Data breaches threaten Philippine outsourcing’s global standing

- The Philippines recorded 76 data breach incidents in the third quarter of 2025
- They compromised about 4 million accounts, up 49% on the quarter
- A Qantas Manila vishing attack exposed 6 million customers
- IBPAP targets at least $43.3 billion in revenue by 2028
MANILA, PHILIPPINES — Data security incidents are posing reputational risks for the Philippines’ information technology-business process management (IT-BPM) sector, with analysts warning that prominent breaches linked to Manila-based contact centers are reinforcing perceptions of weaker security controls in offshore delivery, threatening the industry’s US$43.3 billion revenue roadmap.
According to a report by BusinessWorld, the concerns follow a vishing attack on Qantas Airways’ Manila-based contact center in June 2025 that exposed the data of 6 million customers, alongside a broader pattern of rising data breach incidents across the Philippines’ digital economy.
Qantas breach and incident surge expose offshore delivery to client risk-repricing
The Philippines recorded 76 data breach incidents compromising approximately 4 million accounts in the third quarter of 2025, a 49% increase over the prior quarter that analysts say is inconsistent with growing business process outsourcing (BPO) delivery ambitions.
The Qantas incident — in which cybercriminals used voice phishing to impersonate information technology (IT) personnel at a Manila-based call center — became the reference case analysts cite when assessing the Philippine offshore sector’s exposure to social-engineering threats.
The Information Technology and Business Process Association of the Philippines (IBPAP) roadmap targets at least US$43.3 billion in revenue and 1.85 million artificial intelligence (AI)-enabled workers by 2028, a trajectory analysts say depends on maintaining client confidence in the sector’s data-handling practices.
The Philippines’ IT-BPM industry faces rising competitive pressure from India, Egypt, and Vietnam, with analysts noting that clients increasingly price offshore delivery risk at the location level, making data breach incidents in Manila-based contact centers a sector-wide reputational exposure, not only a firm-level operational failure.
Dominic Vincent D. Ligot, Director for AI Ethics & Data Governance at the Philippine AI Business Association, said any reported cybersecurity incident affects the Philippines’ standing as a global IT-BPM hub, as clients tend to associate high-profile breaches with systemic weakness in offshore delivery security controls.
Industry calls for stronger cybercrime enforcement and legislative reform
IBPAP said member firms are continuing to invest in cybersecurity safeguards, responsible information access controls, and compliance with applicable regulations, while the association advocates for passage of the Critical Information Infrastructure Protection Act and stronger enforcement of the Cybercrime Prevention Act of 2012.
Analysts called for accelerated implementation of the National Cybersecurity Plan 2023-2028 and wider adoption of authentication tools such as One Trust Link (OTL) to reduce social-engineering exposure of the kind that enabled the Qantas vishing attack.
The Philippine AI Business Association recommended that cybersecurity become a standard academic track across all universities, addressing the gap between the sector’s digital growth rate and the available pool of trained security professionals.
For BPO operators and buyers with Philippine delivery, the breach pattern creates pressure from two directions: clients repricing offshore risk by location, and regulators tightening standards for operators handling foreign consumer data.
The sector’s 1.9 million workers and US$40 billion revenue floor provide structural resilience, but location-level risk pricing is the mechanism by which high-profile incidents can affect contract renewal timelines across the industry.
Buyers evaluating Philippines-based contracts should expect growing requirements for certified data governance frameworks and third-party security audits as pre-qualification criteria.
Related news
- Philippine BPO firms urged to boost cyber recovery amid rising attacks · 19 Feb
- Philippines’ $40Bn IT-BPM sector at risk as cyberattacks threaten trust · 8 Jul 2025
Disclosure: Outsource Accelerator uses AI tools in the backend of its editorial workflow. Every article is reviewed and verified by a human editor before publication.
Stay ahead of the outsourcing industry. Join thousands of business leaders who rely on Outsource Accelerator for the news, trends, and expert insights that matter. Subscribe to our free newsletter and never miss an update.

Independent




