authority that resulted in a large data leak. Both actions were accompanied by public statements that framed the activity as a call for respect, justice, or improved security practices. These examples show a recurring focus on Philippine governmental targets and a blend of disruption and data exposure tactics.

Incidents

Attributed incidents are available to members.

2 incidents
CSIDB