A public resource tracking cybersecurity incidents affecting Philippine schools. Because student data deserves better protection.
Schools hold some of the most sensitive data imaginable — children's personal information, family details, medical records. Yet most Philippine schools lack the resources and awareness to protect this data. This tracker exists to raise awareness and drive change.
Most schools don't know breaches are happening in Philippine education. Visibility is the first step to action.
By tracking incidents, we identify common attack vectors and vulnerabilities so schools can prioritize defenses.
Every breach listed here includes lessons learned. We want schools to learn from others' mistakes, not their own.
Free tools and educational resources to assess your school's security posture and build a culture of data protection.
On July 4 and July 5, 2026, the Facebook account 'Nullsec Philippines' addressed the Technological University of the Philippines - Manila (TUP Manila) admissions office directly, first sharing a screenshot of dozens of applicant photographs and then a follow-up post sharing a password-protected cloud-storage folder said to contain a larger set of the same. On July 9, 2026, TUP Manila's University Student Government (USG) published a public 'Update and Statement' acknowledging reports received on July 6 of 'alleged unauthorized access' to Applicant ERS (admissions) information, and stating that the University Information Technology Center (UITC) — TUP's official IT unit — opened an investigation the same day that remains ongoing. The USG statement is a student-government publication rather than a release from TUP's central administration or communications office, but it relays UITC's own acknowledgment that a report was received and is under active investigation, which is sufficient public corroboration under SchoolBreach.org's methodology to de-anonymize this entry and move its status from 'unconfirmed' to 'confirmed.'
On May 2, 2026, Instructure — the U.S.-based owner of the Canvas LMS — disclosed that the threat-actor group ShinyHunters had compromised its environment and claimed roughly 275 million records as ransomware-style extortion. Canvas is widely deployed across Philippine higher education, so the impact is sector-wide. As of mid-May 2026, at least five universities are publicly tied to the incident: DLSU and Ateneo de Manila confirmed as Instructure-notified affected clients; UST and University of the East issued coordinating advisories; San Beda experienced related Canvas service disruption. Per Instructure's global-scope statement, names, email addresses, student ID numbers, and Canvas platform messages were affected; passwords, dates of birth, government identifiers, and financial information are reported as not involved. Per-institution scope is pending Instructure's clarification.
On May 3, 2026, IBA College of Mindanao Inc. was publicly named in two threat-actor Facebook posts (Nullsec Philippines and the affiliated 4b1smo account) claiming access to 500+ student records, with screenshot evidence and a downloadable-file link. The institution responded publicly via its BSIT department's official Facebook page with a statement confirming a security breach of its website but specifically denying a deeper compromise: only the website administrator account was affected, the LMS server is on separate infrastructure and was not accessed, and the institution states the data being claimed by external parties is not from its system. The school's denial and the threat actor's claim are presented side-by-side on this entry; both positions are documented and neither is endorsed by SchoolBreach.org pending independent forensic review or NPC findings.
On May 1, 2026, the Facebook account 'Nullsec Philippines' publicly posted addressing a private K-12 institution, attaching screenshots of what appears to be a logged-in administrative session on the school's student information system. The screenshots include a per-student fee and assessment view (with full student name, gender, year level, and a multi-year assessment history), a coordinator/subject-teacher grade-posting roster, and aggregate admission and assessment dashboards covering both new and returning students with gender-broken-out totals. The exposure spans data on minors. The institution name has been withheld in public display, and identifying section, student, and staff names from the screenshots are not reproduced on this site.
On May 1, 2026, the Facebook account 'Nullsec Philippines' publicly posted addressing a Catholic K-12 institution, attaching screenshots of an Admin Dashboard branded with the institution's name. The post is notable because the threat actor explicitly stated that the institution's website developer is the same one who built another school previously claimed in this batch — making the shared-vendor / supply-chain pattern an actor-confirmed claim rather than an inference. The screenshots show admin-level access to admission and assessment dashboards, a multi-year per-student payments view including nursery-age children, and per-level / per-section enrollment breakdowns. In follow-up comments on the same post, the threat actor stated that 'none of the data was exfiltrated' and confirmed already having access to most of approximately eight sister schools that a community member named in the same thread — materially expanding the supply-chain footprint of the shared SIS vendor. The institution name has been withheld in public display, and identifying section, student, and staff names from the screenshots are not reproduced on this site.
Threat actor 'Crypt0nymz', associated with NullSec Philippines and Fawkes Pilipinas, posted on Facebook claiming to have found a security hole on a private school in Rosario, Batangas that exposed student information including names, enrollment details, and section assignments. Screenshots posted with the disclosure show what appears to be administrative access to the school's payments and admissions dashboard, including data on minors as young as nursery level. The school name has been withheld pending independent confirmation.
Threat actor '4rch4n63l' from NullsecPhilippines exfiltrated 685,318 records from a public college in Batangas City across two files (profile.json and users.json). Student account passwords were stored and exposed in plain text. The school name has been withheld as the incident was sourced solely from the threat actor's post with no independent confirmation.
Cybersecurity researcher Jeremiah Fowler discovered a non-password-protected cloud database containing 210,020 records (153.76 GB) from DepEd's Online Voucher Application Program, exposing sensitive student and parent data.
The National Privacy Commission investigated breaches affecting seven schools, institutions, and local government units after digital investigators found exposed databases containing personal information of at least 2,000 individuals, including passwords.