Analysis of 90 documented school data breaches across the Philippines from 2012 to 2026.
Among Filipinos who suffered a data breach, these were the most common responses. The Philippines ranked #1 in cybersecurity concern (234/300) among 13 countries surveyed.
The average Filipino email has been breached almost 3 times (Surfshark Research). The Philippines needs 180,000 more cybersecurity professionals (ISC² Cybersecurity Workforce Study). Schools — which hold sensitive data on minors — are especially at risk.
Click a point to filter the breach list by year. Hover for details.
How to read this chart: year-over-year counts are not directly comparable. Incidents from before 2026 were catalogued retrospectively and recorded only when a reputable source — media, the National Privacy Commission, or the school itself — confirmed them, so earlier years capture only acknowledged breaches. 2026 is tracked in real time and also includes incidents whose only source is an unverified threat-actor post — a category earlier years structurally never recorded. 76% of 2026 entries are anonymized for exactly that reason (their only source is a threat-actor claim), versus 0% in 2020. The steep 2026 rise therefore reflects both increased attacker activity and wider, faster detection.
Based on confirmed/claimed record counts. "Unknown" counts are excluded. Hover for exact totals.
Average number of records exposed per breach each year. Shows how breach scale is escalating — not just frequency. Years with no quantified records are excluded.
Each bar shows the mix of attack types for that year. Hover to see the breakdown.
Hover to see share of total. Click to filter the breach list.
Hover a severity level to see its definition. Click to filter the breach list.
63% of all breaches are rated Critical or High severity.
DepEd offices vs. universities & colleges vs. other institutions.
Resolution status of all tracked breaches. Click to filter.
What kinds of data are leaked most often across all breaches. Shows the top 15 categories.
+ 261 more data types
Hover to see each region's share of total incidents.
Chinese hackers defaced the University of the Philippines System website amid the Scarborough Shoal standoff — the earliest known cyberattack on a Philippine educational institution.
Two schools and a municipal government in Bohol were hacked and defaced — an early sign that educational institutions were becoming regular targets.
Ateneo Law School's Student Access Module was hacked by AnonCalapan (AnonGhost Philippines), leaking student credentials. The politically motivated attack was part of a broader wave of Philippine hacktivism tied to Typhoon Yolanda criticism.
Chinese hacker group 1937 CN Team defaced the Philippine Public Safety College website over the South China Sea dispute — continuing a pattern of politically motivated attacks on Philippine institutions.
University of the East breach — 1,572 records exposed via unauthorized access. An early warning sign of data-focused attacks.
28 breaches in a single year — by far the worst on record. Hacktivist groups like Pinoy Grayhats targeted university portals nationwide in a mass hacking wave hitting 20+ institutions. San Beda saw 400,000+ plaintext credentials exposed.
University of Perpetual Help hit by ransomware — marking a shift to more destructive, monetized attacks.
De La Salle University experienced a cyberattack, showing even well-resourced institutions are vulnerable.
DepEd OVAP database exposed 210,000+ records. A separate 750GB alleged breach surfaced, targeting government education systems.
13 breaches with millions of records. DepEd Laguna (7M+), DepEd CAR (6M+), and DepEd Ilocos Norte/Aurora (3M+) leaks show systemic vulnerability. Database leaks replace unauthorized access as the dominant attack type.
37 breaches recorded in 2026 — on pace to overtake 2020 as the worst year on record. The Nullsec Philippines / Fawkes Pilipinas / Crypt0nymz collective has driven a sustained, near-daily campaign against Philippine schools spanning DepEd offices, state universities, private colleges, K-12 institutions, and technical institutes. Attack patterns now include shared-hosting compromises, shared-vendor (SIS) supply-chain exposures, and a claimed 685K-record leak — with attackers explicitly stating they have access to additional sister schools they have not yet posted.
The proportion of breaches we cannot publicly attribute to a named institution has grown sharply. In 2020, the previous record year for incident volume, every documented breach was independently confirmed by media, the National Privacy Commission, or the affected institution itself — 0% were anonymized. In 2026, that figure is 76%. The shift is structural, not stylistic: an increasing share of the public record is now sourced solely from threat-actor posts, and our methodology requires those incidents to be anonymized until an independent source corroborates the claim.
Anonymization is a methodological floor, not an editorial preference: when the only public evidence is a threat actor's own post, naming the institution would amplify an unverified claim. But the consequence at scale is that 33% of all entries on this tracker are currently shadow records — incidents we know about internally but cannot publicly attribute, because the affected school has not acknowledged them.
The downstream effects are concrete. Students and parents cannot reset reused passwords or watch for targeted phishing tied to data they don't know is circulating. Other schools in the same vendor cluster cannot harden against vulnerabilities they cannot identify. The National Privacy Commission cannot enforce the 72-hour notification obligation under RA 10173 on incidents it has not been informed of. And the public record of Philippine school cybersecurity is, increasingly, written by the attackers rather than by the institutions they target.
These free tools and guides can help your school close the gaps these trends reveal.
DPA Compliance Checker
Score your school's Data Privacy Act compliance in minutes.
School Security Scorecard
Rate your school's cybersecurity across 8 domains and get an action plan.
Understanding Ransomware
How ransomware works and what school admins need to know before it hits.
View all free security tools →|Browse all guides & articles →