SchoolBreach.org
BreachesTrendsToolsLearnAbout
Free Security Check
Security Check
SchoolBreach.org

A public resource tracking data breaches in Philippine schools. Helping administrators protect student data through awareness, education, and free security tools.

© 2026 SchoolBreach.org · A community service by OceanEd

Navigate

  • Breaches
  • Trends
  • Tools
  • Learn
  • Methodology

Company

  • About
  • Privacy Policy
  • Terms of Service
  • Contact Us

Disclaimer: This tracker is maintained for educational and awareness purposes. Incidents are documented using threat intelligence monitoring, Philippine media reports, NPC filings, and responsible disclosures. Social media platforms are monitored for leads and are corroborated before publication or naming — never through active scanning or exploitation. Severity ratings and summaries are prepared with AI assistance and reviewed editorially. Full methodology →

Back to Breach Tracker
Misconfiguration
CriticalUnconfirmed

A state university in Central Luzon

The name of this institution has been withheld pending verification of the source. This entry is based on an unconfirmed report.

On September 21, 2026, a Facebook post by 'Nullsec Philippines' — signed by the handle '0xTerror' — addressed a state university in Central Luzon and displayed what the actor presents as the contents of the institution's application environment file, retrieved over a publicly reachable URL. The pasted configuration includes an application framework encryption/signing key, credentials for two backend databases set to identical and easily guessable values, a database host address, and — most operationally significant — an Amazon SES SMTP username and password for the institution's no-reply email account. Specific keys, credentials, hostnames, addresses, and identifying URLs are not reproduced on this site. The institution has not issued a public statement. This entry is recorded as 'unconfirmed' on the basis of the single threat-actor claim; the institution name and all identifying values are redacted pending public confirmation.

September 21, 2026No record count claimed; the exposed file contained application, database, and email-service credentials rather than a dataset records affected

Key Facts

Date of Incident
September 21, 2026
Date Discovered
September 21, 2026
Records Affected
No record count claimed; the exposed file contained application, database, and email-service credentials rather than a dataset
Source
Nullsec Philippines / 0xTerror (Facebook)
Data Types Exposed
Application framework encryption/signing key from a publicly reachable environment file (claimed)Credentials for two backend databases — a student-portal/records subsystem and an enrollment/SMS subsystem — with identical, guessable username and password values (claimed)Database host address and related infrastructure details (claimed)Amazon SES (Simple Email Service) SMTP credentials for the institutional no-reply email account (claimed)A third-party vendor test-notification email address (claimed)
Response / Action Taken

No public statement from the institution has been observed at the time of this entry. Status will be updated if and when the school, the National Privacy Commission, or independent reporting confirms the authenticity of the exposed configuration, the exposure window, and remediation. The institution is urged to treat the email-service and database credentials referenced in the threat-actor post as compromised regardless of forensic verification status, given the immediate phishing-impersonation and direct-database-access risk.

Single-source notice: This incident is based on a single public post by a self-identified threat actor. No mainstream news outlet has reported on it, no independent researcher has corroborated it, and the institution has not issued a public statement. The claim remains unverified and the institution's name has been redacted pending verification.

What Happened

On September 21, 2026, the Facebook account using the name Nullsec Philippines publicly posted addressing a state university in Central Luzon. The post opened with the taunt "Your Website is a Piece of Cake" and was signed "~ 0xTerror".

The post pastes what the actor presents as the full contents of the institution's application environment file (a framework-style `.env` configuration), alongside a terminal screenshot showing the file being fetched with a command-line HTTP client against one of the institution's subsystem URLs. The framing is that the environment file was served in cleartext over the public web rather than being blocked from web access — a configuration mistake that exposes every secret the file contains at once.

What the Post Shows

The pasted configuration, taken at the category level (specific values are not reproduced on this site), includes:

  • An application framework encryption/signing key — the master key a framework of this type uses to encrypt sessions and sign cookies; its exposure can enable session forgery and decryption of framework-encrypted data
  • Two sets of database credentials — connection details for two separate backend databases, one described by its naming as a student-portal/records subsystem and one as an enrollment/SMS subsystem. Both are configured with a username and password set to the same short, guessable value
  • A database host address and related infrastructure details — the network location of the backend database tier
  • Amazon SES (Simple Email Service) SMTP credentials — an access-key-style username and secret for the institution's outbound no-reply email account, pointing at a regional Amazon SES SMTP endpoint
  • A third-party vendor test-notification email address — a contact at what appears to be an external development vendor, configured as the destination for test messages

The Most Operationally Significant Detail: The SMTP Credentials

Of everything in the file, the Amazon SES SMTP credentials are the most immediately weaponizable. The institution's no-reply address is the same channel through which students and staff legitimately receive password resets, enrollment notices, registration confirmations, and one-time codes. If the credential is authentic and unrotated, anyone holding it can:

  • Send mail as the institution through its own authorized email service
  • Pass standard authentication checks — messages relayed through the legitimate SES account are far more likely to satisfy SPF/DKIM/DMARC alignment than ordinary spoofing
  • Impersonate any institutional sender — IT helpdesk, registrar, faculty, or finance office — for precise, high-credibility phishing

The database credentials compound the risk: because the same short value is used for both username and password on two subsystems, the exposed file effectively hands over direct backend access, not merely a hint of it. The application key adds a third, independent avenue by undermining the integrity of the framework's own session and cookie protections.

