SchoolBreach.org
BreachesTrendsToolsLearnAbout
Free Security Check
Security Check
SchoolBreach.org

A public resource tracking data breaches in Philippine schools. Helping administrators protect student data through awareness, education, and free security tools.

© 2026 SchoolBreach.org · A community service by OceanEd

Navigate

  • Breaches
  • Trends
  • Tools
  • Learn
  • Methodology

Company

  • About
  • Privacy Policy
  • Terms of Service
  • Contact Us

Disclaimer: This tracker is maintained for educational and awareness purposes. Incidents are documented using threat intelligence monitoring, Philippine media reports, NPC filings, and responsible disclosures. Social media platforms are monitored for leads and are corroborated before publication or naming — never through active scanning or exploitation. Severity ratings and summaries are prepared with AI assistance and reviewed editorially. Full methodology →

Philippine School Data Breach Tracker

A public resource tracking cybersecurity incidents affecting Philippine schools. Because student data deserves better protection.

Free Security ToolsLearn & Guides
90
Incidents Tracked
19.2M+
Records Affected
21
Critical Severity
10
Unresolved
1
Days Since Last Incident

Why Track School Breaches?

Schools hold some of the most sensitive data imaginable — children's personal information, family details, medical records. Yet most Philippine schools lack the resources and awareness to protect this data. This tracker exists to raise awareness and drive change.

Raise Awareness

Most schools don't know breaches are happening in Philippine education. Visibility is the first step to action.

Document Patterns

By tracking incidents, we identify common attack vectors and vulnerabilities so schools can prioritize defenses.

Drive Better Security

Every breach listed here includes lessons learned. We want schools to learn from others' mistakes, not their own.

Protect Your School

Free tools and educational resources to assess your school's security posture and build a culture of data protection.

Free Security ToolsGuides & Resources

10 of 90 incidents

criticalinvestigatingDatabase Leak

A private medical college in Cebu City

On May 31, 2026, a Facebook post by 'Quantum Security Group' (QSG) — signed by the handle 'ZeuS' with the Telegram contact '@XantyEvander' and a Blogspot archive at quantum-sec-group.blogspot.com — addressed a private medical college in Cebu City. The post claimed and provided index-page URLs for the simultaneous defacement of 27 distinct subdomains on the institution's primary domain, including subdomains corresponding to canteen and food-service microsites, three named development environments (dev/dev2/dev3), file storage, library systems, the student information system, three visa-processing subdomains, a campus-perks system, an iCash payment subsystem, and — most operationally significant — a publicly-accessible phpMyAdmin database-administration interface. No data exfiltration was claimed at the time. The defacement was simultaneously registered to a public deface-tracker mirror under the actor's handle. In a follow-up post under the same banner (June 2026, signed collectively as 'QSG Team'), QSG escalated the claim — stating it had exfiltrated the institution's data records and advertising a six-part multi-volume 7z archive set as publicly downloadable via a base64-encoded file-sharing link. On the strength of that exfiltration claim and its accompanying multi-volume archive artifacts, this entry's severity has been raised to critical. The institution name, the specific subdomain URLs, the archive filenames, and the download link are not reproduced on this site. The institution has not issued a public statement.

Jun 24, 2026Unspecified (bulk data exfiltration claimed; volume not disclosed) records
highinvestigatingUnauthorized Access

A state university in Western Visayas

On May 20, 2026, the Facebook account '4b1smo' (a Nullsec Philippines-affiliated account) addressed a state university in Western Visayas with the one-word framing 'hmmm,' tagging the institution's official Public Information Office page. The post included a single composite screenshot of the institution's homepage with a Notepad window overlaid, captioned 'TANGINANG YAN HAHAHAH 4B1SMO' and headed 'DATABASE'. The Notepad listed four grades-related database names alongside the standard MySQL information_schema system database — a pattern consistent with the output of either a `SHOW DATABASES` command or a `SELECT schema_name FROM information_schema.schemata` query, both of which require either authenticated database access or an SQL-injection foothold to obtain from outside. No sample rows, no record count, no specific URL, and no exfiltrated file were attached. The institution name has been withheld in public display pending corroboration.

May 20, 2026Unknown (databases enumerated; no record count claimed) records
criticalinvestigatingDatabase Leak

A state university in Mindanao

On May 10, 2026, a state university in Mindanao was publicly named in a Facebook post by Nullsec Philippines (signed by 'Yasuo' and '0xTerror') claiming a comprehensive credentialed compromise. The actor claims to have obtained LDAP administrative credentials, database usernames and passwords, internal IP addresses and infrastructure details, configuration and authentication information, an estimated 24,942 student records, and — most operationally significant — the SMTP master key for the institution's no-reply email account. Specific credentials and identifying URLs are not reproduced on this site. The institution has not yet issued a public statement; this entry is tracked as 'investigating' on the basis of the threat-actor claim alone, with severity recorded as 'critical' due to the combination of bulk student-record exposure, claimed admin-tier credentials, and a working email-server master key that — if authentic — would enable institution-wide phishing impersonation against the entire affected student body.

May 10, 2026≈24,942 student records claimed by the threat actor; LDAP and database credentials and an SMTP master key separately claimed records
lowinvestigatingWebsite Defacement

A foundation college in Mindanao

On May 3, 2026, the Facebook account '4b1smo' (a newly-promoted Nullsec Philippines-affiliated account) posted a one-line claim addressed to a foundation college in Mindanao, framed as 'time to fix [institution] - Main Page weak security lolx' and accompanied by an archive.md snapshot URL as evidence. The post does not claim data exfiltration, does not name a vulnerability class, and does not describe what 'weak security' refers to beyond the linked screenshot. Nullsec Philippines re-shared the post on its main page within minutes. The institution has not issued a public statement. The institution name, the institution's province, and the archive snapshot URL have been withheld in public display pending corroboration.

