SchoolBreach.org
BreachesTrendsToolsLearnAbout
Free Security Check
Security Check
SchoolBreach.org

A public resource tracking data breaches in Philippine schools. Helping administrators protect student data through awareness, education, and free security tools.

© 2026 SchoolBreach.org · A community service by OceanEd

Navigate

  • Breaches
  • Trends
  • Tools
  • Learn
  • Methodology

Company

  • About
  • Privacy Policy
  • Terms of Service
  • Contact Us

Disclaimer: This tracker is maintained for educational and awareness purposes. Incidents are documented using threat intelligence monitoring, Philippine media reports, NPC filings, and responsible disclosures. Social media platforms are monitored for leads and are corroborated before publication or naming — never through active scanning or exploitation. Severity ratings and summaries are prepared with AI assistance and reviewed editorially. Full methodology →

Philippine School Data Breach Tracker

A public resource tracking cybersecurity incidents affecting Philippine schools. Because student data deserves better protection.

Free Security ToolsLearn & Guides
87
Incidents Tracked
19.2M+
Records Affected
20
Critical Severity
10
Unresolved
5
Days Since Last Incident

Why Track School Breaches?

Schools hold some of the most sensitive data imaginable — children's personal information, family details, medical records. Yet most Philippine schools lack the resources and awareness to protect this data. This tracker exists to raise awareness and drive change.

Raise Awareness

Most schools don't know breaches are happening in Philippine education. Visibility is the first step to action.

Document Patterns

By tracking incidents, we identify common attack vectors and vulnerabilities so schools can prioritize defenses.

Drive Better Security

Every breach listed here includes lessons learned. We want schools to learn from others' mistakes, not their own.

Protect Your School

Free tools and educational resources to assess your school's security posture and build a culture of data protection.

Free Security ToolsGuides & Resources

All Incidents (87)

Showing 10 of 87
criticalunconfirmedUnauthorized Access

A private medical college in Cebu City

On July 23, 2026, a Facebook post by 'Nullsec Philippines' addressed a private medical college in Cebu City — previously the subject of a May-June 2026 Quantum Security Group defacement and data-exfiltration claim tracked separately on this site — claiming to have deleted files on the institution's systems and linking to an archive.md snapshot of the site's pages 'before the disaster.' The post included two embedded screenshots: one showing a webshell-style file-manager interface with a mass-deletion command whose visible output was dominated by permission-denied errors rather than confirmed successful deletion, and a second showing a web-based database-administration tool (Adminer) open against the institution's production Student Information System, displaying a student-fee table's column structure without any row-level data. No student records or data export were shown or claimed. The institution has not issued a public statement about either incident. This entry is recorded as 'unconfirmed' on the basis of the single threat-actor post; the specific hostname, database name, and account handles are not reproduced on this site.

Jul 23, 2026No specific record count claimed or shown; screenshots reviewed demonstrate webshell (command-execution) access and Adminer database-administration access to the production Student Information System, but no row-level student or staff data was shown extracted records
highunconfirmedDatabase Leak

A private computer college campus in Rizal province

On July 21, 2026, a Facebook post attributed to the page 'Nullsec Philippines' addressed a private computer college campus in Rizal province, opening with personal grievances from self-described former students against unnamed staff before framing a claimed breach as a test of the institution's own technology and cybersecurity teaching. The post included a 'HIT BY NULLSEC' defacement banner, a dense greetz line naming recurring and previously undocumented handles signed 'N Z & friends,' and an enumeration of on the order of 140 student records (name, ID number, program/strand, and a hashed password) spanning the ICT, ABM, and STEM tracks, alongside a separate spreadsheet screenshot suggestive of staff/employee credential exposure. The institution has not issued a public statement. This entry is recorded as 'unconfirmed' on the basis of the single threat-actor claim; specific account names, password hashes, and reference URLs are not reproduced on this site.

