A public resource tracking cybersecurity incidents affecting Philippine schools. Because student data deserves better protection.
Schools hold some of the most sensitive data imaginable — children's personal information, family details, medical records. Yet most Philippine schools lack the resources and awareness to protect this data. This tracker exists to raise awareness and drive change.
Most schools don't know breaches are happening in Philippine education. Visibility is the first step to action.
By tracking incidents, we identify common attack vectors and vulnerabilities so schools can prioritize defenses.
Every breach listed here includes lessons learned. We want schools to learn from others' mistakes, not their own.
Free tools and educational resources to assess your school's security posture and build a culture of data protection.
On August 4, 2026, the Facebook account 'Nullsec Philippines,' signed by the persona 'Nostra,' publicly addressed a state university in Mindanao by name and published a link to a plain-text file said to contain extracted student email addresses. The post attached a screenshot of an HTTP interception proxy showing a single POST request to a student-index endpoint on one of the institution's campus subdomains, returning a JSON response that maps institutional student email addresses to first, middle, and last names; the tool reports that single response at roughly 192 KB. A second attached image showed a long, watermarked wall of the same email-and-name pairs. The post was captioned in Tagalog to the effect of 'one more prompt before we go inactive.' The institution has not issued a public statement, no independent media or researcher corroboration has been found, and this entry is recorded as 'unconfirmed' with the institution's name withheld.
On July 25, 2026, a Facebook post signed by the persona 'Ph.Bl4ke' addressed a private college in Cebu City, claiming to have obtained all WordPress account credentials for the institution's website and linking to a downloadable file said to contain the extracted data. The post credited 'CrimsonSec Philippines,' 'Black Bytes,' 'Nullsec Philippines,' and 'St0pc0rrupti0n' in its greetz line, alongside several additional handles under a separate 'Special Greetings' banner. The persona Ph.Bl4ke has previously been linked to three other Philippine school-targeting claims tracked on this site under the 'Storm Breaker Security PH' banner, including one other WordPress-related claim. The institution has not issued a public statement, and no independent media or researcher corroboration has been found. This entry is recorded as 'unconfirmed' on the basis of the single threat-actor claim.
On July 21, 2026, a Facebook post attributed to the page 'Nullsec Philippines' addressed a private computer college campus in Rizal province, opening with personal grievances from self-described former students against unnamed staff before framing a claimed breach as a test of the institution's own technology and cybersecurity teaching. The post included a 'HIT BY NULLSEC' defacement banner, a dense greetz line naming recurring and previously undocumented handles signed 'N Z & friends,' and an enumeration of on the order of 140 student records (name, ID number, program/strand, and a hashed password) spanning the ICT, ABM, and STEM tracks, alongside a separate spreadsheet screenshot suggestive of staff/employee credential exposure. The institution has not issued a public statement. This entry is recorded as 'unconfirmed' on the basis of the single threat-actor claim; specific account names, password hashes, and reference URLs are not reproduced on this site.
On July 4 and July 5, 2026, the Facebook account 'Nullsec Philippines' addressed the Technological University of the Philippines - Manila (TUP Manila) admissions office directly, first sharing a screenshot of dozens of applicant photographs and then a follow-up post sharing a password-protected cloud-storage folder said to contain a larger set of the same. On July 9, 2026, TUP Manila's University Student Government (USG) published a public 'Update and Statement' acknowledging reports received on July 6 of 'alleged unauthorized access' to Applicant ERS (admissions) information, and stating that the University Information Technology Center (UITC) — TUP's official IT unit — opened an investigation the same day that remains ongoing. The USG statement is a student-government publication rather than a release from TUP's central administration or communications office, but it relays UITC's own acknowledgment that a report was received and is under active investigation, which is sufficient public corroboration under SchoolBreach.org's methodology to de-anonymize this entry and move its status from 'unconfirmed' to 'confirmed.'
