A public resource tracking cybersecurity incidents affecting Philippine schools. Because student data deserves better protection.
Schools hold some of the most sensitive data imaginable — children's personal information, family details, medical records. Yet most Philippine schools lack the resources and awareness to protect this data. This tracker exists to raise awareness and drive change.
Most schools don't know breaches are happening in Philippine education. Visibility is the first step to action.
By tracking incidents, we identify common attack vectors and vulnerabilities so schools can prioritize defenses.
Every breach listed here includes lessons learned. We want schools to learn from others' mistakes, not their own.
Free tools and educational resources to assess your school's security posture and build a culture of data protection.
On May 31, 2026, a Facebook post by 'Quantum Security Group' (QSG) — signed by the handle 'ZeuS' with the Telegram contact '@XantyEvander' and a Blogspot archive at quantum-sec-group.blogspot.com — addressed a private medical college in Cebu City. The post claimed and provided index-page URLs for the simultaneous defacement of 27 distinct subdomains on the institution's primary domain, including subdomains corresponding to canteen and food-service microsites, three named development environments (dev/dev2/dev3), file storage, library systems, the student information system, three visa-processing subdomains, a campus-perks system, an iCash payment subsystem, and — most operationally significant — a publicly-accessible phpMyAdmin database-administration interface. No data exfiltration was claimed at the time. The defacement was simultaneously registered to a public deface-tracker mirror under the actor's handle. In a follow-up post under the same banner (June 2026, signed collectively as 'QSG Team'), QSG escalated the claim — stating it had exfiltrated the institution's data records and advertising a six-part multi-volume 7z archive set as publicly downloadable via a base64-encoded file-sharing link. On the strength of that exfiltration claim and its accompanying multi-volume archive artifacts, this entry's severity has been raised to critical. The institution name, the specific subdomain URLs, the archive filenames, and the download link are not reproduced on this site. The institution has not issued a public statement.
On May 20, 2026, the Facebook account '4b1smo' (a Nullsec Philippines-affiliated account) addressed a state university in Western Visayas with the one-word framing 'hmmm,' tagging the institution's official Public Information Office page. The post included a single composite screenshot of the institution's homepage with a Notepad window overlaid, captioned 'TANGINANG YAN HAHAHAH 4B1SMO' and headed 'DATABASE'. The Notepad listed four grades-related database names alongside the standard MySQL information_schema system database — a pattern consistent with the output of either a `SHOW DATABASES` command or a `SELECT schema_name FROM information_schema.schemata` query, both of which require either authenticated database access or an SQL-injection foothold to obtain from outside. No sample rows, no record count, no specific URL, and no exfiltrated file were attached. The institution name has been withheld in public display pending corroboration.
On May 10, 2026, a state university in Mindanao was publicly named in a Facebook post by Nullsec Philippines (signed by 'Yasuo' and '0xTerror') claiming a comprehensive credentialed compromise. The actor claims to have obtained LDAP administrative credentials, database usernames and passwords, internal IP addresses and infrastructure details, configuration and authentication information, an estimated 24,942 student records, and — most operationally significant — the SMTP master key for the institution's no-reply email account. Specific credentials and identifying URLs are not reproduced on this site. The institution has not yet issued a public statement; this entry is tracked as 'investigating' on the basis of the threat-actor claim alone, with severity recorded as 'critical' due to the combination of bulk student-record exposure, claimed admin-tier credentials, and a working email-server master key that — if authentic — would enable institution-wide phishing impersonation against the entire affected student body.
On May 3, 2026, the Facebook account '4b1smo' (a newly-promoted Nullsec Philippines-affiliated account) posted a one-line claim addressed to a foundation college in Mindanao, framed as 'time to fix [institution] - Main Page weak security lolx' and accompanied by an archive.md snapshot URL as evidence. The post does not claim data exfiltration, does not name a vulnerability class, and does not describe what 'weak security' refers to beyond the linked screenshot. Nullsec Philippines re-shared the post on its main page within minutes. The institution has not issued a public statement. The institution name, the institution's province, and the archive snapshot URL have been withheld in public display pending corroboration.
