SchoolBreach.org
BreachesTrendsToolsLearnAbout
Free Security Check
Security Check
SchoolBreach.org

A public resource tracking data breaches in Philippine schools. Helping administrators protect student data through awareness, education, and free security tools.

© 2026 SchoolBreach.org · A community service by OceanEd

Navigate

  • Breaches
  • Trends
  • Tools
  • Learn
  • Methodology

Company

  • About
  • Privacy Policy
  • Terms of Service
  • Contact Us

Disclaimer: This tracker is maintained for educational and awareness purposes. Incidents are documented using threat intelligence monitoring, Philippine media reports, NPC filings, and responsible disclosures. Social media platforms are monitored for leads and are corroborated before publication or naming — never through active scanning or exploitation. Severity ratings and summaries are prepared with AI assistance and reviewed editorially. Full methodology →

Back to Breach Tracker

Breach Trends

Analysis of 92 documented school data breaches across the Philippines from 2012 to 2026.

Key Finding: Attacks Are Escalating — and Most Never Reach the News

  • We logged 39 incidents in 2026 through September 2 — more than any earlier year in this tracker, but not a like-for-like record. See the caveat below before reading that as a spike in attacks.
  • Attack scale is the clearest real escalation: the three largest incidents ever tracked — DepEd Laguna (7M+), DepEd CAR (6M+), and DepEd Ilocos Norte/Aurora (3M+) — all landed within a single quarter of 2025, and each was large enough that it could not stay out of the press.
  • Among incidents we can see, no single vector dominates 2026: it spreads across 5 different attack types, with database leaks, defacements, and unauthorized access running in parallel.
  • Universities and colleges are hit most often (69 of 92 tracked incidents), but DepEd offices account for the largest exposures — 13 incidents holding the great majority of all records tracked.
  • One compromise, many schools is the defining 2026 pattern — web shells on shared hosting, plus shared student-information-system and LMS vendors, let a single foothold reach multiple institutions at once. Learn more →

Why 2026's count is not a like-for-like record. Incidents before 2026 were reconstructed from mainstream news coverage, because that reporting was our only source at the time — so a breach that never got written up was never counted. From 2026 we monitor in real time and catch incidents that never reach the press, which is most of them: 77% of this year's entries have no source beyond the attacker's own post. Earlier years are therefore undercounts of unknown size, and the rise on this page measures how much we can see at least as much as how much is happening. The honest reading is that 2026 is the first year counted properly — not provably the worst.

The Philippines Is a Top Target

106
breached accounts per 100 people in the Philippines — more than double the Asian average of 52
Source: Surfshark Research, 2024
124M
total accounts breached in the Philippines — 2nd highest in Southeast Asia
Source: Surfshark Research, 2024
3 accounts
hacked every minute in the Philippines — a relentless tide of data breaches
Source: Straits Times, 2025
6%
of Philippine organizations are mature enough to repel cyberattacks — up from 1% in 2024, but 54% are still in the bottom two readiness stages
Source: Cisco, 2025
4th
in the world for most cyberattack incidents, with government and education among the top targets
Source: DICT, 2023
0.04%
of GDP spent on cybersecurity — nearly half the ASEAN average of 0.07%
Source: National Cybersecurity Plan 2028, 2023

Filipinos Don't Stay Silent After a Breach

24%
took legal action
21%
closed their account
18%
exposed it on social media

Among Filipinos who suffered a data breach, these were the most common responses. The Philippines ranked #1 in cybersecurity concern (234/300) among 13 countries surveyed.

Source: Unisys Security Index, 2019

The average Filipino email has been breached almost 3 times (Surfshark Research). The Philippines needs 180,000 more cybersecurity professionals (ISC² Cybersecurity Workforce Study). Schools — which hold sensitive data on minors — are especially at risk.

Breaches by Year

Click a point to filter the breach list by year. Hover for details.

