SchoolBreach.org
BreachesTrendsToolsLearnAbout
Free Security Check
Security Check
SchoolBreach.org

A public resource tracking data breaches in Philippine schools. Helping administrators protect student data through awareness, education, and free security tools.

© 2026 SchoolBreach.org · A community service by OceanEd

Navigate

  • Breaches
  • Trends
  • Tools
  • Learn
  • Methodology

Company

  • About
  • Privacy Policy
  • Terms of Service
  • Contact Us

Disclaimer: This tracker is maintained for educational and awareness purposes. Incidents are documented using threat intelligence monitoring, Philippine media reports, NPC filings, and responsible disclosures. Social media platforms are monitored for leads and are corroborated before publication or naming — never through active scanning or exploitation. Severity ratings and summaries are prepared with AI assistance and reviewed editorially. Full methodology →

Philippine School Data Breach Tracker

A public resource tracking cybersecurity incidents affecting Philippine schools. Because student data deserves better protection.

Free Security ToolsLearn & Guides
90
Incidents Tracked
19.2M+
Records Affected
21
Critical Severity
10
Unresolved
1
Days Since Last Incident

Why Track School Breaches?

Schools hold some of the most sensitive data imaginable — children's personal information, family details, medical records. Yet most Philippine schools lack the resources and awareness to protect this data. This tracker exists to raise awareness and drive change.

Raise Awareness

Most schools don't know breaches are happening in Philippine education. Visibility is the first step to action.

Document Patterns

By tracking incidents, we identify common attack vectors and vulnerabilities so schools can prioritize defenses.

Drive Better Security

Every breach listed here includes lessons learned. We want schools to learn from others' mistakes, not their own.

Protect Your School

Free tools and educational resources to assess your school's security posture and build a culture of data protection.

Free Security ToolsGuides & Resources

30 of 90 incidents

Showing 10 of 30
mediumunconfirmedMisconfiguration

A private university in Metro Manila

On July 14, 2026, the Facebook account 'Nullsec Philippines,' signed by the persona 'Nostra,' publicly addressed a private university in Metro Manila's official Facebook page, stating the group was 'not getting involved anymore' but asking the institution to fix its website. Two attached screenshots showed a publicly reachable phpinfo() diagnostic page and the raw, unexecuted source code of a third-party database-administration script, which exposed the script's access password and the site's database credentials in cleartext. No data extraction, defacement, or unauthorized access was claimed. The institution has not issued a public statement, and this entry is recorded as 'unconfirmed' on the basis of a single threat actor's post.

Jul 14, 2026None claimed; the post is a public vulnerability warning rather than a data-exfiltration or breach claim records
mediumconfirmedData Exposure

IBA College of Mindanao Inc.

On May 3, 2026, IBA College of Mindanao Inc. was publicly named in two threat-actor Facebook posts (Nullsec Philippines and the affiliated 4b1smo account) claiming access to 500+ student records, with screenshot evidence and a downloadable-file link. The institution responded publicly via its BSIT department's official Facebook page with a statement confirming a security breach of its website but specifically denying a deeper compromise: only the website administrator account was affected, the LMS server is on separate infrastructure and was not accessed, and the institution states the data being claimed by external parties is not from its system. The school's denial and the threat actor's claim are presented side-by-side on this entry; both positions are documented and neither is endorsed by SchoolBreach.org pending independent forensic review or NPC findings.

May 3, 2026Valencia City, BukidnonDisputed: institution states no sensitive information leaked; threat actor claims 500+ student records records
mediuminvestigatingUnauthorized Access

A state university in Nueva Vizcaya

On May 1, 2026, the threat-actor account 'Nullsec Philippines' posted on Facebook addressing a state university in Nueva Vizcaya, attaching a screenshot of a logged-in session on the institution's College Admission Test (CAT) applicant portal. The screenshot shows a single applicant's profile — including the applicant's photograph, reference ID area, profile-completion status, and exam venue/date/time assignments — published publicly with mocking commentary. Only single-account access is demonstrated; broader administrative compromise has not been shown. The institution name has been withheld in public display pending independent confirmation, and the affected applicant's identifying photograph is not reproduced on this site.

May 1, 2026At least 1 applicant account (broader scope unconfirmed) records
mediumunconfirmedWebsite Defacement

A private university in Bicol Region

A threat actor group using the name "Philippine CyberMafia," signed by an individual using the handle "nightfury," claimed on Facebook to have exploited a cross-site scripting (XSS) vulnerability on a subdomain of a private university in Bicol Region. A screenshot shows a JavaScript dialog executing on the institution's maritime-education subdomain with the message "greetings from pcm hehe ~nightfury was here." The actor's accompanying caption explicitly calls out the institution's failure to sanitize inputs. No data exfiltration has been claimed or demonstrated, and the institution has not issued a public statement.

Apr 23, 2026None demonstrated records
mediumresolvedWebsite Defacement

Assumption College of Davao

Nullsec Philippines defaced the website of Assumption College of Davao (www.acd.edu.ph), replacing the homepage with their logo and the message 'HACKED BY NULLSEC PHILIPPINES'. The school's Information and Communications Technology Center (ICTC) issued an official advisory confirming the defacement and stating that the issue was limited to the website layer, with no evidence of any data breach involving learner/student or personnel information.

Apr 2, 2026Davao CityNone records
mediumresolvedWebsite Defacement

A public senior high school in Malabon City

Storm Breaker Security PH claimed on Facebook to have breached the WordPress website of a public senior high school in NCR. The group posted a defacement page along with what appears to be exposed WordPress API schema data.

Mar 14, 2026Unknown records
mediumresolvedUnauthorized Access

DepEd Division of Malabon City

Storm Breaker Security PH claimed on Facebook to have conducted a DDoS attack against depedmalaboncity.ph, taking the DepEd Malabon City division website offline. Global uptime checks confirmed the site was unreachable from all monitored locations.

Feb 15, 2026Malabon CityNone records
mediumresolvedUnauthorized Access

Samar State University (SSU)

A hacker using the handle 'AR_404' breached the Samar State University website (ssu.edu.ph/AR.php) during the June 2020 wave of Philippine school cyberattacks.

Jun 28, 2020Catbalogan, SamarUnknown records
mediumresolvedUnauthorized Access

Angeles University Foundation (AUF)

The Pinoy Grayhats breached the Angeles University Foundation website (auf.edu.ph) during the June 2020 wave of Philippine school cyberattacks.

Jun 19, 2020Angeles, PampangaUnknown records
mediumresolvedUnauthorized Access

Technological Institute of the Philippines (TIP) Career Center

The Pinoy Grayhats breached the TIP Career Center portal (careercenter.tip.edu.ph) during the June 2020 wave of school cyberattacks.

Jun 19, 2020ManilaUnknown records