SchoolBreach.org
BreachesTrendsToolsLearnAbout
Free Security Check
Security Check
SchoolBreach.org

A public resource tracking data breaches in Philippine schools. Helping administrators protect student data through awareness, education, and free security tools.

© 2026 SchoolBreach.org · A community service by OceanEd

Navigate

  • Breaches
  • Trends
  • Tools
  • Learn
  • Methodology

Company

  • About
  • Privacy Policy
  • Terms of Service
  • Contact Us

Disclaimer: This tracker is maintained for educational and awareness purposes. Incidents are documented using threat intelligence monitoring, Philippine media reports, NPC filings, and responsible disclosures. Social media platforms are monitored for leads and are corroborated before publication or naming — never through active scanning or exploitation. Severity ratings and summaries are prepared with AI assistance and reviewed editorially. Full methodology →

Back to Breach Tracker
Database Leak
HighUnconfirmed

A private computer college campus in Rizal province

The name of this institution has been withheld pending verification of the source. This entry is based on an unconfirmed report.

On July 21, 2026, a Facebook post attributed to the page 'Nullsec Philippines' addressed a private computer college campus in Rizal province, opening with personal grievances from self-described former students against unnamed staff before framing a claimed breach as a test of the institution's own technology and cybersecurity teaching. The post included a 'HIT BY NULLSEC' defacement banner, a dense greetz line naming recurring and previously undocumented handles signed 'N Z & friends,' and an enumeration of on the order of 140 student records (name, ID number, program/strand, and a hashed password) spanning the ICT, ABM, and STEM tracks, alongside a separate spreadsheet screenshot suggestive of staff/employee credential exposure. The institution has not issued a public statement. This entry is recorded as 'unconfirmed' on the basis of the single threat-actor claim; specific account names, password hashes, and reference URLs are not reproduced on this site.

July 21, 2026On the order of 140 student records visible across the screenshots reviewed (name, student ID number, program/strand, and a hashed password per row), claimed by the threat actor; the post's own structure suggests the underlying list may be longer, and a separate screenshot suggests possible additional staff/employee credential exposure records affected

Key Facts

Date of Incident
July 21, 2026
Date Discovered
July 21, 2026
Records Affected
On the order of 140 student records visible across the screenshots reviewed (name, student ID number, program/strand, and a hashed password per row), claimed by the threat actor; the post's own structure suggests the underlying list may be longer, and a separate screenshot suggests possible additional staff/employee credential exposure
Source
Nullsec Philippines / N Z & friends (Facebook)
Data Types Exposed
Student full names, ID numbers, and program/strand codes (ICT, ABM, or STEM) (claimed)Hashed student account passwords, bcrypt format (claimed)A separate spreadsheet screenshot referencing an 'employeeID' field alongside hashed passwords, suggesting possible staff/administrative credential exposure (claimed)Defacement banner image ('HIT BY NULLSEC') (claimed)
Response / Action Taken

No public statement from the institution has been observed at the time of this entry. Status will be updated if and when the school, the National Privacy Commission, or independent reporting confirms the access vector, the authenticity of the claimed dataset, and remediation.

Single-source notice: This incident is based on a single public post by a self-identified threat actor. No mainstream news outlet has reported on it, no independent researcher has corroborated it, and the institution has not issued a public statement. The claim remains unverified and the institution's name has been redacted pending verification.

The post includes an extended enumeration of individual student records and a separate spreadsheet screenshot referencing hashed passwords. Neither the names and ID numbers nor any hash values are reproduced on this site, in line with the methodology of refusing to redistribute breach material.

What Happened

On July 21, 2026, a Facebook post attributed to the page "Nullsec Philippines" addressed a private computer college campus in Rizal province, tagging both the institution's main page and its Student Affairs and Services page. Rather than opening with a technical claim, the post began as an extended, second-person grievance narrative: it recalled specific unnamed staff — a staff member referred to only by role/initialism who was described as arrogant and dismissive of current students' technical ability, a second staff member described as withholding passing grades, and a staff member responsible for payments described as inflexible during exam periods, including a specific per-subject remedial fee — before closing the grievance section with a positive shout-out to a specific staff member by an affectionate nickname (withheld here). The post then pivoted: "So now, here's your chance to show whether what you teach about technology and defense can actually be applied when you're hit by a breach."

The post was signed "- N Z & friends," followed by a separate credit line naming a roster of handles, a stylized ASCII-art banner reading "HIT BY NULLSEC," and a multi-part enumeration of student records.

