SchoolBreach.org
BreachesTrendsToolsLearnAbout
Free Security Check
Security Check
SchoolBreach.org

A public resource tracking data breaches in Philippine schools. Helping administrators protect student data through awareness, education, and free security tools.

© 2026 SchoolBreach.org · A community service by OceanEd

Navigate

  • Breaches
  • Trends
  • Tools
  • Learn
  • Methodology

Company

  • About
  • Privacy Policy
  • Terms of Service
  • Contact Us

Disclaimer: This tracker is maintained for educational and awareness purposes. Incidents are documented using threat intelligence monitoring, Philippine media reports, NPC filings, and responsible disclosures. Social media platforms are monitored for leads and are corroborated before publication or naming — never through active scanning or exploitation. Severity ratings and summaries are prepared with AI assistance and reviewed editorially. Full methodology →

Philippine School Data Breach Tracker

A public resource tracking cybersecurity incidents affecting Philippine schools. Because student data deserves better protection.

Free Security ToolsLearn & Guides
90
Incidents Tracked
19.2M+
Records Affected
21
Critical Severity
10
Unresolved
1
Days Since Last Incident

Why Track School Breaches?

Schools hold some of the most sensitive data imaginable — children's personal information, family details, medical records. Yet most Philippine schools lack the resources and awareness to protect this data. This tracker exists to raise awareness and drive change.

Raise Awareness

Most schools don't know breaches are happening in Philippine education. Visibility is the first step to action.

Document Patterns

By tracking incidents, we identify common attack vectors and vulnerabilities so schools can prioritize defenses.

Drive Better Security

Every breach listed here includes lessons learned. We want schools to learn from others' mistakes, not their own.

Protect Your School

Free tools and educational resources to assess your school's security posture and build a culture of data protection.

Free Security ToolsGuides & Resources

26 of 90 incidents

Showing 10 of 26
highunconfirmedDatabase Leak

A state university in Mindanao

On August 4, 2026, the Facebook account 'Nullsec Philippines,' signed by the persona 'Nostra,' publicly addressed a state university in Mindanao by name and published a link to a plain-text file said to contain extracted student email addresses. The post attached a screenshot of an HTTP interception proxy showing a single POST request to a student-index endpoint on one of the institution's campus subdomains, returning a JSON response that maps institutional student email addresses to first, middle, and last names; the tool reports that single response at roughly 192 KB. A second attached image showed a long, watermarked wall of the same email-and-name pairs. The post was captioned in Tagalog to the effect of 'one more prompt before we go inactive.' The institution has not issued a public statement, no independent media or researcher corroboration has been found, and this entry is recorded as 'unconfirmed' with the institution's name withheld.

Aug 4, 2026No record count stated by the threat actor. The single application response shown in the attached screenshot is reported by the interception tool at roughly 192 KB of name-and-email records, and a separately published text file is described as containing extracted email addresses records
highunconfirmedDatabase Leak

A private computer college campus in Rizal province

On July 21, 2026, a Facebook post attributed to the page 'Nullsec Philippines' addressed a private computer college campus in Rizal province, opening with personal grievances from self-described former students against unnamed staff before framing a claimed breach as a test of the institution's own technology and cybersecurity teaching. The post included a 'HIT BY NULLSEC' defacement banner, a dense greetz line naming recurring and previously undocumented handles signed 'N Z & friends,' and an enumeration of on the order of 140 student records (name, ID number, program/strand, and a hashed password) spanning the ICT, ABM, and STEM tracks, alongside a separate spreadsheet screenshot suggestive of staff/employee credential exposure. The institution has not issued a public statement. This entry is recorded as 'unconfirmed' on the basis of the single threat-actor claim; specific account names, password hashes, and reference URLs are not reproduced on this site.

Jul 21, 2026On the order of 140 student records visible across the screenshots reviewed (name, student ID number, program/strand, and a hashed password per row), claimed by the threat actor; the post's own structure suggests the underlying list may be longer, and a separate screenshot suggests possible additional staff/employee credential exposure records
criticalinvestigatingDatabase Leak

A private medical college in Cebu City

On May 31, 2026, a Facebook post by 'Quantum Security Group' (QSG) — signed by the handle 'ZeuS' with the Telegram contact '@XantyEvander' and a Blogspot archive at quantum-sec-group.blogspot.com — addressed a private medical college in Cebu City. The post claimed and provided index-page URLs for the simultaneous defacement of 27 distinct subdomains on the institution's primary domain, including subdomains corresponding to canteen and food-service microsites, three named development environments (dev/dev2/dev3), file storage, library systems, the student information system, three visa-processing subdomains, a campus-perks system, an iCash payment subsystem, and — most operationally significant — a publicly-accessible phpMyAdmin database-administration interface. No data exfiltration was claimed at the time. The defacement was simultaneously registered to a public deface-tracker mirror under the actor's handle. In a follow-up post under the same banner (June 2026, signed collectively as 'QSG Team'), QSG escalated the claim — stating it had exfiltrated the institution's data records and advertising a six-part multi-volume 7z archive set as publicly downloadable via a base64-encoded file-sharing link. On the strength of that exfiltration claim and its accompanying multi-volume archive artifacts, this entry's severity has been raised to critical. The institution name, the specific subdomain URLs, the archive filenames, and the download link are not reproduced on this site. The institution has not issued a public statement.

