A public resource tracking cybersecurity incidents affecting Philippine schools. Because student data deserves better protection.
Schools hold some of the most sensitive data imaginable — children's personal information, family details, medical records. Yet most Philippine schools lack the resources and awareness to protect this data. This tracker exists to raise awareness and drive change.
Most schools don't know breaches are happening in Philippine education. Visibility is the first step to action.
By tracking incidents, we identify common attack vectors and vulnerabilities so schools can prioritize defenses.
Every breach listed here includes lessons learned. We want schools to learn from others' mistakes, not their own.
Free tools and educational resources to assess your school's security posture and build a culture of data protection.
On August 1, 2026, a Facebook page using the name 'CrimsonSec Philippines,' signed by the persona 'Ph.0xUnknown404,' addressed a university in Bicol Region, claiming to have found and exploited a vulnerability in the student information and accounting portal that students log into. The post claims the actor viewed tens of thousands of student records containing names, photographs, home addresses, contact numbers, parent details, dates of birth and account passwords described as crackable within minutes and reused on other services. The post states that nothing was copied or sold and makes no demands, while attaching screenshots that appear to show a student roster spreadsheet, a directory of several hundred student identification photographs, and roughly a hundred database table exports — material that is not reproduced on this site. The institution has not issued a public statement, and no independent media or researcher corroboration has been found. This entry is recorded as 'unconfirmed' on the basis of the single threat-actor claim.
On July 23, 2026, a Facebook post by 'Nullsec Philippines' addressed a private medical college in Cebu City — previously the subject of a May-June 2026 Quantum Security Group defacement and data-exfiltration claim tracked separately on this site — claiming to have deleted files on the institution's systems and linking to an archive.md snapshot of the site's pages 'before the disaster.' The post included two embedded screenshots: one showing a webshell-style file-manager interface with a mass-deletion command whose visible output was dominated by permission-denied errors rather than confirmed successful deletion, and a second showing a web-based database-administration tool (Adminer) open against the institution's production Student Information System, displaying a student-fee table's column structure without any row-level data. No student records or data export were shown or claimed. The institution has not issued a public statement about either incident. This entry is recorded as 'unconfirmed' on the basis of the single threat-actor post; the specific hostname, database name, and account handles are not reproduced on this site.
On May 31, 2026, a Facebook post by 'Quantum Security Group' (QSG) — signed by the handle 'ZeuS' with the Telegram contact '@XantyEvander' and a Blogspot archive at quantum-sec-group.blogspot.com — addressed a private medical college in Cebu City. The post claimed and provided index-page URLs for the simultaneous defacement of 27 distinct subdomains on the institution's primary domain, including subdomains corresponding to canteen and food-service microsites, three named development environments (dev/dev2/dev3), file storage, library systems, the student information system, three visa-processing subdomains, a campus-perks system, an iCash payment subsystem, and — most operationally significant — a publicly-accessible phpMyAdmin database-administration interface. No data exfiltration was claimed at the time. The defacement was simultaneously registered to a public deface-tracker mirror under the actor's handle. In a follow-up post under the same banner (June 2026, signed collectively as 'QSG Team'), QSG escalated the claim — stating it had exfiltrated the institution's data records and advertising a six-part multi-volume 7z archive set as publicly downloadable via a base64-encoded file-sharing link. On the strength of that exfiltration claim and its accompanying multi-volume archive artifacts, this entry's severity has been raised to critical. The institution name, the specific subdomain URLs, the archive filenames, and the download link are not reproduced on this site. The institution has not issued a public statement.