010203039121314151617181920212223242526

How to read this chart: year-over-year counts are not directly comparable, and the bars for earlier years are floors rather than totals. Incidents from before 2026 were catalogued retrospectively and recorded only when a reputable source — media, the National Privacy Commission, or the school itself — confirmed them, so those years capture only the breaches that were reported. Any incident that never made the news left no record for us to find, which means every pre-2026 bar undercounts its year by an unknown amount. From 2026 incidents are tracked in real time, which also includes those whose only source is an unverified threat-actor post — a category earlier years structurally never recorded. 77% of 2026 entries are anonymized for exactly that reason (their only source is a threat-actor claim), versus 0% in 2020. Read the 2026 rise primarily as a change in visibility; how much of it is a genuine increase in attacker activity cannot be separated out from this data alone.

Records Affected by Year

Based on confirmed/claimed record counts. "Unknown" counts are excluded. Hover for exact totals.

2012
0
2013
0
2014
0
2015
0
2016
0
2017
0
2018
0
2019
2K
2020
401K
2021
23K
2022
2K
2023
0
2024
210K
2025
16.6M
2026
2.6M

Average Records Per Incident

Average number of records exposed per breach each year. Shows how breach scale is escalating — not just frequency. Years with no quantified records are excluded.

2012
—
2013
—
2014
—
2015
—
2016
—
2017
—
2018
—
2019
2K
2020
201K
2021
23K
2022
2K
2023
—
2024
210K
2025
1.8M
2026
164K

How Attack Types Shifted

Each bar shows the mix of attack types for that year. Hover to see the breakdown.

2012
1
1
2013
1
1
2014
1
1
2015
1
1
2019
1
1
2020
21
28
2021
1
1
2022
1
1
1
3
2023
1
1
2024
1
1
2
2025
3
10
13
2026
9
13
9
39
Unauthorized Access
Database Leak
Website Defacement
Data Exposure
Misconfiguration
Ransomware

By Attack Type

Hover to see share of total. Click to filter the breach list.

Unauthorized Access37(40%)
Database Leak28(30%)
Website Defacement16(17%)
Data Exposure9(10%)
Misconfiguration1(1%)
Ransomware1(1%)

By Severity

Hover a severity level to see its definition. Click to filter the breach list.

Critical23 (25%)
High36 (39%)
Medium30 (33%)
Low3 (3%)

64% of all breaches are rated Critical or High severity.

Who Gets Targeted

DepEd offices vs. universities & colleges vs. other institutions.

75%
14%
University / College69 (75%)
DepEd13 (14%)
Other10 (11%)

Breach Status

Resolution status of all tracked breaches. Click to filter.

Resolved46 (50%)
Confirmed21 (23%)
Investigating11 (12%)
Unconfirmed14 (15%)

Most Exposed Data Types

What kinds of data are leaked most often across all breaches. Shows the top 15 categories.

Website content20
Student personal information13
Email addresses12
Student portal data11
Student names9
Full names6
Usernames5
Student numbers4
Birth dates4
Student ID numbers3
Gender3
Section3
Phone numbers3
Personal data3
Database contents3

+ 274 more data types

By Region

Hover to see each region's share of total incidents.

National Capital Region23
CALABARZON15
Central Visayas7
National7
Central Luzon7
Davao Region6
Bicol Region5
Western Visayas5
Northern Mindanao4
Caraga3
Ilocos Region3
Eastern Visayas3
MIMAROPA2
CAR2
Cagayan Valley1
BARMM1

Timeline Highlights

2012

First Documented Incident

Chinese hackers defaced the University of the Philippines System website amid the Scarborough Shoal standoff — the earliest known cyberattack on a Philippine educational institution.

2013

First Multi-Target Attack

Two schools and a municipal government in Bohol were hacked and defaced — an early sign that educational institutions were becoming regular targets.

2014

Hacktivism Hits Higher Education

Ateneo Law School's Student Access Module was hacked by AnonCalapan (AnonGhost Philippines), leaking student credentials. The politically motivated attack was part of a broader wave of Philippine hacktivism tied to Typhoon Yolanda criticism.