On May 2, 2026, the Facebook account 'Nullsec Philippines' publicly posted a defacement claim against a state university in the MIMAROPA region, listing several of the institution's internal management information system (MIS) subdomains — covering its assets, records, and library functions — as having received `nullsec.html` marker pages. The post also bundled roughly twenty additional defaced URLs on unrelated infrastructure, framing the operation as a coordinated mass-mirror. Multiple screenshots were attached, including images of the defacement page, what appear to be administrative views of an internal MIS dashboard, and an apparent employee identity record — evidence that, if authentic, suggests the actor's access went beyond simple web defacement. The post was signed 'Yasuo' and ended with 'mirror? done~'. The institution has not issued a public statement and the named subdomains have not been independently re-checked at the time of this entry. The university name, its province, the literal subdomain prefixes, and any individual identities visible in the attached screenshots have been withheld in public display pending corroboration.
On May 2, 2026, the Facebook account 'Nullsec Philippines' publicly posted a one-line claim addressed to a technical institute in Laguna and linked to a defacement page hosted off-domain on a third-party Philippine content platform — not on the institution's own infrastructure. The post also linked to a public archive snapshot of that page. The post is unusual within the Nullsec batch: no school-domain subdomain is named, no data is claimed, and no specific access vector is described — the entire public footprint of the claim is a single off-domain HTML file that mentions the school. The relationship between the institution and the third-party platform has not been independently verified, and the school has not issued a public statement. The institution name, the institution's city, and the specific URLs of both the defacement page and its archive snapshot have been withheld in public display pending corroboration, because each of those URLs would otherwise reverse-identify the school.
On May 1, 2026, the threat-actor account 'Nullsec Philippines' posted on Facebook addressing a state university in Nueva Vizcaya, attaching a screenshot of a logged-in session on the institution's College Admission Test (CAT) applicant portal. The screenshot shows a single applicant's profile — including the applicant's photograph, reference ID area, profile-completion status, and exam venue/date/time assignments — published publicly with mocking commentary. Only single-account access is demonstrated; broader administrative compromise has not been shown. The institution name has been withheld in public display pending independent confirmation, and the affected applicant's identifying photograph is not reproduced on this site.
On May 1, 2026, the Facebook account 'Nullsec Philippines' publicly posted addressing a private K-12 institution, attaching screenshots of what appears to be a logged-in administrative session on the school's student information system. The screenshots include a per-student fee and assessment view (with full student name, gender, year level, and a multi-year assessment history), a coordinator/subject-teacher grade-posting roster, and aggregate admission and assessment dashboards covering both new and returning students with gender-broken-out totals. The exposure spans data on minors. The institution name has been withheld in public display, and identifying section, student, and staff names from the screenshots are not reproduced on this site.
On May 1, 2026, the Facebook account 'Nullsec Philippines' publicly posted addressing a Catholic K-12 institution, attaching screenshots of an Admin Dashboard branded with the institution's name. The post is notable because the threat actor explicitly stated that the institution's website developer is the same one who built another school previously claimed in this batch — making the shared-vendor / supply-chain pattern an actor-confirmed claim rather than an inference. The screenshots show admin-level access to admission and assessment dashboards, a multi-year per-student payments view including nursery-age children, and per-level / per-section enrollment breakdowns. In follow-up comments on the same post, the threat actor stated that 'none of the data was exfiltrated' and confirmed already having access to most of approximately eight sister schools that a community member named in the same thread — materially expanding the supply-chain footprint of the shared SIS vendor. The institution name has been withheld in public display, and identifying section, student, and staff names from the screenshots are not reproduced on this site.
Threat actor 'Crypt0nymz', associated with NullSec Philippines and Fawkes Pilipinas, posted on Facebook claiming to have found a security hole on a private school in Rosario, Batangas that exposed student information including names, enrollment details, and section assignments. Screenshots posted with the disclosure show what appears to be administrative access to the school's payments and admissions dashboard, including data on minors as young as nursery level. The school name has been withheld pending independent confirmation.