SchoolBreach.org
BreachesTrendsToolsLearnAbout
Free Security Check
Security Check
SchoolBreach.org

A public resource tracking data breaches in Philippine schools. Helping administrators protect student data through awareness, education, and free security tools.

© 2026 SchoolBreach.org · A community service by OceanEd

Navigate

  • Breaches
  • Trends
  • Tools
  • Learn
  • Methodology

Company

  • About
  • Privacy Policy
  • Terms of Service
  • Contact Us

Disclaimer: This tracker is maintained for educational and awareness purposes. Incidents are documented using threat intelligence monitoring, Philippine media reports, NPC filings, and responsible disclosures. Social media platforms are monitored for leads and are corroborated before publication or naming — never through active scanning or exploitation. Severity ratings and summaries are prepared with AI assistance and reviewed editorially. Full methodology →

Back to Breach Tracker
Data Exposure
HighConfirmed

Technological University of the Philippines - Manila

On July 4 and July 5, 2026, the Facebook account 'Nullsec Philippines' addressed the Technological University of the Philippines - Manila (TUP Manila) admissions office directly, first sharing a screenshot of dozens of applicant photographs and then a follow-up post sharing a password-protected cloud-storage folder said to contain a larger set of the same. On July 9, 2026, TUP Manila's University Student Government (USG) published a public 'Update and Statement' acknowledging reports received on July 6 of 'alleged unauthorized access' to Applicant ERS (admissions) information, and stating that the University Information Technology Center (UITC) — TUP's official IT unit — opened an investigation the same day that remains ongoing. The USG statement is a student-government publication rather than a release from TUP's central administration or communications office, but it relays UITC's own acknowledgment that a report was received and is under active investigation, which is sufficient public corroboration under SchoolBreach.org's methodology to de-anonymize this entry and move its status from 'unconfirmed' to 'confirmed.'

July 4, 2026Manila, Metro Manila, National Capital RegionUndetermined; a partial screenshot showed roughly 90 applicant photographs, and the threat actor's follow-up post claims the shared archive represents only 'half' of the full set held records affected

Key Facts

Date of Incident
July 4, 2026
Date Discovered
July 5, 2026
Records Affected
Undetermined; a partial screenshot showed roughly 90 applicant photographs, and the threat actor's follow-up post claims the shared archive represents only 'half' of the full set held
Source
Nullsec Philippines / Nostra (Facebook); TUP University Student Government (Facebook statement, July 9, 2026)
Data Types Exposed
Applicant photographs following an admissions-batch filename pattern (claimed)A larger archive of the same, offered via an encrypted cloud-storage folder with a separately-published decryption key (claimed, not independently verified)
Response / Action Taken

On July 9, 2026, TUP Manila's University Student Government (USG) published a public 'Update and Statement' on Facebook acknowledging reports received on July 6, 2026 of 'alleged unauthorized access' to Applicant ERS (admissions) information, and stating that the University Information Technology Center (UITC) opened an investigation the same day that remains ongoing. The USG statement is a student-government publication, not a release from TUP's central administration or communications office, but it relays UITC's own acknowledgment that a report was received and is under active investigation. SchoolBreach.org has de-anonymized this entry and moved its status from 'unconfirmed' to 'confirmed' on the basis of that acknowledgment, per the methodology's right-of-reply framework, while noting that the statement itself does not confirm the specific applicant-photograph claim, name an access vector, or state a scope of affected records. This entry will be updated further if TUP's central administration issues its own statement, if UITC's findings are published, or if the National Privacy Commission opens proceedings.

Institution Statement

On July 9, 2026, TUP Manila's University Student Government (USG) published an "Update and Statement" on its official Facebook page addressing "the alleged unauthorized access of the Applicant ERS information." The full text, reproduced verbatim:

"UPDATE AND STATEMENT | ON THE ALLEGED UNAUTHORIZED ACCESS OF THE APPLICANT ERS INFORMATION

The University Student Government (USG) recognizes the concerns raised by members of the student body regarding the alleged unauthorized access to Applicant ERS information. We acknowledge the seriousness of this matter and the importance of protecting the privacy and security of student information.

Upon receiving reports of the alleged incident on Monday, July 6, 2026, the USG immediately coordinated with the University Information Technology Center (UITC) to seek clarification and request immediate updates regarding the matter.

