SchoolBreach.org
BreachesTrendsToolsLearnAbout
Free Security Check
Security Check
SchoolBreach.org

A public resource tracking data breaches in Philippine schools. Helping administrators protect student data through awareness, education, and free security tools.

© 2026 SchoolBreach.org · A community service by OceanEd

Navigate

  • Breaches
  • Trends
  • Tools
  • Learn
  • Methodology

Company

  • About
  • Privacy Policy
  • Terms of Service
  • Contact Us

Disclaimer: This tracker is maintained for educational and awareness purposes. Incidents are documented using threat intelligence monitoring, Philippine media reports, NPC filings, and responsible disclosures. Social media platforms are monitored for leads and are corroborated before publication or naming — never through active scanning or exploitation. Severity ratings and summaries are prepared with AI assistance and reviewed editorially. Full methodology →

Philippine School Data Breach Tracker

A public resource tracking cybersecurity incidents affecting Philippine schools. Because student data deserves better protection.

Free Security ToolsLearn & Guides
90
Incidents Tracked
19.2M+
Records Affected
21
Critical Severity
10
Unresolved
1
Days Since Last Incident

Why Track School Breaches?

Schools hold some of the most sensitive data imaginable — children's personal information, family details, medical records. Yet most Philippine schools lack the resources and awareness to protect this data. This tracker exists to raise awareness and drive change.

Raise Awareness

Most schools don't know breaches are happening in Philippine education. Visibility is the first step to action.

Document Patterns

By tracking incidents, we identify common attack vectors and vulnerabilities so schools can prioritize defenses.

Drive Better Security

Every breach listed here includes lessons learned. We want schools to learn from others' mistakes, not their own.

Protect Your School

Free tools and educational resources to assess your school's security posture and build a culture of data protection.

Free Security ToolsGuides & Resources

9 of 90 incidents

highconfirmedData Exposure

Technological University of the Philippines - Manila

On July 4 and July 5, 2026, the Facebook account 'Nullsec Philippines' addressed the Technological University of the Philippines - Manila (TUP Manila) admissions office directly, first sharing a screenshot of dozens of applicant photographs and then a follow-up post sharing a password-protected cloud-storage folder said to contain a larger set of the same. On July 9, 2026, TUP Manila's University Student Government (USG) published a public 'Update and Statement' acknowledging reports received on July 6 of 'alleged unauthorized access' to Applicant ERS (admissions) information, and stating that the University Information Technology Center (UITC) — TUP's official IT unit — opened an investigation the same day that remains ongoing. The USG statement is a student-government publication rather than a release from TUP's central administration or communications office, but it relays UITC's own acknowledgment that a report was received and is under active investigation, which is sufficient public corroboration under SchoolBreach.org's methodology to de-anonymize this entry and move its status from 'unconfirmed' to 'confirmed.'

Jul 4, 2026Manila, Metro ManilaUndetermined; a partial screenshot showed roughly 90 applicant photographs, and the threat actor's follow-up post claims the shared archive represents only 'half' of the full set held records
highconfirmedData Exposure

Philippine Universities — Canvas LMS Breach

On May 2, 2026, Instructure — the U.S.-based owner of the Canvas LMS — disclosed that the threat-actor group ShinyHunters had compromised its environment and claimed roughly 275 million records as ransomware-style extortion. Canvas is widely deployed across Philippine higher education, so the impact is sector-wide. As of mid-May 2026, at least five universities are publicly tied to the incident: DLSU and Ateneo de Manila confirmed as Instructure-notified affected clients; UST and University of the East issued coordinating advisories; San Beda experienced related Canvas service disruption. Per Instructure's global-scope statement, names, email addresses, student ID numbers, and Canvas platform messages were affected; passwords, dates of birth, government identifiers, and financial information are reported as not involved. Per-institution scope is pending Instructure's clarification.

May 6, 2026NationwideUnknown records
mediumconfirmedData Exposure

IBA College of Mindanao Inc.

