SchoolBreach.org
BreachesTrendsToolsLearnAbout
Free Security Check
Security Check
SchoolBreach.org

A public resource tracking data breaches in Philippine schools. Helping administrators protect student data through awareness, education, and free security tools.

© 2026 SchoolBreach.org · A community service by OceanEd

Navigate

  • Breaches
  • Trends
  • Tools
  • Learn
  • Methodology

Company

  • About
  • Privacy Policy
  • Terms of Service
  • Contact Us

Disclaimer: This tracker is maintained for educational and awareness purposes. Incidents are documented using threat intelligence monitoring, Philippine media reports, NPC filings, and responsible disclosures. Social media platforms are monitored for leads and are corroborated before publication or naming — never through active scanning or exploitation. Severity ratings and summaries are prepared with AI assistance and reviewed editorially. Full methodology →

Philippine School Data Breach Tracker

A public resource tracking cybersecurity incidents affecting Philippine schools. Because student data deserves better protection.

Free Security ToolsLearn & Guides
90
Incidents Tracked
19.2M+
Records Affected
21
Critical Severity
10
Unresolved
1
Days Since Last Incident

Why Track School Breaches?

Schools hold some of the most sensitive data imaginable — children's personal information, family details, medical records. Yet most Philippine schools lack the resources and awareness to protect this data. This tracker exists to raise awareness and drive change.

Raise Awareness

Most schools don't know breaches are happening in Philippine education. Visibility is the first step to action.

Document Patterns

By tracking incidents, we identify common attack vectors and vulnerabilities so schools can prioritize defenses.

Drive Better Security

Every breach listed here includes lessons learned. We want schools to learn from others' mistakes, not their own.

Protect Your School

Free tools and educational resources to assess your school's security posture and build a culture of data protection.

Free Security ToolsGuides & Resources

21 of 90 incidents

Showing 10 of 21
highconfirmedData Exposure

Technological University of the Philippines - Manila

On July 4 and July 5, 2026, the Facebook account 'Nullsec Philippines' addressed the Technological University of the Philippines - Manila (TUP Manila) admissions office directly, first sharing a screenshot of dozens of applicant photographs and then a follow-up post sharing a password-protected cloud-storage folder said to contain a larger set of the same. On July 9, 2026, TUP Manila's University Student Government (USG) published a public 'Update and Statement' acknowledging reports received on July 6 of 'alleged unauthorized access' to Applicant ERS (admissions) information, and stating that the University Information Technology Center (UITC) — TUP's official IT unit — opened an investigation the same day that remains ongoing. The USG statement is a student-government publication rather than a release from TUP's central administration or communications office, but it relays UITC's own acknowledgment that a report was received and is under active investigation, which is sufficient public corroboration under SchoolBreach.org's methodology to de-anonymize this entry and move its status from 'unconfirmed' to 'confirmed.'

Jul 4, 2026Manila, Metro ManilaUndetermined; a partial screenshot showed roughly 90 applicant photographs, and the threat actor's follow-up post claims the shared archive represents only 'half' of the full set held records
highconfirmedData Exposure

Philippine Universities — Canvas LMS Breach

On May 2, 2026, Instructure — the U.S.-based owner of the Canvas LMS — disclosed that the threat-actor group ShinyHunters had compromised its environment and claimed roughly 275 million records as ransomware-style extortion. Canvas is widely deployed across Philippine higher education, so the impact is sector-wide. As of mid-May 2026, at least five universities are publicly tied to the incident: DLSU and Ateneo de Manila confirmed as Instructure-notified affected clients; UST and University of the East issued coordinating advisories; San Beda experienced related Canvas service disruption. Per Instructure's global-scope statement, names, email addresses, student ID numbers, and Canvas platform messages were affected; passwords, dates of birth, government identifiers, and financial information are reported as not involved. Per-institution scope is pending Instructure's clarification.