The UITC confirmed that an investigation was initiated on the same day the report was received. As of this writing, the investigation remains ongoing to verify the circumstances surrounding the alleged incident and determine the appropriate findings based on the available evidence.

ON THE STATUS OF THE INVESTIGATION

The USG continues to coordinate closely with the UITC and has formally requested a copy of the official investigation report for proper dissemination to the student body.

According to the UITC, the official findings will first be submitted to the appropriate University offices as part of the administrative process. Once completed, a copy of the official report will be provided to the USG for dissemination.

The USG remains committed to transparency, accountability, and responsible communication. We will continue to coordinate with the concerned offices and ensure that only verified and official information is shared to prevent speculation and misinformation.

We also encourage everyone to remain vigilant in protecting their personal information. Please exercise caution when responding to unsolicited emails, messages, links, or calls requesting sensitive personal details, and rely only on official announcements from the University and the USG regarding this matter."

The statement is published by TUP Manila's University Student Government, a recognized student-governance body, rather than by TUP's central administration or official communications office. It does not itself confirm the specific applicant-photograph claim made in the Nullsec Philippines posts below, and it frames the underlying access as "alleged" pending UITC's findings. What the statement does establish, in the institution's own words, is that: (1) a report of unauthorized access to Applicant ERS information was received on July 6, 2026; (2) UITC — TUP's official IT unit — opened an investigation the same day; and (3) that investigation was still active as of the statement's publication. That is an administrative acknowledgment relayed through the USG, not merely student speculation, and is the basis for treating this entry as institutionally corroborated.

Per SchoolBreach.org's right-of-reply policy, this statement is published in full and unedited. TUP is invited to provide updated statements — including directly from its central administration — as the UITC investigation progresses; updates will be appended above this entry's existing record.

What Happened

On July 4, 2026, the Facebook account using the name Nullsec Philippines publicly posted addressing TUP Manila's admissions office by name, captioned "The applicants are being affected because of your negligence." The post attached a screenshot showing a grid of applicant photographs with filenames following a consistent admissions-batch numbering pattern, watermarked with the group's logo. The same screenshot included two smaller inset images: a post from a separate, unrelated hacking-forum account also using the handle "nostra," soliciting direct messages for a data sample, and a close-up of the group's own logo.

On July 5, 2026, roughly seven hours before this entry's original screenshots were captured, the same account posted a follow-up addressed to TUP by name, captioned in Tagalog "happy to share with u [TUP] kalahati lang pampagising sa developer" — loosely, "just half, enough to wake up the developer." The post included a link to a cloud-storage folder and a plaintext decryption key, and was signed "- Nostra." The attached image was a photo of TUP's official seal on a black background; no data screenshot accompanied this second post.

Both posts were public, drew modest engagement (roughly a dozen to twenty reactions and a handful of comments each), and remained visible on the group's page as of the time of this entry.

On July 6, 2026 — the Monday after the second Nullsec post — TUP's USG states it received reports of the alleged incident and coordinated with UITC, which opened an investigation the same day. The USG published its public update three days later, on July 9, 2026.

What the Posts Show

  • A photo grid — the first post's screenshot displays dozens of individual headshot-style photographs, each named with a sequential filename that appears to encode an admissions batch and applicant number.
  • A claim of a larger archive — the second post's caption asserts that the publicly shared folder is only half of what the threat actor holds, implying an additional, unreleased portion of the same dataset.
  • A cross-platform presence — the inset screenshot in the first post shows a hacking-forum account using the same "nostra" handle, with a membership tenure of roughly ten months on that forum, soliciting private-message contact for a data sample. This indicates the persona operates a presence beyond the Facebook page tracked here.
  • No credential or system-access claim — neither post describes an access vector, names an affected subsystem, or claims database or administrative-account compromise. The claim is limited to possession and redistribution of a set of applicant photographs.