Why the Methodology Treats This as 'Unconfirmed'

This entry is fully anonymized and tagged as 'Unconfirmed' because:

  • The only public source is the threat actor's own Facebook post
  • No corroborating media coverage has been observed
  • No NPC finding is available
  • No public statement has been issued by the institution

If the institution issues a statement, if reputable Philippine technology media independently reports the exposure, or if the NPC publishes a finding, this entry will be updated and de-anonymized in line with the SchoolBreach.org methodology.

Threat-Actor Persona and Cross-References

The post appears on the Nullsec Philippines page and is signed by 0xTerror. The handle 0xTerror recurs across the most operationally significant credential-exposure claims in the 2026 dataset: it co-signed the state university in Mindanao credential-exposure claim (May 10, 2026), which likewise centered on an SMTP master key for a no-reply account, and the private Catholic university in Mindanao PeopleSoft credential-extraction claim (June 2, 2026), and it signed the private university in Cebu City subdomain defacement (April 1, 2026). This is a Nullsec-collective claim, not an unaffiliated emerging actor.

Why This Claim Warrants Attention

  • Single-file, total-secret exposure. A publicly reachable environment file is not a partial leak — it exposes application, database, and email secrets simultaneously, so one misconfiguration compromises multiple systems at once.
  • Live email-impersonation capability. If the SES credentials are authentic and unrotated, the incident converts from a one-time exposure into an ongoing institution-wide phishing capability against students and staff.
  • Weak-by-design database credentials. Reusing one short value as both username and password across two subsystems means the exposed file is directly usable, and would have been trivially guessable even without the leak.
  • Vendor exposure. The presence of an external vendor's test-notification contact suggests a third-party developer relationship whose access and other deployments should also be reviewed.

What Is Not Known

  • Authenticity. Whether the pasted configuration is genuine, current, or already rotated has not been independently verified.
  • Whether the credentials have been used. There is no public indication of whether the SES account or databases have already been accessed by an unauthorized party.
  • Exposure window. How long the environment file was publicly reachable, and whether other parties retrieved it, is unknown.
  • Data impact. The post is a credential/configuration exposure, not a dataset claim; whether any records were accessed through the exposed credentials is not stated.
  • Notification status. Whether the institution, its vendor, the National Privacy Commission, or Amazon Web Services have been notified is unknown.

Recommended Actions for the Institution

  1. 1.Rotate the Amazon SES SMTP credentials immediately and audit recent outbound mail from the no-reply account for messages the institution did not originate. Treat the credential as compromised regardless of forensic verification, given the immediate impersonation risk.
  2. 2.Rotate the application framework encryption/signing key and invalidate existing sessions and signed cookies; plan for the re-encryption of any data protected by the old key.
  3. 3.Change every database credential in the exposed file and replace the reused short value with distinct, strong, per-account secrets; confirm the databases are not reachable directly from the public internet.
  4. 4.Remove the environment file from public web access and audit the web-server configuration so dotfiles and configuration files cannot be served under the web root across all subsystems.
  5. 5.Review web-server and database access logs for retrieval of the environment file and for any unauthorized database or SES activity during the exposure window.
  6. 6.Review the third-party vendor relationship implied by the test-notification contact, including that vendor's access and any other deployments it manages for the institution.
  7. 7.Notify the National Privacy Commission within 72 hours under RA 10173 if any personal data was accessible through the exposed credentials — the materiality assessment should assume the credentials were usable until proven otherwise.
  8. 8.Issue a same-day public advisory. Silence in the face of a public, specific claim leaves the threat actor's framing as the only public narrative. The contrast example on this site is the Assumption College of Davao ICTC advisory.

How to Prevent This Pattern

  1. 1.Keep secrets out of web-served paths. Store configuration outside the document root, and configure the web server to deny requests for dotfiles and configuration files by default.
  2. 2.Never reuse a value as both username and password, and never ship placeholder or "admin/admin"-style credentials into a live deployment.
  3. 3.Scope email-service credentials tightly and monitor SES/SMTP send volume and reputation for anomalies that indicate credential misuse.
  4. 4.Rotate framework keys and service credentials on a schedule and immediately upon any suspected exposure.
  5. 5.Scan public endpoints for exposed configuration files as part of routine security testing, and fold third-party vendors into that scanning scope.
  6. 6.Publish a security contact and responsible-disclosure policy. Researchers should have a private channel; absent one, they have only the public-Facebook-post channel.
Central Luzonstate universitymisconfigurationexposed environment filecredential exposureSMTP credentialsphishing riskweak credentialsNullsecPhilippines0xTerrorFacebookhacktivismunverifiedunconfirmed2026

Related Incidents

High

A state university in Mindanao

August 4, 2026

Critical

A state university in Mindanao

May 10, 2026

Critical

A private medical college in Cebu City

July 23, 2026

Know of a Breach?

Help us keep this tracker accurate and complete. Report school data breaches confidentially.

Report a Breach

Is This Entry Inaccurate?

If you represent the named institution or have evidence that corrects or updates this entry, you can request a correction or submit an official statement for publication.

We review all correction requests and respond within 5 business days. Verified corrections are applied promptly. Institutions may also submit a statement that will appear on this page as a right of reply.

Request a Correction

Protect Your School

Use our free tools and guides to assess your school's security posture.

Free Security ToolsGuides & Resources