SchoolBreach.org
BreachesTrendsToolsLearnAbout
Free Security Check
Security Check
SchoolBreach.org

A public resource tracking data breaches in Philippine schools. Helping administrators protect student data through awareness, education, and free security tools.

© 2026 SchoolBreach.org · A community service by OceanEd

Navigate

  • Breaches
  • Trends
  • Tools
  • Learn
  • Methodology

Company

  • About
  • Privacy Policy
  • Terms of Service
  • Contact Us

Disclaimer: This tracker is maintained for educational and awareness purposes. Incidents are documented using threat intelligence monitoring, Philippine media reports, NPC filings, and responsible disclosures. Social media platforms are monitored for leads and are corroborated before publication or naming — never through active scanning or exploitation. Severity ratings and summaries are prepared with AI assistance and reviewed editorially. Full methodology →

Back to Breach Tracker
Unauthorized Access
HighUnconfirmed

A private college in Cebu City

The name of this institution has been withheld pending verification of the source. This entry is based on an unconfirmed report.

On July 25, 2026, a Facebook post signed by the persona 'Ph.Bl4ke' addressed a private college in Cebu City, claiming to have obtained all WordPress account credentials for the institution's website and linking to a downloadable file said to contain the extracted data. The post credited 'CrimsonSec Philippines,' 'Black Bytes,' 'Nullsec Philippines,' and 'St0pc0rrupti0n' in its greetz line, alongside several additional handles under a separate 'Special Greetings' banner. The persona Ph.Bl4ke has previously been linked to three other Philippine school-targeting claims tracked on this site under the 'Storm Breaker Security PH' banner, including one other WordPress-related claim. The institution has not issued a public statement, and no independent media or researcher corroboration has been found. This entry is recorded as 'unconfirmed' on the basis of the single threat-actor claim.

July 25, 2026Unspecified number of WordPress account credentials claimed by the threat actor records affected

Key Facts

Date of Incident
July 25, 2026
Date Discovered
July 26, 2026
Records Affected
Unspecified number of WordPress account credentials claimed by the threat actor
Source
Ph.Bl4ke (Facebook)
Data Types Exposed
WordPress account credentials (claimed)
Response / Action Taken

No public statement from the institution has been observed at the time of this entry. Status will be updated if and when the school, the National Privacy Commission, or independent reporting confirms the access vector, the authenticity of the claimed dataset, and remediation.

Single-source notice: This incident is based on a single public Facebook post by a self-identified threat actor, reviewed via screenshots provided to this site — the specific post permalink was not independently captured. No mainstream news outlet has reported on it, no independent researcher has corroborated it, and the institution has not issued a public statement. The claim remains unverified and the institution's name has been redacted pending verification.

The post included a defanged download link (hosted on a third-party anonymous file-sharing service) purportedly leading to the extracted credentials, and an image showing what is consistent with a numbered listing of credential-style entries. Neither the link nor the specific contents of that image are reproduced on this site, in line with the methodology of refusing to amplify breach material.

What Happened

On July 25, 2026, a Facebook account using the name Ph.Bl4ke — a page whose Facebook category is labeled "AI content" — publicly posted addressing a private college in Cebu City by name. In substance, the post claimed to have successfully obtained all of the institution's WordPress account credentials, attributed this to inadequate website security and the web developer not having properly strengthened or secured the site, and urged the institution to address the issue and take its website security more seriously.

The post included a defanged link introduced as "Credentials," pointing to a text file on a third-party anonymous file-sharing host, along with an instruction to strip the defanging characters before use — a technique threat actors commonly use to share a working link while evading automatic link-scanning. It closed with a "Greetings to" line crediting CrimsonSec Philippines, Black Bytes, St0pc0rrupti0n, and Nullsec Philippines, and the hashtags #Anonymous #hacktivist #crimsonsecph #everyone.