Jul 21, 2026On the order of 140 student records visible across the screenshots reviewed (name, student ID number, program/strand, and a hashed password per row), claimed by the threat actor; the post's own structure suggests the underlying list may be longer, and a separate screenshot suggests possible additional staff/employee credential exposure records
mediumunconfirmedMisconfiguration

A private university in Metro Manila

On July 14, 2026, the Facebook account 'Nullsec Philippines,' signed by the persona 'Nostra,' publicly addressed a private university in Metro Manila's official Facebook page, stating the group was 'not getting involved anymore' but asking the institution to fix its website. Two attached screenshots showed a publicly reachable phpinfo() diagnostic page and the raw, unexecuted source code of a third-party database-administration script, which exposed the script's access password and the site's database credentials in cleartext. No data extraction, defacement, or unauthorized access was claimed. The institution has not issued a public statement, and this entry is recorded as 'unconfirmed' on the basis of a single threat actor's post.

Jul 14, 2026None claimed; the post is a public vulnerability warning rather than a data-exfiltration or breach claim records
highconfirmedData Exposure

Technological University of the Philippines - Manila

On July 4 and July 5, 2026, the Facebook account 'Nullsec Philippines' addressed the Technological University of the Philippines - Manila (TUP Manila) admissions office directly, first sharing a screenshot of dozens of applicant photographs and then a follow-up post sharing a password-protected cloud-storage folder said to contain a larger set of the same. On July 9, 2026, TUP Manila's University Student Government (USG) published a public 'Update and Statement' acknowledging reports received on July 6 of 'alleged unauthorized access' to Applicant ERS (admissions) information, and stating that the University Information Technology Center (UITC) — TUP's official IT unit — opened an investigation the same day that remains ongoing. The USG statement is a student-government publication rather than a release from TUP's central administration or communications office, but it relays UITC's own acknowledgment that a report was received and is under active investigation, which is sufficient public corroboration under SchoolBreach.org's methodology to de-anonymize this entry and move its status from 'unconfirmed' to 'confirmed.'

Jul 4, 2026Manila, Metro ManilaUndetermined; a partial screenshot showed roughly 90 applicant photographs, and the threat actor's follow-up post claims the shared archive represents only 'half' of the full set held records
criticalinvestigatingDatabase Leak

A private medical college in Cebu City

On May 31, 2026, a Facebook post by 'Quantum Security Group' (QSG) — signed by the handle 'ZeuS' with the Telegram contact '@XantyEvander' and a Blogspot archive at quantum-sec-group.blogspot.com — addressed a private medical college in Cebu City. The post claimed and provided index-page URLs for the simultaneous defacement of 27 distinct subdomains on the institution's primary domain, including subdomains corresponding to canteen and food-service microsites, three named development environments (dev/dev2/dev3), file storage, library systems, the student information system, three visa-processing subdomains, a campus-perks system, an iCash payment subsystem, and — most operationally significant — a publicly-accessible phpMyAdmin database-administration interface. No data exfiltration was claimed at the time. The defacement was simultaneously registered to a public deface-tracker mirror under the actor's handle. In a follow-up post under the same banner (June 2026, signed collectively as 'QSG Team'), QSG escalated the claim — stating it had exfiltrated the institution's data records and advertising a six-part multi-volume 7z archive set as publicly downloadable via a base64-encoded file-sharing link. On the strength of that exfiltration claim and its accompanying multi-volume archive artifacts, this entry's severity has been raised to critical. The institution name, the specific subdomain URLs, the archive filenames, and the download link are not reproduced on this site. The institution has not issued a public statement.

Jun 24, 2026Unspecified (bulk data exfiltration claimed; volume not disclosed) records
criticalunconfirmedUnauthorized Access

A private Catholic university in Mindanao

On June 2, 2026, a Facebook post by 'Nullsec Philippines' — signed by the handles '0x.Zh3n' and '0xTerror' — addressed a private Catholic university in Mindanao and published what the actors claim is the result of an unauthenticated file-read exploitation of a PeopleSoft WSRP Consumer ResourceProxy servlet on the institution's student-records subsystem. The post enumerates 11 AES-encrypted application credentials extracted from WebLogic domain and boot configuration files (covering the domain, the node manager, the SSL private key passphrase, the Java keystore and truststore, the embedded LDAP, the database connection, and the boot administrator), 7 SHA-512 crypt password hashes from the operating-system shadow file (including an admin account and six named user accounts), 1 RSA public key from authorized_keys, the WebLogic domain AES master encryption key file, and six years of historical Java keystore backups (2019, 2021, 2022, 2023, 2025). The post discloses the specific credential blobs, hash values, the affected hostname, the internal database IP, and the named user accounts in cleartext form; none of these values are reproduced on this site. The institution has not issued a public statement. This entry is recorded as 'unconfirmed' on the basis of the single threat-actor claim; the institution name and all identifying values are redacted pending public confirmation.