On June 2, 2026, a Facebook post by 'Nullsec Philippines' — signed by the handles '0x.Zh3n' and '0xTerror' — addressed a private Catholic university in Mindanao and published what the actors claim is the result of an unauthenticated file-read exploitation of a PeopleSoft WSRP Consumer ResourceProxy servlet on the institution's student-records subsystem. The post enumerates 11 AES-encrypted application credentials extracted from WebLogic domain and boot configuration files (covering the domain, the node manager, the SSL private key passphrase, the Java keystore and truststore, the embedded LDAP, the database connection, and the boot administrator), 7 SHA-512 crypt password hashes from the operating-system shadow file (including an admin account and six named user accounts), 1 RSA public key from authorized_keys, the WebLogic domain AES master encryption key file, and six years of historical Java keystore backups (2019, 2021, 2022, 2023, 2025). The post discloses the specific credential blobs, hash values, the affected hostname, the internal database IP, and the named user accounts in cleartext form; none of these values are reproduced on this site. The institution has not issued a public statement. This entry is recorded as 'unconfirmed' on the basis of the single threat-actor claim; the institution name and all identifying values are redacted pending public confirmation.
On May 27, 2026, a Facebook page operating under the name 'Quantum Security Group' (QSG), signed by the handle '#ch4nc3ll0rx_1337', claimed in a public post addressed to a private IT-focused university chain in the Philippines that they had compromised one of the institution's subdomain portals and exfiltrated ≈200,100 student records along with ≈4,044 records of submitted student-requirement documents (transcripts, birth certificates, Form 138/137, diplomas, government IDs, and other personal documentation). The actor framed the disclosure around the irony that the institution publicly markets cybersecurity courses and programs. The institution has not issued a public statement. This entry is recorded as 'unconfirmed' on the basis of the single threat-actor claim; specific identifying URLs, the exfiltrated proof links, and the actor's download URLs are not reproduced on this site.
On May 10, 2026, a state university in Mindanao was publicly named in a Facebook post by Nullsec Philippines (signed by 'Yasuo' and '0xTerror') claiming a comprehensive credentialed compromise. The actor claims to have obtained LDAP administrative credentials, database usernames and passwords, internal IP addresses and infrastructure details, configuration and authentication information, an estimated 24,942 student records, and — most operationally significant — the SMTP master key for the institution's no-reply email account. Specific credentials and identifying URLs are not reproduced on this site. The institution has not yet issued a public statement; this entry is tracked as 'investigating' on the basis of the threat-actor claim alone, with severity recorded as 'critical' due to the combination of bulk student-record exposure, claimed admin-tier credentials, and a working email-server master key that — if authentic — would enable institution-wide phishing impersonation against the entire affected student body.
On May 3, 2026, the joint Facebook account 'NSP & DNH' (Nullsec Philippines × Deathnote Hackers International) publicly posted a claim of breach against the DepEd training platform at training.deped.gov.ph, accompanied by a CSV file said to contain 999,995 rows of user data with fields including full names, emails, user IDs, and profile links. Cybersecurity research and advocacy organization Deep Web Konek (DWK) independently reviewed the circulated dataset on the same day and reported that the row count aligns with the actor's claim, that the schema is consistent with structured institutional databases, and that sample entries display realistic naming patterns — assessing the dataset as 'likely authentic with strong internal consistency.' SchoolBreach.org's editorial team independently observed that training.deped.gov.ph is no longer reachable, returning a Cloudflare error rather than the usual training-platform interface as of May 3, 2026 — confirming that DepEd's IT operations team has taken the platform offline in response. The combination of independent dataset validation by DWK and the platform being pulled offline supports tracking this entry as confirmed.
Nullsec Philippines breached two private colleges in San Fernando, La Union by compromising their shared hosting account. Beyond defacing both websites, the attackers exfiltrated the full school database — over 16 CSV tables containing student payments, enrollment records, tuition fees, user accounts with plaintext passwords, and teacher evaluations.
Threat actor 'Ch4nc3ll0rx 1337' defaced the DepEd Tayo Roxas City website (depedroxascity.com), dumped 7GB of web directories and 17MB of compressed databases, and claimed a total of 107 related defacements.
Threat actor '4rch4n63l' from NullsecPhilippines exfiltrated 685,318 records from a public college in Batangas City across two files (profile.json and users.json). Student account passwords were stored and exposed in plain text. The school name has been withheld as the incident was sourced solely from the threat actor's post with no independent confirmation.