On May 3, 2026, IBA College of Mindanao Inc. was publicly named in two threat-actor Facebook posts (Nullsec Philippines and the affiliated 4b1smo account) claiming access to 500+ student records, with screenshot evidence and a downloadable-file link. The institution responded publicly via its BSIT department's official Facebook page with a statement confirming a security breach of its website but specifically denying a deeper compromise: only the website administrator account was affected, the LMS server is on separate infrastructure and was not accessed, and the institution states the data being claimed by external parties is not from its system. The school's denial and the threat actor's claim are presented side-by-side on this entry; both positions are documented and neither is endorsed by SchoolBreach.org pending independent forensic review or NPC findings.

May 3, 2026Valencia City, BukidnonDisputed: institution states no sensitive information leaked; threat actor claims 500+ student records records
highinvestigatingData Exposure

A Christian school in Imus City, Cavite

On May 1, 2026, the Facebook account 'Nullsec Philippines' publicly posted addressing a private K-12 institution, attaching screenshots of what appears to be a logged-in administrative session on the school's student information system. The screenshots include a per-student fee and assessment view (with full student name, gender, year level, and a multi-year assessment history), a coordinator/subject-teacher grade-posting roster, and aggregate admission and assessment dashboards covering both new and returning students with gender-broken-out totals. The exposure spans data on minors. The institution name has been withheld in public display, and identifying section, student, and staff names from the screenshots are not reproduced on this site.

May 1, 2026Estimated 800-900 current-cycle students across all year levels, combining new applicants and returning students (multi-year history reachable via the same view) records
highinvestigatingData Exposure

A Catholic K-12 institution in San Juan, Batangas

On May 1, 2026, the Facebook account 'Nullsec Philippines' publicly posted addressing a Catholic K-12 institution, attaching screenshots of an Admin Dashboard branded with the institution's name. The post is notable because the threat actor explicitly stated that the institution's website developer is the same one who built another school previously claimed in this batch — making the shared-vendor / supply-chain pattern an actor-confirmed claim rather than an inference. The screenshots show admin-level access to admission and assessment dashboards, a multi-year per-student payments view including nursery-age children, and per-level / per-section enrollment breakdowns. In follow-up comments on the same post, the threat actor stated that 'none of the data was exfiltrated' and confirmed already having access to most of approximately eight sister schools that a community member named in the same thread — materially expanding the supply-chain footprint of the shared SIS vendor. The institution name has been withheld in public display, and identifying section, student, and staff names from the screenshots are not reproduced on this site.

May 1, 2026Estimated 900-1,000 current-cycle students; multi-year records spanning at least four academic years reachable via the same view records
highinvestigatingData Exposure

A private school in Rosario, Batangas

Threat actor 'Crypt0nymz', associated with NullSec Philippines and Fawkes Pilipinas, posted on Facebook claiming to have found a security hole on a private school in Rosario, Batangas that exposed student information including names, enrollment details, and section assignments. Screenshots posted with the disclosure show what appears to be administrative access to the school's payments and admissions dashboard, including data on minors as young as nursery level. The school name has been withheld pending independent confirmation.

Apr 28, 2026Estimated 800-1,000 current-cycle students (multi-year history reachable via the same view) records
criticalresolvedData Exposure

A public college in Batangas City

Threat actor '4rch4n63l' from NullsecPhilippines exfiltrated 685,318 records from a public college in Batangas City across two files (profile.json and users.json). Student account passwords were stored and exposed in plain text. The school name has been withheld as the incident was sourced solely from the threat actor's post with no independent confirmation.

Mar 4, 2026685,318 records
criticalresolvedData Exposure

DepEd Online Voucher Application Program (OVAP)

Cybersecurity researcher Jeremiah Fowler discovered a non-password-protected cloud database containing 210,020 records (153.76 GB) from DepEd's Online Voucher Application Program, exposing sensitive student and parent data.

Feb 20, 2024Nationwide210,020 records
highconfirmedData Exposure

Seven Schools, Institutions, and LGUs (NPC Investigation)

The National Privacy Commission investigated breaches affecting seven schools, institutions, and local government units after digital investigators found exposed databases containing personal information of at least 2,000 individuals, including passwords.

Jan 1, 2022Nationwide2,000 records