Jun 2, 2026No student records claimed; 11 AES-encrypted application credentials, 7 SHA-512 OS-level password hashes, 1 RSA public key, the WebLogic domain encryption-key file, and six years of historical keystore backups claimed by the threat actor records
criticalunconfirmedDatabase Leak

A private IT-focused university chain in the Philippines

On May 27, 2026, a Facebook page operating under the name 'Quantum Security Group' (QSG), signed by the handle '#ch4nc3ll0rx_1337', claimed in a public post addressed to a private IT-focused university chain in the Philippines that they had compromised one of the institution's subdomain portals and exfiltrated ≈200,100 student records along with ≈4,044 records of submitted student-requirement documents (transcripts, birth certificates, Form 138/137, diplomas, government IDs, and other personal documentation). The actor framed the disclosure around the irony that the institution publicly markets cybersecurity courses and programs. The institution has not issued a public statement. This entry is recorded as 'unconfirmed' on the basis of the single threat-actor claim; specific identifying URLs, the exfiltrated proof links, and the actor's download URLs are not reproduced on this site.

May 27, 2026≈200,100 student records and ≈4,044 student-requirement document submissions claimed by the threat actor records
highinvestigatingUnauthorized Access

A state university in Western Visayas

On May 20, 2026, the Facebook account '4b1smo' (a Nullsec Philippines-affiliated account) addressed a state university in Western Visayas with the one-word framing 'hmmm,' tagging the institution's official Public Information Office page. The post included a single composite screenshot of the institution's homepage with a Notepad window overlaid, captioned 'TANGINANG YAN HAHAHAH 4B1SMO' and headed 'DATABASE'. The Notepad listed four grades-related database names alongside the standard MySQL information_schema system database — a pattern consistent with the output of either a `SHOW DATABASES` command or a `SELECT schema_name FROM information_schema.schemata` query, both of which require either authenticated database access or an SQL-injection foothold to obtain from outside. No sample rows, no record count, no specific URL, and no exfiltrated file were attached. The institution name has been withheld in public display pending corroboration.

May 20, 2026Unknown (databases enumerated; no record count claimed) records
criticalinvestigatingDatabase Leak

A state university in Mindanao

On May 10, 2026, a state university in Mindanao was publicly named in a Facebook post by Nullsec Philippines (signed by 'Yasuo' and '0xTerror') claiming a comprehensive credentialed compromise. The actor claims to have obtained LDAP administrative credentials, database usernames and passwords, internal IP addresses and infrastructure details, configuration and authentication information, an estimated 24,942 student records, and — most operationally significant — the SMTP master key for the institution's no-reply email account. Specific credentials and identifying URLs are not reproduced on this site. The institution has not yet issued a public statement; this entry is tracked as 'investigating' on the basis of the threat-actor claim alone, with severity recorded as 'critical' due to the combination of bulk student-record exposure, claimed admin-tier credentials, and a working email-server master key that — if authentic — would enable institution-wide phishing impersonation against the entire affected student body.

May 10, 2026≈24,942 student records claimed by the threat actor; LDAP and database credentials and an SMTP master key separately claimed records
highconfirmedData Exposure

Philippine Universities — Canvas LMS Breach

On May 2, 2026, Instructure — the U.S.-based owner of the Canvas LMS — disclosed that the threat-actor group ShinyHunters had compromised its environment and claimed roughly 275 million records as ransomware-style extortion. Canvas is widely deployed across Philippine higher education, so the impact is sector-wide. As of mid-May 2026, at least five universities are publicly tied to the incident: DLSU and Ateneo de Manila confirmed as Instructure-notified affected clients; UST and University of the East issued coordinating advisories; San Beda experienced related Canvas service disruption. Per Instructure's global-scope statement, names, email addresses, student ID numbers, and Canvas platform messages were affected; passwords, dates of birth, government identifiers, and financial information are reported as not involved. Per-institution scope is pending Instructure's clarification.

May 6, 2026NationwideUnknown records