Why This Entry Is Now Confirmed and Named

This entry was originally published anonymized and tagged "unconfirmed" because its only source was a single threat actor's own Facebook posts. On July 9, 2026, that changed:

  • TUP Manila's University Student Government publicly posted, under its own name, an acknowledgment that a report of unauthorized access to Applicant ERS information was received on July 6, 2026
  • The statement relays a specific action taken by UITC — TUP's official IT unit — opening an investigation the same day, which is an administrative acknowledgment, not merely student speculation
  • Per SchoolBreach.org's methodology, a public statement from the institution (including a recognized student-governance body relaying an administrative office's action) is sufficient to de-anonymize an entry and move it to "confirmed" status, regardless of whether the statement corroborates every particular of the original threat-actor claim

What the July 9 statement does not do is confirm the applicant-photograph claim specifically, name an access vector, or state a scope of affected records. Those questions remain open pending UITC's findings.

Threat-Actor Persona and Cross-References

The second post is signed "- Nostra," the same sign-off style used in the St. Ignatius Technical Institute of Business and Arts Cabuyao Campus defacement claim (May 2, 2026), which was also a one-line Nullsec Philippines post signed identically. The handle "Nostra" and its variants ("N0STR4," "Nostra & Friends") recur throughout the Nullsec Philippines campaign documented on this site, including greetz lines on the state university in Nueva Vizcaya CAT applicant claim (May 1, 2026) and the private school in Rosario, Batangas claim (April 28, 2026).

This entry's subject matter — a public claim of exposed admissions-applicant photographs — most closely parallels the Nueva Vizcaya CAT-portal entry, though that earlier claim showed a single applicant's session while this one displays a larger batch grid with no visible session or portal chrome, making the underlying access vector (misconfigured storage versus an authenticated portal session) less clear from the public post alone.

Why This Claim Warrants Attention

  • Bulk applicant imagery, not a single account. Unlike prior single-applicant claims tracked on this site, the screenshot here shows dozens of individuals at once, and the threat actor states more is withheld — if genuine, this points to exposure at the storage or batch-export level rather than a single compromised session.
  • A stated intent to escalate. The "half now" framing in the second post signals the threat actor is deliberately staging a partial release, a pattern associated with pressuring an institution rather than a one-off disclosure.
  • Applicants, not enrolled students, are affected. Prospective students who may have no other relationship with the institution yet are named as the affected population, widening the pool of individuals who would need to be notified if the claim is authentic.
  • A cross-platform footprint. The same handle's presence on a separate hacking forum suggests the material may already be circulating, or being offered, outside the Facebook post visible here.

What Is Not Known

  • Whether the photographs are authentic and current. No independent party has confirmed the images originate from TUP's admissions system rather than being recycled from an older or unrelated source.
  • The access vector. Nothing in the public posts or the USG statement describes how the photographs were obtained — an exposed storage bucket, a compromised admissions-portal account, or a leaked internal export are all consistent with what has been shown.
  • The true scope of the dataset. The claim that the shared folder is "half" of what is held is unverified and could be exaggerated for effect.
  • UITC's findings. The investigation was still ongoing as of the USG's July 9 statement; no official findings had been released to the student body or the public at that time.

Recommended Actions for the Institution

  1. 1.Determine whether the admissions applicant-photo directory is or was exposed. Audit the storage location, hosting configuration, and access logs for the admissions system that generates or stores applicant photographs.
  2. 2.Preserve forensic evidence immediately, if not already captured as part of UITC's ongoing investigation. Capture logs, storage-access records, and any available object-versioning history before they age out of retention.
  3. 3.Audit third-party and developer access. The threat actor's own framing ("pampagising sa developer") suggests a vendor- or developer-managed system may be implicated; review any external contractor's access scope and credentials.
  4. 4.Notify the National Privacy Commission within 72 hours under RA 10173, if not already done. The legal trigger is risk to personal data, not certainty of exfiltration — a claim involving applicant photographs of this scale meets that threshold.
  5. 5.Publish UITC's findings once the investigation concludes, through TUP's central administration or communications office in addition to the USG's channel, so the public record includes an official institutional account rather than only a student-government relay.
  6. 6.Rotate credentials for any system that could plausibly generate or serve the affected images, including admissions-portal service accounts and any developer or vendor accounts with storage access.
  7. 7.Extend log retention to at least 90 days for the affected system given the apparent multi-week or longer dwell time implied by a bulk export of this kind.
  8. 8.Prepare applicant-facing communication in the event the claim is substantiated, given that applicants — not currently-enrolled students — are the affected population and may not otherwise expect to hear from the institution.