Two images were attached: one combining an ASCII-art graphic reading "PHILIPPINES" with a "Special Greetings" line naming additional handles, followed by a numbered list of entries consistent in format with a credential or account dump; and a second showing a terminal window with green-on-black text and ASCII art, consistent with a hacking-tool or shell interface. Comments beneath the post include a reply from the Ph.Bl4ke account itself confirming the institution's full name, and a comment reading simply "Palo," signed "-PredixorX."

What the Post Claims

  • WordPress credential compromise. The poster claims to have obtained "all" WordPress account credentials for the institution's website. The post does not specify whether this covers only administrative accounts or a broader set of author/editor-level accounts.
  • A purported credential dump file. The post links to a text file, named in a way that echoes the "Crimson" branding also used in the greetz line, hosted on a third-party anonymous file-sharing service. The file's actual contents have not been independently reviewed by this site.
  • A numbered list graphic. One attached image shows rows of small text formatted as a numbered list, consistent with a credential or account enumeration. The specific values are not legible in the reviewed screenshots and are not reproduced here regardless.
  • A terminal/shell screenshot. A second attached image shows a terminal window with green-on-black text and an ASCII-art graphic, offered as apparent supporting evidence of tooling used, without further explanation in the post itself.

Why the Methodology Treats This as 'Unconfirmed'

This entry is fully anonymized and tagged as 'Unconfirmed' because:

  • The only public source is the threat actor's own Facebook post, reviewed via screenshots provided to this site — the specific post permalink was not independently captured
  • No corroborating media coverage has been observed
  • No NPC finding is available
  • No public statement has been issued by the institution

If the institution issues a statement, if reputable Philippine technology media independently reports the incident, or if the NPC publishes a finding, this entry will be updated and de-anonymized in line with the SchoolBreach.org methodology.

Threat-Actor Persona and Cross-References

The post is signed by Ph.Bl4ke, a persona with an existing history on this site under the Storm Breaker Security PH banner: a WordPress-related defacement claim against a public senior high school in Malabon City (March 14, 2026), a DDoS claim against the DepEd Division of Malabon City (February 15, 2026), and a SQL-injection database-leak claim against a private college in Cavite (January 12, 2026, where Ph.Bl4ke was listed among several named team members). Notably, the March 2026 Malabon claim also centered on WordPress — the same platform named in this incident.

This post's "Special Greetings" line names several handles not previously seen on this site — 4RT3M1S, Ph.0xUnknown404, Ph.Synx4, PredixorX, bithub, s1gn4L, and W3L7231 — several following the same "Ph." naming convention as prior Storm Breaker Security PH members (Ph.Error and Ph.Madac, per this site's earlier entries). The greetz line separately credits CrimsonSec Philippines, Black Bytes, St0pc0rrupti0n, and Nullsec Philippines — the latter two also surface in this post's own comment thread, where the St0pc0rrupti0n account commented directly, signed "-PredixorX," tying that handle to both the special-greetings list and an independent comment. This is the first appearance of CrimsonSec Philippines, St0pc0rrupti0n, and PredixorX credited alongside a specific breach claim tracked on this site, rather than as a name-only mention elsewhere.

Why This Claim Warrants Attention

  • CMS-level compromise risk. If accurate, credential access to the WordPress backend can enable content replacement, malicious redirect injection, or use of the compromised site to host phishing pages targeting the institution's own community.
  • Credential reuse exposure. Any individuals whose WordPress credentials were obtained may have reused the same password elsewhere, creating downstream risk beyond the website itself.
  • Publicly linked "proof." The post links to a file purportedly containing the extracted credentials on a third-party host, meaning — if genuine — the material is already available to anyone who follows the link, independent of any action this site takes.
  • Pattern continuation. This is the fourth claim tracked on this site tied to the Ph.Bl4ke persona and the second specifically involving WordPress, suggesting a recurring interest in this platform among the actor's targets.

