SchoolBreach.org
BreachesTrendsToolsLearnAbout
Free Security Check
Security Check
SchoolBreach.org

A public resource tracking data breaches in Philippine schools. Helping administrators protect student data through awareness, education, and free security tools.

© 2026 SchoolBreach.org · A community service by OceanEd

Navigate

  • Breaches
  • Trends
  • Tools
  • Learn
  • Methodology

Company

  • About
  • Privacy Policy
  • Terms of Service
  • Contact Us

Disclaimer: This tracker is maintained for educational and awareness purposes. Incidents are documented using threat intelligence monitoring, Philippine media reports, NPC filings, and responsible disclosures. Social media platforms are monitored for leads and are corroborated before publication or naming — never through active scanning or exploitation. Severity ratings and summaries are prepared with AI assistance and reviewed editorially. Full methodology →

Philippine School Data Breach Tracker

A public resource tracking cybersecurity incidents affecting Philippine schools. Because student data deserves better protection.

Free Security ToolsLearn & Guides
90
Incidents Tracked
19.2M+
Records Affected
21
Critical Severity
10
Unresolved
1
Days Since Last Incident

Why Track School Breaches?

Schools hold some of the most sensitive data imaginable — children's personal information, family details, medical records. Yet most Philippine schools lack the resources and awareness to protect this data. This tracker exists to raise awareness and drive change.

Raise Awareness

Most schools don't know breaches are happening in Philippine education. Visibility is the first step to action.

Document Patterns

By tracking incidents, we identify common attack vectors and vulnerabilities so schools can prioritize defenses.

Drive Better Security

Every breach listed here includes lessons learned. We want schools to learn from others' mistakes, not their own.

Protect Your School

Free tools and educational resources to assess your school's security posture and build a culture of data protection.

Free Security ToolsGuides & Resources

37 of 90 incidents

Showing 10 of 37
criticalunconfirmedUnauthorized Access

A university in Bicol Region

On August 1, 2026, a Facebook page using the name 'CrimsonSec Philippines,' signed by the persona 'Ph.0xUnknown404,' addressed a university in Bicol Region, claiming to have found and exploited a vulnerability in the student information and accounting portal that students log into. The post claims the actor viewed tens of thousands of student records containing names, photographs, home addresses, contact numbers, parent details, dates of birth and account passwords described as crackable within minutes and reused on other services. The post states that nothing was copied or sold and makes no demands, while attaching screenshots that appear to show a student roster spreadsheet, a directory of several hundred student identification photographs, and roughly a hundred database table exports — material that is not reproduced on this site. The institution has not issued a public statement, and no independent media or researcher corroboration has been found. This entry is recorded as 'unconfirmed' on the basis of the single threat-actor claim.

Aug 1, 2026Tens of thousands of student records claimed by the threat actor; no figure independently verified records
highunconfirmedUnauthorized Access

A private college in Cebu City

On July 25, 2026, a Facebook post signed by the persona 'Ph.Bl4ke' addressed a private college in Cebu City, claiming to have obtained all WordPress account credentials for the institution's website and linking to a downloadable file said to contain the extracted data. The post credited 'CrimsonSec Philippines,' 'Black Bytes,' 'Nullsec Philippines,' and 'St0pc0rrupti0n' in its greetz line, alongside several additional handles under a separate 'Special Greetings' banner. The persona Ph.Bl4ke has previously been linked to three other Philippine school-targeting claims tracked on this site under the 'Storm Breaker Security PH' banner, including one other WordPress-related claim. The institution has not issued a public statement, and no independent media or researcher corroboration has been found. This entry is recorded as 'unconfirmed' on the basis of the single threat-actor claim.

Jul 25, 2026Unspecified number of WordPress account credentials claimed by the threat actor records
criticalunconfirmedUnauthorized Access

A private medical college in Cebu City

On July 23, 2026, a Facebook post by 'Nullsec Philippines' addressed a private medical college in Cebu City — previously the subject of a May-June 2026 Quantum Security Group defacement and data-exfiltration claim tracked separately on this site — claiming to have deleted files on the institution's systems and linking to an archive.md snapshot of the site's pages 'before the disaster.' The post included two embedded screenshots: one showing a webshell-style file-manager interface with a mass-deletion command whose visible output was dominated by permission-denied errors rather than confirmed successful deletion, and a second showing a web-based database-administration tool (Adminer) open against the institution's production Student Information System, displaying a student-fee table's column structure without any row-level data. No student records or data export were shown or claimed. The institution has not issued a public statement about either incident. This entry is recorded as 'unconfirmed' on the basis of the single threat-actor post; the specific hostname, database name, and account handles are not reproduced on this site.

