SchoolBreach.org
BreachesTrendsToolsLearnAbout
Free Security Check
Security Check
SchoolBreach.org

A public resource tracking data breaches in Philippine schools. Helping administrators protect student data through awareness, education, and free security tools.

© 2026 SchoolBreach.org · A community service by OceanEd

Navigate

  • Breaches
  • Trends
  • Tools
  • Learn
  • Methodology

Company

  • About
  • Privacy Policy
  • Terms of Service
  • Contact Us

Disclaimer: This tracker is maintained for educational and awareness purposes. Incidents are documented using threat intelligence monitoring, Philippine media reports, NPC filings, and responsible disclosures. Social media platforms are monitored for leads and are corroborated before publication or naming — never through active scanning or exploitation. Severity ratings and summaries are prepared with AI assistance and reviewed editorially. Full methodology →

Philippine School Data Breach Tracker

A public resource tracking cybersecurity incidents affecting Philippine schools. Because student data deserves better protection.

Free Security ToolsLearn & Guides
90
Incidents Tracked
19.2M+
Records Affected
21
Critical Severity
10
Unresolved
1
Days Since Last Incident

Why Track School Breaches?

Schools hold some of the most sensitive data imaginable — children's personal information, family details, medical records. Yet most Philippine schools lack the resources and awareness to protect this data. This tracker exists to raise awareness and drive change.

Raise Awareness

Most schools don't know breaches are happening in Philippine education. Visibility is the first step to action.

Document Patterns

By tracking incidents, we identify common attack vectors and vulnerabilities so schools can prioritize defenses.

Drive Better Security

Every breach listed here includes lessons learned. We want schools to learn from others' mistakes, not their own.

Protect Your School

Free tools and educational resources to assess your school's security posture and build a culture of data protection.

Free Security ToolsGuides & Resources

16 of 90 incidents

Showing 10 of 16
lowinvestigatingWebsite Defacement

A foundation college in Mindanao

On May 3, 2026, the Facebook account '4b1smo' (a newly-promoted Nullsec Philippines-affiliated account) posted a one-line claim addressed to a foundation college in Mindanao, framed as 'time to fix [institution] - Main Page weak security lolx' and accompanied by an archive.md snapshot URL as evidence. The post does not claim data exfiltration, does not name a vulnerability class, and does not describe what 'weak security' refers to beyond the linked screenshot. Nullsec Philippines re-shared the post on its main page within minutes. The institution has not issued a public statement. The institution name, the institution's province, and the archive snapshot URL have been withheld in public display pending corroboration.

May 3, 2026Not claimed; threat actor described 'weak security' on the institution's main page records
highinvestigatingWebsite Defacement

A state university in MIMAROPA

On May 2, 2026, the Facebook account 'Nullsec Philippines' publicly posted a defacement claim against a state university in the MIMAROPA region, listing several of the institution's internal management information system (MIS) subdomains — covering its assets, records, and library functions — as having received `nullsec.html` marker pages. The post also bundled roughly twenty additional defaced URLs on unrelated infrastructure, framing the operation as a coordinated mass-mirror. Multiple screenshots were attached, including images of the defacement page, what appear to be administrative views of an internal MIS dashboard, and an apparent employee identity record — evidence that, if authentic, suggests the actor's access went beyond simple web defacement. The post was signed 'Yasuo' and ended with 'mirror? done~'. The institution has not issued a public statement and the named subdomains have not been independently re-checked at the time of this entry. The university name, its province, the literal subdomain prefixes, and any individual identities visible in the attached screenshots have been withheld in public display pending corroboration.

May 2, 2026Not claimed numerically; attached screenshots suggest admin-tier visibility into the institution's MIS rather than defacement alone records
lowinvestigatingWebsite Defacement

A technical institute in Laguna

On May 2, 2026, the Facebook account 'Nullsec Philippines' publicly posted a one-line claim addressed to a technical institute in Laguna and linked to a defacement page hosted off-domain on a third-party Philippine content platform — not on the institution's own infrastructure. The post also linked to a public archive snapshot of that page. The post is unusual within the Nullsec batch: no school-domain subdomain is named, no data is claimed, and no specific access vector is described — the entire public footprint of the claim is a single off-domain HTML file that mentions the school. The relationship between the institution and the third-party platform has not been independently verified, and the school has not issued a public statement. The institution name, the institution's city, and the specific URLs of both the defacement page and its archive snapshot have been withheld in public display pending corroboration, because each of those URLs would otherwise reverse-identify the school.

May 2, 2026None claimed by the threat actor; relationship to the named institution not independently verified records
mediumunconfirmedWebsite Defacement

A private university in Bicol Region

A threat actor group using the name "Philippine CyberMafia," signed by an individual using the handle "nightfury," claimed on Facebook to have exploited a cross-site scripting (XSS) vulnerability on a subdomain of a private university in Bicol Region. A screenshot shows a JavaScript dialog executing on the institution's maritime-education subdomain with the message "greetings from pcm hehe ~nightfury was here." The actor's accompanying caption explicitly calls out the institution's failure to sanitize inputs. No data exfiltration has been claimed or demonstrated, and the institution has not issued a public statement.

Apr 23, 2026None demonstrated records
mediumresolvedWebsite Defacement

Assumption College of Davao

Nullsec Philippines defaced the website of Assumption College of Davao (www.acd.edu.ph), replacing the homepage with their logo and the message 'HACKED BY NULLSEC PHILIPPINES'. The school's Information and Communications Technology Center (ICTC) issued an official advisory confirming the defacement and stating that the issue was limited to the website layer, with no evidence of any data breach involving learner/student or personnel information.

Apr 2, 2026Davao CityNone records
lowresolvedWebsite Defacement

A private university in Cebu City

Fawkes Pilipinas, affiliated with Nullsec Philippines, claimed to have defaced the A private university in Cebu City Publishing House subdomain. The group posted a defacement page at A private university in Cebu City and stated they identified vulnerabilities in the subdomain but claimed no data was harmed.

Apr 1, 2026None (website only) records
mediumresolvedWebsite Defacement

A public senior high school in Malabon City

Storm Breaker Security PH claimed on Facebook to have breached the WordPress website of a public senior high school in NCR. The group posted a defacement page along with what appears to be exposed WordPress API schema data.

Mar 14, 2026Unknown records
criticalconfirmedWebsite Defacement

DepEd Tayo Roxas City

Threat actor 'Ch4nc3ll0rx 1337' defaced the DepEd Tayo Roxas City website (depedroxascity.com), dumped 7GB of web directories and 17MB of compressed databases, and claimed a total of 107 related defacements.

Mar 8, 2026Roxas City7 GB exposed
criticalconfirmedWebsite Defacement

DepEd Tayo Lucena City

Threat actor 'Ch4nc3ll0rx 1337' defaced and leaked data from the DepEd Tayo Lucena City website (depedlucenadms.com), dumping 3,000+ lines of database contents and claiming full server compromise with backdoors deployed.

Mar 4, 2026Lucena City3,000+ lines records
highresolvedWebsite Defacement

Philippine National Police Academy (PNPA)

The Philippine National Police Academy website was defaced and its database allegedly breached by hacking group Phantom Troupe, who claimed to have accessed personal information of over 23,000 users.

Feb 3, 2021Silang, Cavite23,000+ records