A public resource tracking cybersecurity incidents affecting Philippine schools. Because student data deserves better protection.
Schools hold some of the most sensitive data imaginable — children's personal information, family details, medical records. Yet most Philippine schools lack the resources and awareness to protect this data. This tracker exists to raise awareness and drive change.
Most schools don't know breaches are happening in Philippine education. Visibility is the first step to action.
By tracking incidents, we identify common attack vectors and vulnerabilities so schools can prioritize defenses.
Every breach listed here includes lessons learned. We want schools to learn from others' mistakes, not their own.
Free tools and educational resources to assess your school's security posture and build a culture of data protection.
On August 4, 2026, the Facebook account 'Nullsec Philippines,' signed by the persona 'Nostra,' publicly addressed a state university in Mindanao by name and published a link to a plain-text file said to contain extracted student email addresses. The post attached a screenshot of an HTTP interception proxy showing a single POST request to a student-index endpoint on one of the institution's campus subdomains, returning a JSON response that maps institutional student email addresses to first, middle, and last names; the tool reports that single response at roughly 192 KB. A second attached image showed a long, watermarked wall of the same email-and-name pairs. The post was captioned in Tagalog to the effect of 'one more prompt before we go inactive.' The institution has not issued a public statement, no independent media or researcher corroboration has been found, and this entry is recorded as 'unconfirmed' with the institution's name withheld.
On August 1, 2026, a Facebook page using the name 'CrimsonSec Philippines,' signed by the persona 'Ph.0xUnknown404,' addressed a university in Bicol Region, claiming to have found and exploited a vulnerability in the student information and accounting portal that students log into. The post claims the actor viewed tens of thousands of student records containing names, photographs, home addresses, contact numbers, parent details, dates of birth and account passwords described as crackable within minutes and reused on other services. The post states that nothing was copied or sold and makes no demands, while attaching screenshots that appear to show a student roster spreadsheet, a directory of several hundred student identification photographs, and roughly a hundred database table exports — material that is not reproduced on this site. The institution has not issued a public statement, and no independent media or researcher corroboration has been found. This entry is recorded as 'unconfirmed' on the basis of the single threat-actor claim.
On July 25, 2026, a Facebook post signed by the persona 'Ph.Bl4ke' addressed a private college in Cebu City, claiming to have obtained all WordPress account credentials for the institution's website and linking to a downloadable file said to contain the extracted data. The post credited 'CrimsonSec Philippines,' 'Black Bytes,' 'Nullsec Philippines,' and 'St0pc0rrupti0n' in its greetz line, alongside several additional handles under a separate 'Special Greetings' banner. The persona Ph.Bl4ke has previously been linked to three other Philippine school-targeting claims tracked on this site under the 'Storm Breaker Security PH' banner, including one other WordPress-related claim. The institution has not issued a public statement, and no independent media or researcher corroboration has been found. This entry is recorded as 'unconfirmed' on the basis of the single threat-actor claim.
On July 23, 2026, a Facebook post by 'Nullsec Philippines' addressed a private medical college in Cebu City — previously the subject of a May-June 2026 Quantum Security Group defacement and data-exfiltration claim tracked separately on this site — claiming to have deleted files on the institution's systems and linking to an archive.md snapshot of the site's pages 'before the disaster.' The post included two embedded screenshots: one showing a webshell-style file-manager interface with a mass-deletion command whose visible output was dominated by permission-denied errors rather than confirmed successful deletion, and a second showing a web-based database-administration tool (Adminer) open against the institution's production Student Information System, displaying a student-fee table's column structure without any row-level data. No student records or data export were shown or claimed. The institution has not issued a public statement about either incident. This entry is recorded as 'unconfirmed' on the basis of the single threat-actor post; the specific hostname, database name, and account handles are not reproduced on this site.
