A public resource tracking cybersecurity incidents affecting Philippine schools. Because student data deserves better protection.
Schools hold some of the most sensitive data imaginable — children's personal information, family details, medical records. Yet most Philippine schools lack the resources and awareness to protect this data. This tracker exists to raise awareness and drive change.
Most schools don't know breaches are happening in Philippine education. Visibility is the first step to action.
By tracking incidents, we identify common attack vectors and vulnerabilities so schools can prioritize defenses.
Every breach listed here includes lessons learned. We want schools to learn from others' mistakes, not their own.
Free tools and educational resources to assess your school's security posture and build a culture of data protection.
On July 14, 2026, the Facebook account 'Nullsec Philippines,' signed by the persona 'Nostra,' publicly addressed a private university in Metro Manila's official Facebook page, stating the group was 'not getting involved anymore' but asking the institution to fix its website. Two attached screenshots showed a publicly reachable phpinfo() diagnostic page and the raw, unexecuted source code of a third-party database-administration script, which exposed the script's access password and the site's database credentials in cleartext. No data extraction, defacement, or unauthorized access was claimed. The institution has not issued a public statement, and this entry is recorded as 'unconfirmed' on the basis of a single threat actor's post.
On May 3, 2026, IBA College of Mindanao Inc. was publicly named in two threat-actor Facebook posts (Nullsec Philippines and the affiliated 4b1smo account) claiming access to 500+ student records, with screenshot evidence and a downloadable-file link. The institution responded publicly via its BSIT department's official Facebook page with a statement confirming a security breach of its website but specifically denying a deeper compromise: only the website administrator account was affected, the LMS server is on separate infrastructure and was not accessed, and the institution states the data being claimed by external parties is not from its system. The school's denial and the threat actor's claim are presented side-by-side on this entry; both positions are documented and neither is endorsed by SchoolBreach.org pending independent forensic review or NPC findings.
On May 1, 2026, the threat-actor account 'Nullsec Philippines' posted on Facebook addressing a state university in Nueva Vizcaya, attaching a screenshot of a logged-in session on the institution's College Admission Test (CAT) applicant portal. The screenshot shows a single applicant's profile — including the applicant's photograph, reference ID area, profile-completion status, and exam venue/date/time assignments — published publicly with mocking commentary. Only single-account access is demonstrated; broader administrative compromise has not been shown. The institution name has been withheld in public display pending independent confirmation, and the affected applicant's identifying photograph is not reproduced on this site.
A threat actor group using the name "Philippine CyberMafia," signed by an individual using the handle "nightfury," claimed on Facebook to have exploited a cross-site scripting (XSS) vulnerability on a subdomain of a private university in Bicol Region. A screenshot shows a JavaScript dialog executing on the institution's maritime-education subdomain with the message "greetings from pcm hehe ~nightfury was here." The actor's accompanying caption explicitly calls out the institution's failure to sanitize inputs. No data exfiltration has been claimed or demonstrated, and the institution has not issued a public statement.
Nullsec Philippines defaced the website of Assumption College of Davao (www.acd.edu.ph), replacing the homepage with their logo and the message 'HACKED BY NULLSEC PHILIPPINES'. The school's Information and Communications Technology Center (ICTC) issued an official advisory confirming the defacement and stating that the issue was limited to the website layer, with no evidence of any data breach involving learner/student or personnel information.
Storm Breaker Security PH claimed on Facebook to have breached the WordPress website of a public senior high school in NCR. The group posted a defacement page along with what appears to be exposed WordPress API schema data.
Storm Breaker Security PH claimed on Facebook to have conducted a DDoS attack against depedmalaboncity.ph, taking the DepEd Malabon City division website offline. Global uptime checks confirmed the site was unreachable from all monitored locations.
A hacker using the handle 'AR_404' breached the Samar State University website (ssu.edu.ph/AR.php) during the June 2020 wave of Philippine school cyberattacks.
The Pinoy Grayhats breached the Angeles University Foundation website (auf.edu.ph) during the June 2020 wave of Philippine school cyberattacks.
The Pinoy Grayhats breached the TIP Career Center portal (careercenter.tip.edu.ph) during the June 2020 wave of school cyberattacks.