Jul 23, 2026No specific record count claimed or shown; screenshots reviewed demonstrate webshell (command-execution) access and Adminer database-administration access to the production Student Information System, but no row-level student or staff data was shown extracted records
criticalunconfirmedUnauthorized Access

A private Catholic university in Mindanao

On June 2, 2026, a Facebook post by 'Nullsec Philippines' — signed by the handles '0x.Zh3n' and '0xTerror' — addressed a private Catholic university in Mindanao and published what the actors claim is the result of an unauthenticated file-read exploitation of a PeopleSoft WSRP Consumer ResourceProxy servlet on the institution's student-records subsystem. The post enumerates 11 AES-encrypted application credentials extracted from WebLogic domain and boot configuration files (covering the domain, the node manager, the SSL private key passphrase, the Java keystore and truststore, the embedded LDAP, the database connection, and the boot administrator), 7 SHA-512 crypt password hashes from the operating-system shadow file (including an admin account and six named user accounts), 1 RSA public key from authorized_keys, the WebLogic domain AES master encryption key file, and six years of historical Java keystore backups (2019, 2021, 2022, 2023, 2025). The post discloses the specific credential blobs, hash values, the affected hostname, the internal database IP, and the named user accounts in cleartext form; none of these values are reproduced on this site. The institution has not issued a public statement. This entry is recorded as 'unconfirmed' on the basis of the single threat-actor claim; the institution name and all identifying values are redacted pending public confirmation.

Jun 2, 2026No student records claimed; 11 AES-encrypted application credentials, 7 SHA-512 OS-level password hashes, 1 RSA public key, the WebLogic domain encryption-key file, and six years of historical keystore backups claimed by the threat actor records
highinvestigatingUnauthorized Access

A state university in Western Visayas

On May 20, 2026, the Facebook account '4b1smo' (a Nullsec Philippines-affiliated account) addressed a state university in Western Visayas with the one-word framing 'hmmm,' tagging the institution's official Public Information Office page. The post included a single composite screenshot of the institution's homepage with a Notepad window overlaid, captioned 'TANGINANG YAN HAHAHAH 4B1SMO' and headed 'DATABASE'. The Notepad listed four grades-related database names alongside the standard MySQL information_schema system database — a pattern consistent with the output of either a `SHOW DATABASES` command or a `SELECT schema_name FROM information_schema.schemata` query, both of which require either authenticated database access or an SQL-injection foothold to obtain from outside. No sample rows, no record count, no specific URL, and no exfiltrated file were attached. The institution name has been withheld in public display pending corroboration.

May 20, 2026Unknown (databases enumerated; no record count claimed) records
mediuminvestigatingUnauthorized Access

A state university in Nueva Vizcaya

On May 1, 2026, the threat-actor account 'Nullsec Philippines' posted on Facebook addressing a state university in Nueva Vizcaya, attaching a screenshot of a logged-in session on the institution's College Admission Test (CAT) applicant portal. The screenshot shows a single applicant's profile — including the applicant's photograph, reference ID area, profile-completion status, and exam venue/date/time assignments — published publicly with mocking commentary. Only single-account access is demonstrated; broader administrative compromise has not been shown. The institution name has been withheld in public display pending independent confirmation, and the affected applicant's identifying photograph is not reproduced on this site.

May 1, 2026At least 1 applicant account (broader scope unconfirmed) records
highresolvedUnauthorized Access

A private school in Tagum City

Threat actor 'Crypt0nymz' from NullSec Philippines claimed to have bypassed A private school in Tagum City's WAF and accessed the 'smct' database, exposing a grades table with student numbers, names, and grades. The attacker cited outdated web security and a debugger mode left enabled.

Mar 4, 2026Unknown records
highunconfirmedUnauthorized Access

A private college in Davao City

A threat actor using the alias "Alexandria" claimed on Facebook to have compromised the servers, applications, and Blackboard Learn LMS of a private college in Davao City. The post alleges full administrator access, the ability to bypass a two-factor authentication mechanism, persistence on internal systems, and the capability to destroy LMS data with no available backups. Screenshots of what appears to be the institution's Blackboard admin panel, user directory, and academic-term configuration were shared as evidence. The institution has not issued a public statement and no independent source has confirmed the claim.

Mar 3, 2026Unknown records
mediumresolvedUnauthorized Access

DepEd Division of Malabon City

Storm Breaker Security PH claimed on Facebook to have conducted a DDoS attack against depedmalaboncity.ph, taking the DepEd Malabon City division website offline. Global uptime checks confirmed the site was unreachable from all monitored locations.

Feb 15, 2026Malabon CityNone records
highunconfirmedUnauthorized Access

A state university in Ilocos Region

A threat actor group using the name "Philippine CyberMafia," signed by an individual using the handle "~/.toothless," claimed on Facebook to have compromised a subdomain-hosted internal administrative application of a state university in Ilocos Region. The post taunted the institution's administrators and referenced the SQL-injection payload "1=1," strongly implying an authentication-bypass SQLi as the access vector. Screenshots show authenticated access to the app's Transactions and Users views, which expose columns for student names, ID numbers, email addresses, phone numbers, programs, and courses. The institution has not issued a public statement and no independent source has confirmed the claim.

Dec 24, 2025Unknown records