What Is Not Known

  • Whether the credentials are genuine. No independent party has verified that the linked file contains real, currently-valid WordPress credentials for the institution.
  • How many accounts are affected. The post claims "all" credentials were obtained but gives no count, and the attached list image is not legible in the reviewed screenshots.
  • The access vector. The post does not explain how the credentials were purportedly obtained — whether by brute force, phishing, a leaked configuration file, or another method.
  • Whether the institution is aware. No public statement, advisory, or reply has been observed from the institution as of this entry.

Recommended Actions for the Institution

  1. 1.Treat the claim as credible until ruled out. Absent verification, the institution should assume the claimed WordPress credentials may be valid and act accordingly.
  2. 2.Force a password reset for every WordPress account — administrator, editor, author, and any other role — rather than only the most privileged accounts.
  3. 3.Rotate any credentials shared with WordPress, including database connection credentials and any API keys or SMTP credentials stored in the CMS configuration, since a WordPress-level compromise often exposes these too.
  4. 4.Enable multi-factor authentication on all WordPress accounts going forward, particularly for administrator-level roles.
  5. 5.Audit WordPress access and authentication logs for at least the preceding 90 days to establish whether unauthorized logins occurred and, if so, when access began.
  6. 6.Review installed themes and plugins for unauthorized modifications, including unfamiliar admin accounts, scheduled tasks, or file-editor changes that could indicate persistence mechanisms.
  7. 7.Notify the National Privacy Commission within 72 hours under RA 10173 if the review finds any indication that personal data accessible through the compromised accounts was put at risk — the legal trigger is risk to personal data, not certainty of exfiltration.
  8. 8.Issue a same-day public advisory. Silence in the face of a public claim leaves the threat actor's framing as the only public narrative. The contrast example on this site is the Assumption College of Davao ICTC advisory, issued the same day as that claim.
  9. 9.Engage a forensic review of the hosting environment, not just the WordPress application, to rule out a broader server-level compromise.
  10. 10.Preserve the threat actor's post and any linked material before it is altered or removed, for use in any NPC filing or law-enforcement referral.

How to Prevent This Pattern

  1. 1.Keep WordPress core, themes, and plugins on a current patch schedule — outdated components remain one of the most common entry points into school websites tracked on this site.
  2. 2.Enforce strong, unique passwords and MFA for every CMS account, not only administrator accounts.
  3. 3.Limit the number of accounts with administrator-level WordPress access to the minimum necessary.
  4. 4.Disable or restrict the WordPress REST API and XML-RPC endpoints where not actively used, since both have historically been used for credential enumeration and brute-force attacks.
  5. 5.Deploy a Web Application Firewall in front of the CMS to detect and block brute-force login attempts and known WordPress exploit patterns.
  6. 6.Store WordPress database and service credentials outside of web-accessible configuration files, and rotate them on a fixed schedule independent of any specific incident.
  7. 7.Publish a security contact and responsible-disclosure policy. Researchers and community members should have a private channel; absent one, they have only the public-Facebook-post channel.
Cebu CityCentral Visayasprivate collegeWordPresscredential theftunauthorized accessPh.Bl4keStorm Breaker Security PHCrimsonSecPhilippinesNullsecPhilippinesBlackBytesPredixorXSt0pc0rrupti0nFacebookhacktivismunverifiedunconfirmed2026

Related Incidents

Critical

A private medical college in Cebu City

July 23, 2026

Critical

A private medical college in Cebu City

June 24, 2026

Critical

A private Catholic university in Mindanao

June 2, 2026

Know of a Breach?

Help us keep this tracker accurate and complete. Report school data breaches confidentially.

Report a Breach

Is This Entry Inaccurate?

If you represent the named institution or have evidence that corrects or updates this entry, you can request a correction or submit an official statement for publication.

We review all correction requests and respond within 5 business days. Verified corrections are applied promptly. Institutions may also submit a statement that will appear on this page as a right of reply.

Request a Correction

Protect Your School

Use our free tools and guides to assess your school's security posture.

Free Security ToolsGuides & Resources