Philippines

Maya and GCash Are Naming Their Cyber Threats Out Loud, Right Before Their IPOs

5 min read

Maya and GCash, the two platforms that between them handle a meaningful share of the Philippines’ everyday financial life, both went on record this week naming the same three things as their biggest cybersecurity threats: ransomware, phishing, and AI-enabled attacks. Maya specifically flagged account takeover attempts against its consumers and phishing campaigns targeting its own employees’ passwords and identities. In response, the company pointed to multi-factor authentication, biometric verification, and AI-based anomaly detection as its current lines of defense. GCash, which serves more than 94 million registered users, said it considers its platform secure regardless of transaction volume.

None of this is a surprising list. What is worth paying attention to is the timing and the fact that it was said publicly at all, by both companies, in the same week. Fintech platforms do not typically volunteer detailed threat taxonomies to the press unless there is a reason to get ahead of the conversation — and both companies currently have an unusually good reason.

The IPO Backdrop Changes What “Disclosure” Means

Mynt, GCash’s parent company, has already filed its registration statement with the SEC and its listing application with the Philippine Stock Exchange, targeting a fourth-quarter debut with an offer period tentatively scheduled for early October and a listing date pencilled in for late October. The filing sets a maximum indicative price of P10 per share across up to 8.03 billion common shares, with proceeds potentially reaching P92.3 billion if the overallotment option is fully exercised — which would make it the largest IPO in Philippine market history. Maya, for its part, has been separately evaluating a US listing that could raise up to $1 billion, backed by its major shareholders KKR, Tencent, and the International Finance Corporation, alongside continued discussion of a follow-on Philippine listing.

Once a company is inside a real IPO process, cybersecurity stops being purely a customer-trust issue and becomes a disclosure issue. Prospective public shareholders, underwriters, and regulators expect platforms of this scale to demonstrate they understand their own threat surface in specific terms, not just in the generic language of a corporate social responsibility page. Naming ransomware, phishing, and AI-enabled attacks as the top three threats — rather than issuing a vague statement about “taking security seriously” — reads less like a voluntary consumer-safety announcement and more like the kind of specific, defensible language that tends to show up in risk-factor sections of an actual prospectus. Both companies effectively pre-announced, in consumer-friendly form, what investors would eventually be reading in far drier language inside their own regulatory filings.

The Threat Landscape Behind the Statement Is Real, Not Boilerplate

The specific threats both companies named line up closely with what regional law enforcement has already been documenting. Interpol’s own Asia and South Pacific Cyber Threat Assessment Report for 2025/2026 found that cybercrime now accounts for roughly 30% of all recorded crime in more than half of the Asia-Pacific countries it surveyed, with phishing, ransomware, and AI-enabled scams identified as the dominant categories. The same report describes transnational organized crime networks running large-scale scam operations across the region — some involving forced labor — that collectively generate close to $40 billion a year through tactics like romance-based fraud and fake investment schemes. The Philippines, given its dense mobile-wallet adoption and large diaspora remittance flows, sits squarely inside the kind of market these operations target.

That regional context matters for how seriously this week’s disclosures should be read. This isn’t two companies reacting to a single incident or manufacturing a headline; it’s two dominant platforms acknowledging, in public, a threat pattern that regional law enforcement has already flagged as escalating and increasingly automated. AI-enabled attacks specifically move faster than the manual fraud tactics Philippine fintech platforms were originally built to detect — anomaly-detection systems tuned for human-paced fraud attempts have to be re-tuned for attacks that can iterate and adapt in real time, which is presumably part of why both companies pointed to AI-based detection as part of their own countermeasures rather than treating it purely as a threat category.

What This Means for the Rest of the Ecosystem

GCash and Maya are the two platforms every other Philippine fintech and startup effectively builds around — as a rail for payments, as a login method, as the assumed baseline for what “secure enough” looks like to a Filipino consumer. When the two largest platforms in the country say plainly that AI-enabled attacks are now a top-tier threat category, that is a signal smaller fintech operators, lenders, and marketplaces integrating with either platform should take seriously in their own security posture, not just a data point about two companies preparing to go public. It also raises the bar for what “security” needs to mean in a startup’s own pitch to investors here: a founder who can speak specifically about ransomware, phishing, and AI-enabled fraud vectors — rather than gesturing at compliance checkboxes — is speaking the same language the country’s two largest fintech platforms are now using with their own future public shareholders.

cybersecurity fintech GCash IPO Maya

Share this article

Share on X Share on LinkedIn Share on Facebook

Related Articles

Newsletter

By subscribing, you agree to our Privacy Policy.