Analysis of 92 documented school data breaches across the Philippines from 2012 to 2026.
Why 2026's count is not a like-for-like record. Incidents before 2026 were reconstructed from mainstream news coverage, because that reporting was our only source at the time — so a breach that never got written up was never counted. From 2026 we monitor in real time and catch incidents that never reach the press, which is most of them: 77% of this year's entries have no source beyond the attacker's own post. Earlier years are therefore undercounts of unknown size, and the rise on this page measures how much we can see at least as much as how much is happening. The honest reading is that 2026 is the first year counted properly — not provably the worst.
Among Filipinos who suffered a data breach, these were the most common responses. The Philippines ranked #1 in cybersecurity concern (234/300) among 13 countries surveyed.
The average Filipino email has been breached almost 3 times (Surfshark Research). The Philippines needs 180,000 more cybersecurity professionals (ISC² Cybersecurity Workforce Study). Schools — which hold sensitive data on minors — are especially at risk.
Click a point to filter the breach list by year. Hover for details.
How to read this chart: year-over-year counts are not directly comparable, and the bars for earlier years are floors rather than totals. Incidents from before 2026 were catalogued retrospectively and recorded only when a reputable source — media, the National Privacy Commission, or the school itself — confirmed them, so those years capture only the breaches that were reported. Any incident that never made the news left no record for us to find, which means every pre-2026 bar undercounts its year by an unknown amount. From 2026 incidents are tracked in real time, which also includes those whose only source is an unverified threat-actor post — a category earlier years structurally never recorded. 77% of 2026 entries are anonymized for exactly that reason (their only source is a threat-actor claim), versus 0% in 2020. Read the 2026 rise primarily as a change in visibility; how much of it is a genuine increase in attacker activity cannot be separated out from this data alone.
Based on confirmed/claimed record counts. "Unknown" counts are excluded. Hover for exact totals.
Average number of records exposed per breach each year. Shows how breach scale is escalating — not just frequency. Years with no quantified records are excluded.
Each bar shows the mix of attack types for that year. Hover to see the breakdown.
Hover to see share of total. Click to filter the breach list.
Hover a severity level to see its definition. Click to filter the breach list.
64% of all breaches are rated Critical or High severity.
DepEd offices vs. universities & colleges vs. other institutions.
Resolution status of all tracked breaches. Click to filter.
What kinds of data are leaked most often across all breaches. Shows the top 15 categories.
+ 274 more data types
Hover to see each region's share of total incidents.
Chinese hackers defaced the University of the Philippines System website amid the Scarborough Shoal standoff — the earliest known cyberattack on a Philippine educational institution.
Two schools and a municipal government in Bohol were hacked and defaced — an early sign that educational institutions were becoming regular targets.
Ateneo Law School's Student Access Module was hacked by AnonCalapan (AnonGhost Philippines), leaking student credentials. The politically motivated attack was part of a broader wave of Philippine hacktivism tied to Typhoon Yolanda criticism.
Chinese hacker group 1937 CN Team defaced the Philippine Public Safety College website over the South China Sea dispute — continuing a pattern of politically motivated attacks on Philippine institutions.
University of the East breach — 1,572 records exposed via unauthorized access. An early warning sign of data-focused attacks.
28 breaches in a single year — by far the worst on record. Hacktivist groups like Pinoy Grayhats targeted university portals nationwide in a mass hacking wave hitting 20+ institutions. San Beda saw 400,000+ plaintext credentials exposed.
University of Perpetual Help hit by ransomware — marking a shift to more destructive, monetized attacks.
De La Salle University experienced a cyberattack, showing even well-resourced institutions are vulnerable.
DepEd OVAP database exposed 210,000+ records. A separate 750GB alleged breach surfaced, targeting government education systems.
13 breaches with millions of records. DepEd Laguna (7M+), DepEd CAR (6M+), and DepEd Ilocos Norte/Aurora (3M+) leaks show systemic vulnerability. Database leaks replace unauthorized access as the dominant attack type.
39 breaches recorded through September 2 2026, more than any earlier year here — though this is the first year we monitored continuously rather than reconstructing from news coverage, so it is not comparable to the 28 logged in 2020. The Nullsec Philippines / Fawkes Pilipinas / Crypt0nymz collective has driven a sustained, near-daily campaign spanning DepEd offices, state universities, private colleges, K-12 institutions, and technical institutes. The tradecraft broadened over the year: shared-hosting web shells, shared-vendor (SIS and LMS) supply-chain exposures, credential extraction from enterprise platforms, and misconfigured admin tooling leaking source and data. A claimed 685K-record leak in March and a ~1M-row DepEd training-platform CSV in May are the largest single exposures. Attackers have explicitly stated they hold access to additional sister schools they have not yet posted.
The proportion of breaches we cannot publicly attribute to a named institution has grown sharply. In 2020, the busiest year in our retrospective record, every documented breach was independently confirmed by media, the National Privacy Commission, or the affected institution itself — 0% were anonymized. In 2026, that figure is 77%. The shift is structural, not stylistic: an increasing share of the public record is now sourced solely from threat-actor posts, and our methodology requires those incidents to be anonymized until an independent source corroborates the claim.
Anonymization is a methodological floor, not an editorial preference: when the only public evidence is a threat actor's own post, naming the institution would amplify an unverified claim. But the consequence at scale is that 35% of all entries on this tracker are currently shadow records — incidents we know about internally but cannot publicly attribute, because the affected school has not acknowledged them.
The downstream effects are concrete. Students and parents cannot reset reused passwords or watch for targeted phishing tied to data they don't know is circulating. Other schools in the same vendor cluster cannot harden against vulnerabilities they cannot identify. The National Privacy Commission cannot enforce the 72-hour notification obligation under RA 10173 on incidents it has not been informed of. And the public record of Philippine school cybersecurity is, increasingly, written by the attackers rather than by the institutions they target.
These free tools and guides can help your school close the gaps these trends reveal.
DPA Compliance Checker
Score your school's Data Privacy Act compliance in minutes.
School Security Scorecard
Rate your school's cybersecurity across 8 domains and get an action plan.
Understanding Ransomware
How ransomware works and what school admins need to know before it hits.
View all free security tools →|Browse all guides & articles →