What the Post Reveals

  • A defacement-style marker. An ASCII-art text banner reading "HIT BY NULLSEC" appears directly beneath the grievance text, in a visual style consistent with prior Nullsec Philippines website defacements tracked on this site.
  • A large tabular listing of student records. Across the screenshots reviewed, the post enumerates on the order of 140 individual rows, each containing a student's full name, an ID number, an academic program/strand code (ICT, ABM, or STEM), and what appears to be a bcrypt-format hashed password. The list spans multiple alphabetical ranges consistent with a bulk export rather than a hand-picked sample, and the post's structure suggests the underlying list may extend beyond what was captured in the screenshots reviewed for this entry.
  • A second, smaller data screenshot. A separate spreadsheet-style screenshot in the same post shows a column header including what reads as "employeeID" alongside a hashed-password column, distinct in format from the student ID numbers in the main list. This raises the possibility that the exposure extends to a staff or administrative credential store rather than student records alone, though this cannot be confirmed from the material reviewed.
  • No stated access vector. The post does not describe how access was obtained, whether the data was pulled from a live database, an export file, or a backup, or how current the records are.

Why the Methodology Treats This as 'Unconfirmed'

This entry is fully anonymized and tagged as 'unconfirmed' because:

  • The only public source is the threat actor's own Facebook post
  • No corroborating media coverage has been observed
  • No NPC finding is available
  • No public statement has been issued by the institution
  • The claimed record count and the authenticity of the password hashes cannot be independently verified from a set of screenshots alone

If the institution issues a statement, if reputable Philippine technology media independently reports the incident, or if the NPC publishes a finding, this entry will be updated and de-anonymized in line with the SchoolBreach.org methodology.

Grievance Framing: A Vendetta Element Layered Onto a Hacktivist Claim

Most Nullsec Philippines posts tracked on this site open directly with a technical or data claim. This post is unusual in leading with an extended personal-grievance narrative — addressed in the second person to the institution, recalling specific unnamed staff and specific policies (grading, exam-period payment enforcement, a remedial-exam fee) in the manner of a former student, before pivoting to the breach claim as a rhetorical test of the institution's own teaching. That framing is consistent with the post being authored or co-authored by someone with direct personal history at the institution, which — if accurate — would also mean the actor may have, or have had, legitimate access credentials, direct knowledge of internal systems and staff, or both. This changes the threat model from a purely opportunistic external scan to one that may include insider or former-insider knowledge, which the institution's response should account for regardless of whether the technical claim is otherwise confirmed.

Threat-Actor Persona and Cross-References

The signature roster on this post is unusually dense. The greetz line names Lei$, Nostra, F33dler, Seve, Zhen, Tralalelo tralala, Invader, Cryptonymz, and Stax, in addition to the "N Z & friends" sign-off. Several of these are recurring handles already tracked on this site under slightly different stylizations: Nostra (as in the technical institute in Laguna defacement and the IBA College of Mindanao Inc. student-info claim, both signed "Nostra" or "Nostra & friends"), Zhen (consistent with 0x.Zh3n, co-signer of the private Catholic university in Mindanao PeopleSoft credential-extraction claim), Cryptonymz (consistent with Crypt0nymz, the persona behind the private school in Rosario, Batangas disclosure and the earliest-tracked private school in Tagum City breach), Seve (consistent with the recurring greetz name 0xSeve), and Invader (consistent with the recurring greetz name 1nv4d3r). F33dler, Tralalelo tralala, and Stax do not appear in any prior entry on this site and are logged here as newly observed handles associated with the collective.

The density of the roster — nine handles plus a separate sign-off — is itself notable. Prior Nullsec-linked posts tracked on this site are typically signed by one or two named personas with a shorter greetz list; a full-roster credit line here is consistent with either a genuinely collaborative operation or a single author invoking the wider collective's reputation. Either reading places this claim within the same continuing campaign documented elsewhere on this site rather than as an isolated, unaffiliated incident.

Why This Claim Warrants Attention

  • Scale. On the order of 140 individual student records are visible across the screenshots reviewed, spanning three academic strands/programs, with the post's own structure suggesting the total may be larger.
  • Credentials, not just directory data. Each row pairs a name and ID number with what appears to be a hashed password, meaning any successful offline crack of a weak or reused password would yield working account access, not just contact information.
  • Possible dual exposure. A second screenshot suggestive of an "employeeID"-keyed table raises the possibility that staff/administrative credentials are exposed alongside student data, which would broaden the incident's scope beyond the student information system.
  • Possible insider or former-insider knowledge. The grievance framing described above raises the possibility of a current or former insider, or someone with close personal knowledge of the institution's staff and policies — a different threat model than an anonymous external scan.
  • Multi-persona attribution. The breadth of the signature roster ties this claim to an active, ongoing campaign against Philippine schools rather than a one-off incident, per the cross-references above.