How to Prevent This Pattern

  1. 1.Treat admissions-applicant photo directories as sensitive personal data, not incidental assets, with the same access controls applied to grade or financial records.
  2. 2.Avoid predictable, sequential filename schemes for applicant-submitted images; sequential batch numbering makes bulk enumeration and scraping trivial once any single file is reachable.
  3. 3.Restrict developer and vendor access to production applicant data, using de-identified or synthetic data in development and staging environments instead.
  4. 4.Publish a security contact and responsible-disclosure policy. Researchers and even hacktivist actors default to public Facebook posts when there is no private channel to route a finding to.
  5. 5.Conduct periodic external exposure scans of storage buckets, admissions-portal endpoints, and developer-facing subdomains to catch misconfigurations before they are publicly disclosed.

Institution Statement

Right of Reply — Official statement from the named institution

UPDATE AND STATEMENT | ON THE ALLEGED UNAUTHORIZED ACCESS OF THE APPLICANT ERS INFORMATION The University Student Government (USG) recognizes the concerns raised by members of the student body regarding the alleged unauthorized access to Applicant ERS information. We acknowledge the seriousness of this matter and the importance of protecting the privacy and security of student information. Upon receiving reports of the alleged incident on Monday, July 6, 2026, the USG immediately coordinated with the University Information Technology Center (UITC) to seek clarification and request immediate updates regarding the matter. The UITC confirmed that an investigation was initiated on the same day the report was received. As of this writing, the investigation remains ongoing to verify the circumstances surrounding the alleged incident and determine the appropriate findings based on the available evidence. ON THE STATUS OF THE INVESTIGATION The USG continues to coordinate closely with the UITC and has formally requested a copy of the official investigation report for proper dissemination to the student body. According to the UITC, the official findings will first be submitted to the appropriate University offices as part of the administrative process. Once completed, a copy of the official report will be provided to the USG for dissemination. The USG remains committed to transparency, accountability, and responsible communication. We will continue to coordinate with the concerned offices and ensure that only verified and official information is shared to prevent speculation and misinformation. We also encourage everyone to remain vigilant in protecting their personal information. Please exercise caution when responding to unsolicited emails, messages, links, or calls requesting sensitive personal details, and rely only on official announcements from the University and the USG regarding this matter.

Sources & References

All sources are independently verified. Access dates and archive links are recorded for each citation.

  1. [1]
    Nullsec Philippines — applicant photo grid post (Facebook, July 4, 2026) — Facebook post naming TUP Manila's admissions office directly, captioned 'The applicants are being affected because of your negligence,' with an attached screenshot of dozens of applicant photographs. Not reproduced on this site.
    Accessed: July 5, 2026
  2. [2]
    Nullsec Philippines — cloud-storage folder follow-up post (Facebook, July 5, 2026) — Follow-up Facebook post naming TUP, signed '- Nostra,' containing a link to a cloud-storage folder and a decryption key. Neither the link nor the key is reproduced on this site.
    Accessed: July 5, 2026
  3. [3]
    TUP USG Manila — "Update and Statement" on the alleged unauthorized access of Applicant ERS information (Facebook, July 9, 2026) — TUP Manila's University Student Government publicly acknowledges reports received July 6, 2026 of alleged unauthorized access to Applicant ERS information, and states that the University Information Technology Center (UITC) opened an investigation the same day that remains ongoing.
    Accessed: July 11, 2026
TUPTechnological University of the PhilippinesTUP ManilaMetro ManilaNational Capital Regionstate universityadmissions portaldata exposureapplicant photosNullsecPhilippinesNostraFacebookhacktivismschool statement2026

Related Incidents

High

A state university in Mindanao

August 4, 2026

Medium

A private university in Metro Manila

July 14, 2026

Critical

A private medical college in Cebu City

July 23, 2026

Know of a Breach?

Help us keep this tracker accurate and complete. Report school data breaches confidentially.

Report a Breach

Is This Entry Inaccurate?

If you represent the named institution or have evidence that corrects or updates this entry, you can request a correction or submit an official statement for publication.

We review all correction requests and respond within 5 business days. Verified corrections are applied promptly. Institutions may also submit a statement that will appear on this page as a right of reply.

Request a Correction

Protect Your School

Use our free tools and guides to assess your school's security posture.

Free Security ToolsGuides & Resources