2015

Geopolitical Hacktivism Continues

Chinese hacker group 1937 CN Team defaced the Philippine Public Safety College website over the South China Sea dispute — continuing a pattern of politically motivated attacks on Philippine institutions.

2019

First Major Data Breach

University of the East breach — 1,572 records exposed via unauthorized access. An early warning sign of data-focused attacks.

2020

Mass Hacking Wave

28 breaches in a single year — by far the worst on record. Hacktivist groups like Pinoy Grayhats targeted university portals nationwide in a mass hacking wave hitting 20+ institutions. San Beda saw 400,000+ plaintext credentials exposed.

2022

Ransomware Arrives

University of Perpetual Help hit by ransomware — marking a shift to more destructive, monetized attacks.

2023

Major University Targeted

De La Salle University experienced a cyberattack, showing even well-resourced institutions are vulnerable.

2024

DepEd Under Fire

DepEd OVAP database exposed 210,000+ records. A separate 750GB alleged breach surfaced, targeting government education systems.

2025

Explosion in Scale

13 breaches with millions of records. DepEd Laguna (7M+), DepEd CAR (6M+), and DepEd Ilocos Norte/Aurora (3M+) leaks show systemic vulnerability. Database leaks replace unauthorized access as the dominant attack type.

2026

Real-Time Tracking Begins — and the Record Fills In

39 breaches recorded through September 2 2026, more than any earlier year here — though this is the first year we monitored continuously rather than reconstructing from news coverage, so it is not comparable to the 28 logged in 2020. The Nullsec Philippines / Fawkes Pilipinas / Crypt0nymz collective has driven a sustained, near-daily campaign spanning DepEd offices, state universities, private colleges, K-12 institutions, and technical institutes. The tradecraft broadened over the year: shared-hosting web shells, shared-vendor (SIS and LMS) supply-chain exposures, credential extraction from enterprise platforms, and misconfigured admin tooling leaking source and data. A claimed 685K-record leak in March and a ~1M-row DepEd training-platform CSV in May are the largest single exposures. Attackers have explicitly stated they hold access to additional sister schools they have not yet posted.

The Silence Problem

The proportion of breaches we cannot publicly attribute to a named institution has grown sharply. In 2020, the busiest year in our retrospective record, every documented breach was independently confirmed by media, the National Privacy Commission, or the affected institution itself — 0% were anonymized. In 2026, that figure is 77%. The shift is structural, not stylistic: an increasing share of the public record is now sourced solely from threat-actor posts, and our methodology requires those incidents to be anonymized until an independent source corroborates the claim.

2020 (busiest retrospective year)
0%
of 28 documented breaches were anonymized — every incident was independently corroborated and the institution could be named
2026 (year-to-date)
77%
of 39 documented breaches are anonymized — sourced only from threat-actor posts, with no school statement, no NPC finding, and no media coverage to corroborate

Why this matters

Anonymization is a methodological floor, not an editorial preference: when the only public evidence is a threat actor's own post, naming the institution would amplify an unverified claim. But the consequence at scale is that 35% of all entries on this tracker are currently shadow records — incidents we know about internally but cannot publicly attribute, because the affected school has not acknowledged them.

The downstream effects are concrete. Students and parents cannot reset reused passwords or watch for targeted phishing tied to data they don't know is circulating. Other schools in the same vendor cluster cannot harden against vulnerabilities they cannot identify. The National Privacy Commission cannot enforce the 72-hour notification obligation under RA 10173 on incidents it has not been informed of. And the public record of Philippine school cybersecurity is, increasingly, written by the attackers rather than by the institutions they target.

Don't Wait for a Breach

These free tools and guides can help your school close the gaps these trends reveal.

DPA Compliance Checker

Score your school's Data Privacy Act compliance in minutes.

School Security Scorecard

Rate your school's cybersecurity across 8 domains and get an action plan.

Understanding Ransomware

How ransomware works and what school admins need to know before it hits.

View all free security tools →|Browse all guides & articles →