A public resource tracking cybersecurity incidents affecting Philippine schools. Because student data deserves better protection.
Schools hold some of the most sensitive data imaginable — children's personal information, family details, medical records. Yet most Philippine schools lack the resources and awareness to protect this data. This tracker exists to raise awareness and drive change.
Most schools don't know breaches are happening in Philippine education. Visibility is the first step to action.
By tracking incidents, we identify common attack vectors and vulnerabilities so schools can prioritize defenses.
Every breach listed here includes lessons learned. We want schools to learn from others' mistakes, not their own.
Free tools and educational resources to assess your school's security posture and build a culture of data protection.
Nullsec Philippines defaced the website of Assumption College of Davao (www.acd.edu.ph), replacing the homepage with their logo and the message 'HACKED BY NULLSEC PHILIPPINES'. The school's Information and Communications Technology Center (ICTC) issued an official advisory confirming the defacement and stating that the issue was limited to the website layer, with no evidence of any data breach involving learner/student or personnel information.
Fawkes Pilipinas, affiliated with Nullsec Philippines, claimed to have defaced the A private university in Cebu City Publishing House subdomain. The group posted a defacement page at A private university in Cebu City and stated they identified vulnerabilities in the subdomain but claimed no data was harmed.
Threat actor group Fawkes Pilipinas, affiliated with Nullsec Philippines, claimed to have exfiltrated data from a private college in Bulacan. The post, framed around allegations of discrimination and bullying, included a download link to a 4MB+ CSV file purportedly containing college data. The school has not confirmed or denied the breach.
Nullsec Philippines breached two private colleges in San Fernando, La Union by compromising their shared hosting account. Beyond defacing both websites, the attackers exfiltrated the full school database — over 16 CSV tables containing student payments, enrollment records, tuition fees, user accounts with plaintext passwords, and teacher evaluations.
Storm Breaker Security PH claimed on Facebook to have breached the WordPress website of a public senior high school in NCR. The group posted a defacement page along with what appears to be exposed WordPress API schema data.
Threat actor '4rch4n63l' from NullsecPhilippines exfiltrated 685,318 records from a public college in Batangas City across two files (profile.json and users.json). Student account passwords were stored and exposed in plain text. The school name has been withheld as the incident was sourced solely from the threat actor's post with no independent confirmation.
Threat actor 'Crypt0nymz' from NullSec Philippines claimed to have bypassed A private school in Tagum City's WAF and accessed the 'smct' database, exposing a grades table with student numbers, names, and grades. The attacker cited outdated web security and a debugger mode left enabled.
Storm Breaker Security PH claimed on Facebook to have conducted a DDoS attack against depedmalaboncity.ph, taking the DepEd Malabon City division website offline. Global uptime checks confirmed the site was unreachable from all monitored locations.
Storm Breaker Security PH claimed on Facebook to have leaked the database of a private college in Cavite via SQL injection. The post included screenshots of database table structures exposing faculty, facility, organization, and building data, along with a Mediafire link to the full database dump.
A hacker using the alias 'MaxxX' advertised a dataset containing over 175,000 lines of student data from USeP's Student Records Information System, including IDs, names, emails, and academic records.