What Is Not Known

  • Whether the records are authentic and current. The name/ID/program/hash rows have not been independently verified; the dataset could be current, stale, partially fabricated, or drawn from a prior unrelated exposure.
  • The true scope of the dataset. Only the rows visible in the screenshots reviewed for this entry can be counted; the post's own framing implies the underlying list is longer.
  • Whether the "employeeID" screenshot belongs to the same system as the student list, a different system at the same institution, or an unrelated source entirely.
  • The access vector. The post does not state how the data was obtained.
  • Whether the institution is aware. No public statement has been observed, and it is not known whether the post has been reported to the institution privately.

Recommended Actions for the Institution

  1. 1.Treat the claim as credible until independently disproved. Begin incident response immediately rather than waiting for the access vector to be confirmed.
  2. 2.Rotate every credential category tied to the student information system, and to any staff/administrative system if the second screenshot is confirmed to reflect a real employee credential table.
  3. 3.Force a password reset for all affected students in the ICT, ABM, and STEM programs at minimum, and institution-wide if the employee-keyed table is confirmed to be part of the same exposure.
  4. 4.Audit authentication and database-access logs with at least a 90-day retention floor, given the grievance framing raises the possibility of access predating the post itself.
  5. 5.Review offboarding and account-deactivation procedures for former students and separated staff. The post's framing suggests the author(s) may be former students; confirm that portal accounts are deactivated promptly upon graduation, transfer, or withdrawal, and audit for stale accounts still capable of authenticating.
  6. 6.Notify the National Privacy Commission within 72 hours under Republic Act No. 10173. The legal trigger is risk to personal data, not certainty of exfiltration; names, ID numbers, and password hashes plainly meet that threshold.
  7. 7.Issue a same-day public advisory. Silence leaves the threat actor's framing as the only public narrative. The contrast example on this site is the Assumption College of Davao ICTC advisory.
  8. 8.Notify affected students of the credential exposure directly and require a password reset on next login, independent of whether the institution can confirm the dataset's authenticity beforehand.
  9. 9.Engage a forensic firm to determine whether the student and possible employee datasets share a common system or access path, and to establish dwell time.
  10. 10.Preserve evidence from the post — the account, the images, and any linked material — before it is altered or removed, for use in any NPC filing or law-enforcement referral.

How to Prevent This Pattern

  1. 1.Deactivate accounts on a fixed schedule tied to enrollment or employment status, not on an ad hoc basis, so that former students' or former staff's credentials cannot remain valid indefinitely.
  2. 2.Segregate student and staff/employee credential stores, so that a compromise of one does not automatically imply compromise of the other, and incident scoping is faster.
  3. 3.Enforce password complexity requirements and periodic rotation for portal accounts — a bcrypt hash is only as strong as the password it protects.
  4. 4.Apply rate limiting and anomaly monitoring to authentication endpoints to detect and slow bulk credential-stuffing or brute-force attempts against a leaked hash set.
  5. 5.Maintain a published security contact and responsible-disclosure policy, so that current or former students and staff with a grievance or a genuine security finding have a channel other than a public Facebook post.
  6. 6.Run recurring access reviews for any account tied to a current or former student, staff member, or contractor, independent of any specific incident.
RizalCALABARZONcomputer collegedatabase leakstudent recordscredential exposureNullsecPhilippinesNostra0x.Zh3nCrypt0nymzFacebookhacktivismvendettaunconfirmed2026

Related Incidents

Critical

A state university in Mindanao

May 10, 2026

Critical

A private Catholic university in Mindanao

June 2, 2026

Critical

A private IT-focused university chain in the Philippines

May 27, 2026

Know of a Breach?

Help us keep this tracker accurate and complete. Report school data breaches confidentially.

Report a Breach

Is This Entry Inaccurate?

If you represent the named institution or have evidence that corrects or updates this entry, you can request a correction or submit an official statement for publication.

We review all correction requests and respond within 5 business days. Verified corrections are applied promptly. Institutions may also submit a statement that will appear on this page as a right of reply.

Request a Correction

Protect Your School

Use our free tools and guides to assess your school's security posture.

Free Security ToolsGuides & Resources