A public resource tracking cybersecurity incidents affecting Philippine schools. Because student data deserves better protection.
Schools hold some of the most sensitive data imaginable — children's personal information, family details, medical records. Yet most Philippine schools lack the resources and awareness to protect this data. This tracker exists to raise awareness and drive change.
Most schools don't know breaches are happening in Philippine education. Visibility is the first step to action.
By tracking incidents, we identify common attack vectors and vulnerabilities so schools can prioritize defenses.
Every breach listed here includes lessons learned. We want schools to learn from others' mistakes, not their own.
Free tools and educational resources to assess your school's security posture and build a culture of data protection.
A threat actor group using the name "Philippine CyberMafia," signed by an individual using the handle "~/.toothless," claimed on Facebook to have compromised a subdomain-hosted internal administrative application of a state university in Ilocos Region. The post taunted the institution's administrators and referenced the SQL-injection payload "1=1," strongly implying an authentication-bypass SQLi as the access vector. Screenshots show authenticated access to the app's Transactions and Users views, which expose columns for student names, ID numbers, email addresses, phone numbers, programs, and courses. The institution has not issued a public statement and no independent source has confirmed the claim.
Quantum Security Group breached DepEd CAR's infrastructure, exfiltrating over 6 million records across 42 databases including 30,000+ teacher personal records with plaintext passwords, and defaced multiple DepEd CAR subdomains.
Quantum Security Group claimed breaches of DepEd Ilocos Norte (3M+ records across 17 databases and 155 CSV files) and DepEd Aurora (full database backup), exposing sensitive personal information including TIN numbers and PhilHealth IDs.
Quantum Security Group leaked 7 million database records from DepEd Division of Laguna, including plaintext passwords, employee details, and multiple internal system databases spanning email, document tracking, and HR systems.
A threat actor using the alias 'jamesyu' posted data from UP Tacloban's Learning Management System for sale, exposing over 1,600 student records including names, university emails, degree programs, and profile pictures linked to the official LMS domain.
A threat actor claimed to have leaked the SQL database from Saint Pedro Poveda College's i-CLAIM asset management system, exposing detailed information about institutional assets, their physical locations, and supplier data.
A hacker using the alias 'MaxxX' advertised a dataset containing over 175,000 lines of student data from USeP's Student Records Information System, including IDs, names, emails, and academic records.
A 1.42GB data leak from the University of San Carlos exposed 155,300 partial student records and 11,877 complete Form 137 permanent academic transcripts — official documents containing a student's lifetime academic history, posing extreme risk of lifelong identity theft.
A threat actor claiming affiliation with DeathNote Hackers (DNH) leaked approximately 19,000 records from UP Mindanao, including faculty personal data and student academic records, after an initial website defacement that the university had denied was a breach.
A threat actor using the alias 'Unit' posted 115,882 records from the DepEd Schools Division of Masbate for sale at $480 in cryptocurrency, exposing both faculty employment details and student personal information including Learner Reference Numbers.