A public resource tracking cybersecurity incidents affecting Philippine schools. Because student data deserves better protection.
Schools hold some of the most sensitive data imaginable — children's personal information, family details, medical records. Yet most Philippine schools lack the resources and awareness to protect this data. This tracker exists to raise awareness and drive change.
Most schools don't know breaches are happening in Philippine education. Visibility is the first step to action.
By tracking incidents, we identify common attack vectors and vulnerabilities so schools can prioritize defenses.
Every breach listed here includes lessons learned. We want schools to learn from others' mistakes, not their own.
Free tools and educational resources to assess your school's security posture and build a culture of data protection.
On May 3, 2026, the Facebook account '4b1smo' (a newly-promoted Nullsec Philippines-affiliated account) posted a one-line claim addressed to a foundation college in Mindanao, framed as 'time to fix [institution] - Main Page weak security lolx' and accompanied by an archive.md snapshot URL as evidence. The post does not claim data exfiltration, does not name a vulnerability class, and does not describe what 'weak security' refers to beyond the linked screenshot. Nullsec Philippines re-shared the post on its main page within minutes. The institution has not issued a public statement. The institution name, the institution's province, and the archive snapshot URL have been withheld in public display pending corroboration.
On May 2, 2026, the Facebook account 'Nullsec Philippines' publicly posted a defacement claim against a state university in the MIMAROPA region, listing several of the institution's internal management information system (MIS) subdomains — covering its assets, records, and library functions — as having received `nullsec.html` marker pages. The post also bundled roughly twenty additional defaced URLs on unrelated infrastructure, framing the operation as a coordinated mass-mirror. Multiple screenshots were attached, including images of the defacement page, what appear to be administrative views of an internal MIS dashboard, and an apparent employee identity record — evidence that, if authentic, suggests the actor's access went beyond simple web defacement. The post was signed 'Yasuo' and ended with 'mirror? done~'. The institution has not issued a public statement and the named subdomains have not been independently re-checked at the time of this entry. The university name, its province, the literal subdomain prefixes, and any individual identities visible in the attached screenshots have been withheld in public display pending corroboration.
On May 2, 2026, the Facebook account 'Nullsec Philippines' publicly posted a one-line claim addressed to a technical institute in Laguna and linked to a defacement page hosted off-domain on a third-party Philippine content platform — not on the institution's own infrastructure. The post also linked to a public archive snapshot of that page. The post is unusual within the Nullsec batch: no school-domain subdomain is named, no data is claimed, and no specific access vector is described — the entire public footprint of the claim is a single off-domain HTML file that mentions the school. The relationship between the institution and the third-party platform has not been independently verified, and the school has not issued a public statement. The institution name, the institution's city, and the specific URLs of both the defacement page and its archive snapshot have been withheld in public display pending corroboration, because each of those URLs would otherwise reverse-identify the school.
A threat actor group using the name "Philippine CyberMafia," signed by an individual using the handle "nightfury," claimed on Facebook to have exploited a cross-site scripting (XSS) vulnerability on a subdomain of a private university in Bicol Region. A screenshot shows a JavaScript dialog executing on the institution's maritime-education subdomain with the message "greetings from pcm hehe ~nightfury was here." The actor's accompanying caption explicitly calls out the institution's failure to sanitize inputs. No data exfiltration has been claimed or demonstrated, and the institution has not issued a public statement.
Nullsec Philippines defaced the website of Assumption College of Davao (www.acd.edu.ph), replacing the homepage with their logo and the message 'HACKED BY NULLSEC PHILIPPINES'. The school's Information and Communications Technology Center (ICTC) issued an official advisory confirming the defacement and stating that the issue was limited to the website layer, with no evidence of any data breach involving learner/student or personnel information.
Fawkes Pilipinas, affiliated with Nullsec Philippines, claimed to have defaced the A private university in Cebu City Publishing House subdomain. The group posted a defacement page at A private university in Cebu City and stated they identified vulnerabilities in the subdomain but claimed no data was harmed.
Storm Breaker Security PH claimed on Facebook to have breached the WordPress website of a public senior high school in NCR. The group posted a defacement page along with what appears to be exposed WordPress API schema data.
Threat actor 'Ch4nc3ll0rx 1337' defaced the DepEd Tayo Roxas City website (depedroxascity.com), dumped 7GB of web directories and 17MB of compressed databases, and claimed a total of 107 related defacements.
Threat actor 'Ch4nc3ll0rx 1337' defaced and leaked data from the DepEd Tayo Lucena City website (depedlucenadms.com), dumping 3,000+ lines of database contents and claiming full server compromise with backdoors deployed.
The Philippine National Police Academy website was defaced and its database allegedly breached by hacking group Phantom Troupe, who claimed to have accessed personal information of over 23,000 users.