6 million exposed, and who signs for offshore legal staffing

76 breaches in a quarter is a fact about a country, not about your hire.

Filipino legal virtual assistant reviews documents with a colleague in a home office.
3 min readPublished Sep 10, 2026
DA
Davin Acuram

Outsource Accelerator reported that data breaches tied to Manila contact centers are now being read as evidence about the entire Philippine outsourcing sector. Buyers are pricing offshore risk at the location level, which is a fact about procurement departments rather than about any individual hire.

The reference case in that report is a vishing attack on Qantas Airways' Manila-based contact center in June 2025, which exposed the data of 6 million customers. Criminals phoned in and impersonated IT staff. Somebody believed them.

Where the numbers come from

Citing BusinessWorld, Outsource Accelerator reported 76 data breach incidents in the Philippines in the third quarter of 2025, compromising roughly 4 million accounts, a 49% increase over the prior quarter. The report sets that against the industry association's roadmap of at least $43.3 billion in revenue and 1.85 million AI-enabled workers by 2028. It also notes a sector of 1.9 million workers and a $40 billion revenue floor.

So the incident count sits on top of a working population of 1.9 million people. That tells you a country has a security training gap. It does not tell you which desk. Different unit of measure.

Priced by location

Analysts quoted in the report say clients associate a high-profile breach with systemic weakness across offshore delivery generally. That instinct is not lazy. A procurement team can audit a location, demand a certified governance framework, and read a third-party security report. It cannot audit judgment. Checkable beats accurate, every time, when a contract renewal is on the calendar.

But a country is a strange thing to underwrite. Asking a vendor which country the work sits in, and stopping there, buys a proxy for a hundred separate things. Location-level pricing has never been cross-examined. The attack in the report did not exploit a time zone. It exploited a help desk that took a stranger at his word.

What a firm actually buys

A firm hiring one paralegal, or four, is not buying seats on a floor of a thousand. It is buying a named person with credentials to specific systems, supervised by someone who knows their voice. Social engineering scales where anonymity does. Forty people in a firm is not that. What does not shift is the duty: supervision of delegated work does not change with the country the work sits in, and no vendor certificate carries it for you.

Ask who can reset a password.