Jun 24, 2026Unspecified (bulk data exfiltration claimed; volume not disclosed) records
criticalunconfirmedDatabase Leak

A private IT-focused university chain in the Philippines

On May 27, 2026, a Facebook page operating under the name 'Quantum Security Group' (QSG), signed by the handle '#ch4nc3ll0rx_1337', claimed in a public post addressed to a private IT-focused university chain in the Philippines that they had compromised one of the institution's subdomain portals and exfiltrated ≈200,100 student records along with ≈4,044 records of submitted student-requirement documents (transcripts, birth certificates, Form 138/137, diplomas, government IDs, and other personal documentation). The actor framed the disclosure around the irony that the institution publicly markets cybersecurity courses and programs. The institution has not issued a public statement. This entry is recorded as 'unconfirmed' on the basis of the single threat-actor claim; specific identifying URLs, the exfiltrated proof links, and the actor's download URLs are not reproduced on this site.

May 27, 2026≈200,100 student records and ≈4,044 student-requirement document submissions claimed by the threat actor records
criticalinvestigatingDatabase Leak

A state university in Mindanao

On May 10, 2026, a state university in Mindanao was publicly named in a Facebook post by Nullsec Philippines (signed by 'Yasuo' and '0xTerror') claiming a comprehensive credentialed compromise. The actor claims to have obtained LDAP administrative credentials, database usernames and passwords, internal IP addresses and infrastructure details, configuration and authentication information, an estimated 24,942 student records, and — most operationally significant — the SMTP master key for the institution's no-reply email account. Specific credentials and identifying URLs are not reproduced on this site. The institution has not yet issued a public statement; this entry is tracked as 'investigating' on the basis of the threat-actor claim alone, with severity recorded as 'critical' due to the combination of bulk student-record exposure, claimed admin-tier credentials, and a working email-server master key that — if authentic — would enable institution-wide phishing impersonation against the entire affected student body.

May 10, 2026≈24,942 student records claimed by the threat actor; LDAP and database credentials and an SMTP master key separately claimed records
criticalconfirmedDatabase Leak

DepEd Training Platform (training.deped.gov.ph)

On May 3, 2026, the joint Facebook account 'NSP & DNH' (Nullsec Philippines × Deathnote Hackers International) publicly posted a claim of breach against the DepEd training platform at training.deped.gov.ph, accompanied by a CSV file said to contain 999,995 rows of user data with fields including full names, emails, user IDs, and profile links. Cybersecurity research and advocacy organization Deep Web Konek (DWK) independently reviewed the circulated dataset on the same day and reported that the row count aligns with the actor's claim, that the schema is consistent with structured institutional databases, and that sample entries display realistic naming patterns — assessing the dataset as 'likely authentic with strong internal consistency.' SchoolBreach.org's editorial team independently observed that training.deped.gov.ph is no longer reachable, returning a Cloudflare error rather than the usual training-platform interface as of May 3, 2026 — confirming that DepEd's IT operations team has taken the platform offline in response. The combination of independent dataset validation by DWK and the platform being pulled offline supports tracking this entry as confirmed.

May 3, 2026Pasig City999,995 records
highunconfirmedDatabase Leak

An international school in Quezon City

A threat actor using the alias "L1NX" posted a Facebook listing offering to sell a database allegedly sourced from an international school in Quezon City. The listing advertises a wide range of student, parent, and administrative data for USD 133, and cites what appear to be cloud-service credentials as proof. The claim has not been independently verified and the institution has not issued a public statement.

Apr 21, 2026Unknown records
highconfirmedDatabase Leak

Bangsamoro Ministry of Basic, Higher and Technical Education (MBHTE)

Fawkes Pilipinas, affiliated with Nullsec Philippines, claimed to have breached the Bangsamoro Ministry of Basic, Higher and Technical Education (MBHTE) and posted a 1 MB+ JSON sample of exfiltrated data. The MBHTE website (mbhte.bangsamoro.gov.ph) was subsequently suspended by Bangsamoro Government Web Hosting Services, citing a detected cyber breach.

Mar 31, 2026Cotabato City1 MB+ exposed
highresolvedDatabase Leak

A private college in Bulacan

Threat actor group Fawkes Pilipinas, affiliated with Nullsec Philippines, claimed to have exfiltrated data from a private college in Bulacan. The post, framed around allegations of discrimination and bullying, included a download link to a 4MB+ CSV file purportedly containing college data. The school has not confirmed or denied the breach.

Mar 31, 20264 MB+ exposed
criticalresolvedDatabase Leak

Two educational institutions in San Fernando, La Union

Nullsec Philippines breached two private colleges in San Fernando, La Union by compromising their shared hosting account. Beyond defacing both websites, the attackers exfiltrated the full school database — over 16 CSV tables containing student payments, enrollment records, tuition fees, user accounts with plaintext passwords, and teacher evaluations.

Mar 29, 2026Unknown records