On July 21, 2026, a Facebook post attributed to the page 'Nullsec Philippines' addressed a private computer college campus in Rizal province, opening with personal grievances from self-described former students against unnamed staff before framing a claimed breach as a test of the institution's own technology and cybersecurity teaching. The post included a 'HIT BY NULLSEC' defacement banner, a dense greetz line naming recurring and previously undocumented handles signed 'N Z & friends,' and an enumeration of on the order of 140 student records (name, ID number, program/strand, and a hashed password) spanning the ICT, ABM, and STEM tracks, alongside a separate spreadsheet screenshot suggestive of staff/employee credential exposure. The institution has not issued a public statement. This entry is recorded as 'unconfirmed' on the basis of the single threat-actor claim; specific account names, password hashes, and reference URLs are not reproduced on this site.
On July 14, 2026, the Facebook account 'Nullsec Philippines,' signed by the persona 'Nostra,' publicly addressed a private university in Metro Manila's official Facebook page, stating the group was 'not getting involved anymore' but asking the institution to fix its website. Two attached screenshots showed a publicly reachable phpinfo() diagnostic page and the raw, unexecuted source code of a third-party database-administration script, which exposed the script's access password and the site's database credentials in cleartext. No data extraction, defacement, or unauthorized access was claimed. The institution has not issued a public statement, and this entry is recorded as 'unconfirmed' on the basis of a single threat actor's post.
On June 2, 2026, a Facebook post by 'Nullsec Philippines' — signed by the handles '0x.Zh3n' and '0xTerror' — addressed a private Catholic university in Mindanao and published what the actors claim is the result of an unauthenticated file-read exploitation of a PeopleSoft WSRP Consumer ResourceProxy servlet on the institution's student-records subsystem. The post enumerates 11 AES-encrypted application credentials extracted from WebLogic domain and boot configuration files (covering the domain, the node manager, the SSL private key passphrase, the Java keystore and truststore, the embedded LDAP, the database connection, and the boot administrator), 7 SHA-512 crypt password hashes from the operating-system shadow file (including an admin account and six named user accounts), 1 RSA public key from authorized_keys, the WebLogic domain AES master encryption key file, and six years of historical Java keystore backups (2019, 2021, 2022, 2023, 2025). The post discloses the specific credential blobs, hash values, the affected hostname, the internal database IP, and the named user accounts in cleartext form; none of these values are reproduced on this site. The institution has not issued a public statement. This entry is recorded as 'unconfirmed' on the basis of the single threat-actor claim; the institution name and all identifying values are redacted pending public confirmation.
On May 27, 2026, a Facebook page operating under the name 'Quantum Security Group' (QSG), signed by the handle '#ch4nc3ll0rx_1337', claimed in a public post addressed to a private IT-focused university chain in the Philippines that they had compromised one of the institution's subdomain portals and exfiltrated ≈200,100 student records along with ≈4,044 records of submitted student-requirement documents (transcripts, birth certificates, Form 138/137, diplomas, government IDs, and other personal documentation). The actor framed the disclosure around the irony that the institution publicly markets cybersecurity courses and programs. The institution has not issued a public statement. This entry is recorded as 'unconfirmed' on the basis of the single threat-actor claim; specific identifying URLs, the exfiltrated proof links, and the actor's download URLs are not reproduced on this site.
A threat actor group using the name "Philippine CyberMafia," signed by an individual using the handle "nightfury," claimed on Facebook to have exploited a cross-site scripting (XSS) vulnerability on a subdomain of a private university in Bicol Region. A screenshot shows a JavaScript dialog executing on the institution's maritime-education subdomain with the message "greetings from pcm hehe ~nightfury was here." The actor's accompanying caption explicitly calls out the institution's failure to sanitize inputs. No data exfiltration has been claimed or demonstrated, and the institution has not issued a public statement.
A threat actor using the alias "L1NX" posted a Facebook listing offering to sell a database allegedly sourced from an international school in Quezon City. The listing advertises a wide range of student, parent, and administrative data for USD 133, and cites what appear to be cloud-service credentials as proof. The claim has not been independently verified and the institution has not issued a public statement.