What Happened
On April 2, 2026, the hacktivist group Nullsec Philippines posted on Facebook claiming to have defaced the website of Assumption College of Davao (www.acd.edu.ph). The defacement page replaced the school's homepage with the Nullsec Philippines logo — a skull bearing the Philippine flag — along with the message "HACKED BY NULLSEC PHILIPPINES" and the slogan "#PUNISH THE INJUSTICE#."
School Response
The school's Information and Communications Technology Center (ICTC) issued an official advisory on April 2, 2026, confirming the incident:
- 1.The website experienced temporary defacement by an unauthorized external party.
- 2.The issue is strictly limited to the website layer. Core institutional systems remain unaffected.
- 3.As of April 2, 2026, there is no evidence of any data breach involving learner/student or personnel information.
The ICTC stated that their team is restoring the site and implementing enhanced security measures to prevent future occurrences.
What Was Compromised
- Website defacement — the school's main website was replaced with a defacement page
- No data breach — the school confirmed no evidence of data exfiltration involving student or personnel information
- Core systems unaffected — the incident was limited to the website layer
Attacker
Nullsec Philippines is a Philippine-based hacktivist group responsible for a series of attacks against educational institutions. The defacement page included greetings to: Lei$, N0STR4, Astria, Xf1ltr4t0r, 1nv4d3r, AstralX99, Wiz, B00tz, Lost32x, r3dh0t:~$, Klyntar, 0x.Zh3n, seve, 0x.Terror, Ph.Bin0x, zane0days, Yasuo, Crypt0nymz, and BERT1337.
The post also included "Greetz & Respected" shout-outs to: Anonymous Philippines, Lulzsec Pilipinas, and Pinoy Vendetta, and linked to the group's Facebook page and Telegram channel (t.me/nullsechackers).
This attack is part of the group's broader campaign against Philippine educational institutions throughout 2026.
Resolution
The defacement was confirmed via direct access to the site. Within approximately 3 hours, the school restored the website — the site briefly showed a 404 as an intermediate state before the normal homepage returned. The school's ICTC issued an official advisory confirming the incident and stated they are implementing enhanced security measures.
How to Prevent This
- 1.Keep web server software updated — ensure CMS platforms, plugins, and server software are fully patched
- 2.Use a Web Application Firewall (WAF) — to detect and block defacement and injection attacks
- 3.Implement file integrity monitoring — detect unauthorized changes to website files in real time
- 4.Enforce strong authentication — require MFA for all administrative accounts
- 5.Restrict admin panel access — limit backend access to trusted IP addresses
- 6.Maintain offline backups — ensure rapid restoration in the event of a defacement
Institution Statement
Right of Reply — Official statement from the named institution
The Information and Communications Technology Center (ICTC) of Assumption College of Davao wishes to inform the community regarding a recent security incident involving our official website (www.acd.edu.ph). The website experienced temporary defacement by an unauthorized external party. The issue is strictly limited to the website layer. Core institutional systems remain unaffected. As of April 2, 2026, there is no evidence of any data breach involving learner/student or personnel information. Our team is currently restoring the site and implementing enhanced security measures to prevent future occurrences.Sources & References
All sources are independently verified. Access dates and archive links are recorded for each citation.
- [1]Nullsec Philippines defacement claim (Facebook) — Facebook post by Nullsec Philippines claiming responsibility for the defacement of Assumption College of Davao (April 2, 2026)
- [2]ICTC Advisory — Official Statement on Website Security (Facebook) — Official advisory from Assumption College of Davao's ICTC confirming the website defacement and stating no evidence of data breach involving learner/student or personnel information (April 2, 2026)Accessed: April 2, 2026