May 3, 2026Not claimed; threat actor described 'weak security' on the institution's main page records
highinvestigatingWebsite Defacement

A state university in MIMAROPA

On May 2, 2026, the Facebook account 'Nullsec Philippines' publicly posted a defacement claim against a state university in the MIMAROPA region, listing several of the institution's internal management information system (MIS) subdomains — covering its assets, records, and library functions — as having received `nullsec.html` marker pages. The post also bundled roughly twenty additional defaced URLs on unrelated infrastructure, framing the operation as a coordinated mass-mirror. Multiple screenshots were attached, including images of the defacement page, what appear to be administrative views of an internal MIS dashboard, and an apparent employee identity record — evidence that, if authentic, suggests the actor's access went beyond simple web defacement. The post was signed 'Yasuo' and ended with 'mirror? done~'. The institution has not issued a public statement and the named subdomains have not been independently re-checked at the time of this entry. The university name, its province, the literal subdomain prefixes, and any individual identities visible in the attached screenshots have been withheld in public display pending corroboration.

May 2, 2026Not claimed numerically; attached screenshots suggest admin-tier visibility into the institution's MIS rather than defacement alone records
lowinvestigatingWebsite Defacement

A technical institute in Laguna

On May 2, 2026, the Facebook account 'Nullsec Philippines' publicly posted a one-line claim addressed to a technical institute in Laguna and linked to a defacement page hosted off-domain on a third-party Philippine content platform — not on the institution's own infrastructure. The post also linked to a public archive snapshot of that page. The post is unusual within the Nullsec batch: no school-domain subdomain is named, no data is claimed, and no specific access vector is described — the entire public footprint of the claim is a single off-domain HTML file that mentions the school. The relationship between the institution and the third-party platform has not been independently verified, and the school has not issued a public statement. The institution name, the institution's city, and the specific URLs of both the defacement page and its archive snapshot have been withheld in public display pending corroboration, because each of those URLs would otherwise reverse-identify the school.

May 2, 2026None claimed by the threat actor; relationship to the named institution not independently verified records
mediuminvestigatingUnauthorized Access

A state university in Nueva Vizcaya

On May 1, 2026, the threat-actor account 'Nullsec Philippines' posted on Facebook addressing a state university in Nueva Vizcaya, attaching a screenshot of a logged-in session on the institution's College Admission Test (CAT) applicant portal. The screenshot shows a single applicant's profile — including the applicant's photograph, reference ID area, profile-completion status, and exam venue/date/time assignments — published publicly with mocking commentary. Only single-account access is demonstrated; broader administrative compromise has not been shown. The institution name has been withheld in public display pending independent confirmation, and the affected applicant's identifying photograph is not reproduced on this site.

May 1, 2026At least 1 applicant account (broader scope unconfirmed) records
highinvestigatingData Exposure

A Christian school in Imus City, Cavite

On May 1, 2026, the Facebook account 'Nullsec Philippines' publicly posted addressing a private K-12 institution, attaching screenshots of what appears to be a logged-in administrative session on the school's student information system. The screenshots include a per-student fee and assessment view (with full student name, gender, year level, and a multi-year assessment history), a coordinator/subject-teacher grade-posting roster, and aggregate admission and assessment dashboards covering both new and returning students with gender-broken-out totals. The exposure spans data on minors. The institution name has been withheld in public display, and identifying section, student, and staff names from the screenshots are not reproduced on this site.

May 1, 2026Estimated 800-900 current-cycle students across all year levels, combining new applicants and returning students (multi-year history reachable via the same view) records
highinvestigatingData Exposure

A Catholic K-12 institution in San Juan, Batangas

On May 1, 2026, the Facebook account 'Nullsec Philippines' publicly posted addressing a Catholic K-12 institution, attaching screenshots of an Admin Dashboard branded with the institution's name. The post is notable because the threat actor explicitly stated that the institution's website developer is the same one who built another school previously claimed in this batch — making the shared-vendor / supply-chain pattern an actor-confirmed claim rather than an inference. The screenshots show admin-level access to admission and assessment dashboards, a multi-year per-student payments view including nursery-age children, and per-level / per-section enrollment breakdowns. In follow-up comments on the same post, the threat actor stated that 'none of the data was exfiltrated' and confirmed already having access to most of approximately eight sister schools that a community member named in the same thread — materially expanding the supply-chain footprint of the shared SIS vendor. The institution name has been withheld in public display, and identifying section, student, and staff names from the screenshots are not reproduced on this site.

May 1, 2026Estimated 900-1,000 current-cycle students; multi-year records spanning at least four academic years reachable via the same view records
highinvestigatingData Exposure

A private school in Rosario, Batangas

Threat actor 'Crypt0nymz', associated with NullSec Philippines and Fawkes Pilipinas, posted on Facebook claiming to have found a security hole on a private school in Rosario, Batangas that exposed student information including names, enrollment details, and section assignments. Screenshots posted with the disclosure show what appears to be administrative access to the school's payments and admissions dashboard, including data on minors as young as nursery level. The school name has been withheld pending independent confirmation.

Apr 28, 2026Estimated 800-1,000 current-cycle students (multi-year history reachable via the same view) records