A public resource tracking cybersecurity incidents affecting Philippine schools. Because student data deserves better protection.
Schools hold some of the most sensitive data imaginable — children's personal information, family details, medical records. Yet most Philippine schools lack the resources and awareness to protect this data. This tracker exists to raise awareness and drive change.
Most schools don't know breaches are happening in Philippine education. Visibility is the first step to action.
By tracking incidents, we identify common attack vectors and vulnerabilities so schools can prioritize defenses.
Every breach listed here includes lessons learned. We want schools to learn from others' mistakes, not their own.
Free tools and educational resources to assess your school's security posture and build a culture of data protection.
On July 4 and July 5, 2026, the Facebook account 'Nullsec Philippines' addressed the Technological University of the Philippines - Manila (TUP Manila) admissions office directly, first sharing a screenshot of dozens of applicant photographs and then a follow-up post sharing a password-protected cloud-storage folder said to contain a larger set of the same. On July 9, 2026, TUP Manila's University Student Government (USG) published a public 'Update and Statement' acknowledging reports received on July 6 of 'alleged unauthorized access' to Applicant ERS (admissions) information, and stating that the University Information Technology Center (UITC) — TUP's official IT unit — opened an investigation the same day that remains ongoing. The USG statement is a student-government publication rather than a release from TUP's central administration or communications office, but it relays UITC's own acknowledgment that a report was received and is under active investigation, which is sufficient public corroboration under SchoolBreach.org's methodology to de-anonymize this entry and move its status from 'unconfirmed' to 'confirmed.'
On May 2, 2026, Instructure — the U.S.-based owner of the Canvas LMS — disclosed that the threat-actor group ShinyHunters had compromised its environment and claimed roughly 275 million records as ransomware-style extortion. Canvas is widely deployed across Philippine higher education, so the impact is sector-wide. As of mid-May 2026, at least five universities are publicly tied to the incident: DLSU and Ateneo de Manila confirmed as Instructure-notified affected clients; UST and University of the East issued coordinating advisories; San Beda experienced related Canvas service disruption. Per Instructure's global-scope statement, names, email addresses, student ID numbers, and Canvas platform messages were affected; passwords, dates of birth, government identifiers, and financial information are reported as not involved. Per-institution scope is pending Instructure's clarification.
On May 3, 2026, the joint Facebook account 'NSP & DNH' (Nullsec Philippines × Deathnote Hackers International) publicly posted a claim of breach against the DepEd training platform at training.deped.gov.ph, accompanied by a CSV file said to contain 999,995 rows of user data with fields including full names, emails, user IDs, and profile links. Cybersecurity research and advocacy organization Deep Web Konek (DWK) independently reviewed the circulated dataset on the same day and reported that the row count aligns with the actor's claim, that the schema is consistent with structured institutional databases, and that sample entries display realistic naming patterns — assessing the dataset as 'likely authentic with strong internal consistency.' SchoolBreach.org's editorial team independently observed that training.deped.gov.ph is no longer reachable, returning a Cloudflare error rather than the usual training-platform interface as of May 3, 2026 — confirming that DepEd's IT operations team has taken the platform offline in response. The combination of independent dataset validation by DWK and the platform being pulled offline supports tracking this entry as confirmed.
On May 3, 2026, IBA College of Mindanao Inc. was publicly named in two threat-actor Facebook posts (Nullsec Philippines and the affiliated 4b1smo account) claiming access to 500+ student records, with screenshot evidence and a downloadable-file link. The institution responded publicly via its BSIT department's official Facebook page with a statement confirming a security breach of its website but specifically denying a deeper compromise: only the website administrator account was affected, the LMS server is on separate infrastructure and was not accessed, and the institution states the data being claimed by external parties is not from its system. The school's denial and the threat actor's claim are presented side-by-side on this entry; both positions are documented and neither is endorsed by SchoolBreach.org pending independent forensic review or NPC findings.
Fawkes Pilipinas, affiliated with Nullsec Philippines, claimed to have breached the Bangsamoro Ministry of Basic, Higher and Technical Education (MBHTE) and posted a 1 MB+ JSON sample of exfiltrated data. The MBHTE website (mbhte.bangsamoro.gov.ph) was subsequently suspended by Bangsamoro Government Web Hosting Services, citing a detected cyber breach.
Threat actor 'Ch4nc3ll0rx 1337' defaced the DepEd Tayo Roxas City website (depedroxascity.com), dumped 7GB of web directories and 17MB of compressed databases, and claimed a total of 107 related defacements.
Threat actor 'Ch4nc3ll0rx 1337' defaced and leaked data from the DepEd Tayo Lucena City website (depedlucenadms.com), dumping 3,000+ lines of database contents and claiming full server compromise with backdoors deployed.
Quantum Security Group breached DepEd CAR's infrastructure, exfiltrating over 6 million records across 42 databases including 30,000+ teacher personal records with plaintext passwords, and defaced multiple DepEd CAR subdomains.
Quantum Security Group claimed breaches of DepEd Ilocos Norte (3M+ records across 17 databases and 155 CSV files) and DepEd Aurora (full database backup), exposing sensitive personal information including TIN numbers and PhilHealth IDs.
Quantum Security Group leaked 7 million database records from DepEd Division of Laguna, including plaintext passwords, employee details, and multiple internal system databases spanning email, document tracking, and HR systems.