On May 20, 2026, the Facebook account '4b1smo' (a Nullsec Philippines-affiliated account) addressed a state university in Western Visayas with the one-word framing 'hmmm,' tagging the institution's official Public Information Office page. The post included a single composite screenshot of the institution's homepage with a Notepad window overlaid, captioned 'TANGINANG YAN HAHAHAH 4B1SMO' and headed 'DATABASE'. The Notepad listed four grades-related database names alongside the standard MySQL information_schema system database — a pattern consistent with the output of either a `SHOW DATABASES` command or a `SELECT schema_name FROM information_schema.schemata` query, both of which require either authenticated database access or an SQL-injection foothold to obtain from outside. No sample rows, no record count, no specific URL, and no exfiltrated file were attached. The institution name has been withheld in public display pending corroboration.
On May 2, 2026, Instructure — the U.S.-based owner of the Canvas LMS — disclosed that the threat-actor group ShinyHunters had compromised its environment and claimed roughly 275 million records as ransomware-style extortion. Canvas is widely deployed across Philippine higher education, so the impact is sector-wide. As of mid-May 2026, at least five universities are publicly tied to the incident: DLSU and Ateneo de Manila confirmed as Instructure-notified affected clients; UST and University of the East issued coordinating advisories; San Beda experienced related Canvas service disruption. Per Instructure's global-scope statement, names, email addresses, student ID numbers, and Canvas platform messages were affected; passwords, dates of birth, government identifiers, and financial information are reported as not involved. Per-institution scope is pending Instructure's clarification.
On May 2, 2026, the Facebook account 'Nullsec Philippines' publicly posted a defacement claim against a state university in the MIMAROPA region, listing several of the institution's internal management information system (MIS) subdomains — covering its assets, records, and library functions — as having received `nullsec.html` marker pages. The post also bundled roughly twenty additional defaced URLs on unrelated infrastructure, framing the operation as a coordinated mass-mirror. Multiple screenshots were attached, including images of the defacement page, what appear to be administrative views of an internal MIS dashboard, and an apparent employee identity record — evidence that, if authentic, suggests the actor's access went beyond simple web defacement. The post was signed 'Yasuo' and ended with 'mirror? done~'. The institution has not issued a public statement and the named subdomains have not been independently re-checked at the time of this entry. The university name, its province, the literal subdomain prefixes, and any individual identities visible in the attached screenshots have been withheld in public display pending corroboration.
On May 1, 2026, the Facebook account 'Nullsec Philippines' publicly posted addressing a private K-12 institution, attaching screenshots of what appears to be a logged-in administrative session on the school's student information system. The screenshots include a per-student fee and assessment view (with full student name, gender, year level, and a multi-year assessment history), a coordinator/subject-teacher grade-posting roster, and aggregate admission and assessment dashboards covering both new and returning students with gender-broken-out totals. The exposure spans data on minors. The institution name has been withheld in public display, and identifying section, student, and staff names from the screenshots are not reproduced on this site.
On May 1, 2026, the Facebook account 'Nullsec Philippines' publicly posted addressing a Catholic K-12 institution, attaching screenshots of an Admin Dashboard branded with the institution's name. The post is notable because the threat actor explicitly stated that the institution's website developer is the same one who built another school previously claimed in this batch — making the shared-vendor / supply-chain pattern an actor-confirmed claim rather than an inference. The screenshots show admin-level access to admission and assessment dashboards, a multi-year per-student payments view including nursery-age children, and per-level / per-section enrollment breakdowns. In follow-up comments on the same post, the threat actor stated that 'none of the data was exfiltrated' and confirmed already having access to most of approximately eight sister schools that a community member named in the same thread — materially expanding the supply-chain footprint of the shared SIS vendor. The institution name has been withheld in public display, and identifying section, student, and staff names from the screenshots are not reproduced on this site.
Threat actor 'Crypt0nymz', associated with NullSec Philippines and Fawkes Pilipinas, posted on Facebook claiming to have found a security hole on a private school in Rosario, Batangas that exposed student information including names, enrollment details, and section assignments. Screenshots posted with the disclosure show what appears to be administrative access to the school's payments and admissions dashboard, including data on minors as young as nursery level. The school name has been withheld pending independent confirmation.