May 6, 2026NationwideUnknown records
criticalconfirmedDatabase Leak

DepEd Training Platform (training.deped.gov.ph)

On May 3, 2026, the joint Facebook account 'NSP & DNH' (Nullsec Philippines × Deathnote Hackers International) publicly posted a claim of breach against the DepEd training platform at training.deped.gov.ph, accompanied by a CSV file said to contain 999,995 rows of user data with fields including full names, emails, user IDs, and profile links. Cybersecurity research and advocacy organization Deep Web Konek (DWK) independently reviewed the circulated dataset on the same day and reported that the row count aligns with the actor's claim, that the schema is consistent with structured institutional databases, and that sample entries display realistic naming patterns — assessing the dataset as 'likely authentic with strong internal consistency.' SchoolBreach.org's editorial team independently observed that training.deped.gov.ph is no longer reachable, returning a Cloudflare error rather than the usual training-platform interface as of May 3, 2026 — confirming that DepEd's IT operations team has taken the platform offline in response. The combination of independent dataset validation by DWK and the platform being pulled offline supports tracking this entry as confirmed.

May 3, 2026Pasig City999,995 records
mediumconfirmedData Exposure

IBA College of Mindanao Inc.

On May 3, 2026, IBA College of Mindanao Inc. was publicly named in two threat-actor Facebook posts (Nullsec Philippines and the affiliated 4b1smo account) claiming access to 500+ student records, with screenshot evidence and a downloadable-file link. The institution responded publicly via its BSIT department's official Facebook page with a statement confirming a security breach of its website but specifically denying a deeper compromise: only the website administrator account was affected, the LMS server is on separate infrastructure and was not accessed, and the institution states the data being claimed by external parties is not from its system. The school's denial and the threat actor's claim are presented side-by-side on this entry; both positions are documented and neither is endorsed by SchoolBreach.org pending independent forensic review or NPC findings.

May 3, 2026Valencia City, BukidnonDisputed: institution states no sensitive information leaked; threat actor claims 500+ student records records
highconfirmedDatabase Leak

Bangsamoro Ministry of Basic, Higher and Technical Education (MBHTE)

Fawkes Pilipinas, affiliated with Nullsec Philippines, claimed to have breached the Bangsamoro Ministry of Basic, Higher and Technical Education (MBHTE) and posted a 1 MB+ JSON sample of exfiltrated data. The MBHTE website (mbhte.bangsamoro.gov.ph) was subsequently suspended by Bangsamoro Government Web Hosting Services, citing a detected cyber breach.

Mar 31, 2026Cotabato City1 MB+ exposed
criticalconfirmedWebsite Defacement

DepEd Tayo Roxas City

Threat actor 'Ch4nc3ll0rx 1337' defaced the DepEd Tayo Roxas City website (depedroxascity.com), dumped 7GB of web directories and 17MB of compressed databases, and claimed a total of 107 related defacements.

Mar 8, 2026Roxas City7 GB exposed
criticalconfirmedWebsite Defacement

DepEd Tayo Lucena City

Threat actor 'Ch4nc3ll0rx 1337' defaced and leaked data from the DepEd Tayo Lucena City website (depedlucenadms.com), dumping 3,000+ lines of database contents and claiming full server compromise with backdoors deployed.

Mar 4, 2026Lucena City3,000+ lines records
criticalconfirmedDatabase Leak

DepEd Cordillera Administrative Region (CAR)

Quantum Security Group breached DepEd CAR's infrastructure, exfiltrating over 6 million records across 42 databases including 30,000+ teacher personal records with plaintext passwords, and defaced multiple DepEd CAR subdomains.

Nov 19, 2025Baguio City6,000,000+ records
criticalconfirmedDatabase Leak

DepEd Ilocos Norte & Aurora Divisions

Quantum Security Group claimed breaches of DepEd Ilocos Norte (3M+ records across 17 databases and 155 CSV files) and DepEd Aurora (full database backup), exposing sensitive personal information including TIN numbers and PhilHealth IDs.

Nov 1, 2025Ilocos Norte / Aurora3,000,000+ records
criticalconfirmedDatabase Leak

DepEd Division of Laguna

Quantum Security Group leaked 7 million database records from DepEd Division of Laguna, including plaintext passwords, employee details, and multiple internal system databases spanning email, document tracking, and HR systems.

Oct 4, 2025Laguna7,000,000+ records