SchoolBreach.org
BreachesTrendsToolsLearnAbout
Free Security Check
Security Check
SchoolBreach.org

A public resource tracking data breaches in Philippine schools. Helping administrators protect student data through awareness, education, and free security tools.

© 2026 SchoolBreach.org · A community service by OceanEd

Navigate

  • Breaches
  • Trends
  • Tools
  • Learn
  • Methodology

Company

  • About
  • Privacy Policy
  • Terms of Service
  • Contact Us

Disclaimer: This tracker is maintained for educational and awareness purposes. Incidents are documented using threat intelligence monitoring, Philippine media reports, NPC filings, and responsible disclosures. Social media platforms are monitored for leads and are corroborated before publication or naming — never through active scanning or exploitation. Severity ratings and summaries are prepared with AI assistance and reviewed editorially. Full methodology →

Back to Breach Tracker

Breach Trends

Analysis of 90 documented school data breaches across the Philippines from 2012 to 2026.

Key Finding: Breaches Are Escalating

  • Breaches surged from 1 incident in 2012 to 28 incidents in 2020, with attack scale growing from hundreds to millions of records.
  • Attack type shifted from unauthorized access & defacement (2020) to massive database leaks (2025).
  • DepEd regional offices are the most frequent target, with breaches spreading from NCR to nationwide.
  • Shared hosting exploitation emerged as a key attack vector in 2026 — attackers use web shells to compromise one hosting account and pivot to multiple schools simultaneously. Learn more →

The Philippines Is a Top Target

106
breached accounts per 100 people in the Philippines — more than double the Asian average of 52
Source: Surfshark Research, 2024
124M
total accounts breached in the Philippines — 2nd highest in Southeast Asia
Source: Surfshark Research, 2024
3 accounts
hacked every minute in the Philippines — a relentless tide of data breaches
Source: Straits Times, 2025
6%
of Philippine organizations are mature enough to repel cyberattacks — up from 1% in 2024, but 54% are still in the bottom two readiness stages
Source: Cisco, 2025
4th
in the world for most cyberattack incidents, with government and education among the top targets
Source: DICT, 2023
0.04%
of GDP spent on cybersecurity — nearly half the ASEAN average of 0.07%
Source: National Cybersecurity Plan 2028, 2023

Filipinos Don't Stay Silent After a Breach

24%
took legal action
21%
closed their account
18%
exposed it on social media

Among Filipinos who suffered a data breach, these were the most common responses. The Philippines ranked #1 in cybersecurity concern (234/300) among 13 countries surveyed.

Source: Unisys Security Index, 2019

The average Filipino email has been breached almost 3 times (Surfshark Research). The Philippines needs 180,000 more cybersecurity professionals (ISC² Cybersecurity Workforce Study). Schools — which hold sensitive data on minors — are especially at risk.

Breaches by Year

Click a point to filter the breach list by year. Hover for details.

010203037121314151617181920212223242526

How to read this chart: year-over-year counts are not directly comparable. Incidents from before 2026 were catalogued retrospectively and recorded only when a reputable source — media, the National Privacy Commission, or the school itself — confirmed them, so earlier years capture only acknowledged breaches. 2026 is tracked in real time and also includes incidents whose only source is an unverified threat-actor post — a category earlier years structurally never recorded. 76% of 2026 entries are anonymized for exactly that reason (their only source is a threat-actor claim), versus 0% in 2020. The steep 2026 rise therefore reflects both increased attacker activity and wider, faster detection.

Records Affected by Year

Based on confirmed/claimed record counts. "Unknown" counts are excluded. Hover for exact totals.

2012
0
2013
0
2014
0
2015
0
2016
0
2017
0
2018
0
2019
2K
2020
401K
2021
23K
2022
2K
2023
0
2024
210K
2025
16.6M
2026
1.9M

Average Records Per Incident

Average number of records exposed per breach each year. Shows how breach scale is escalating — not just frequency. Years with no quantified records are excluded.

2012
—
2013
—
2014
—
2015
—
2016
—
2017
—
2018
—
2019
2K
2020
201K
2021
23K
2022
2K
2023
—
2024
210K
2025
1.8M
2026
137K

How Attack Types Shifted

Each bar shows the mix of attack types for that year. Hover to see the breakdown.

2012
1
1
2013
1
1
2014
1
1
2015
1
1
2019
1
1
2020
21
28
2021
1
1
2022
1
1
1
3
2023
1
1
2024
1
1
2
2025
3
10
13
2026
9
11
9
7
37
Unauthorized Access
Database Leak
Website Defacement
Data Exposure
Misconfiguration
Ransomware

By Attack Type

Hover to see share of total. Click to filter the breach list.

Unauthorized Access37(41%)
Database Leak26(29%)
Website Defacement16(18%)
Data Exposure9(10%)
Misconfiguration1(1%)
Ransomware1(1%)

By Severity

Hover a severity level to see its definition. Click to filter the breach list.

Critical21 (23%)
High36 (40%)
Medium30 (33%)
Low3 (3%)

63% of all breaches are rated Critical or High severity.

Who Gets Targeted

DepEd offices vs. universities & colleges vs. other institutions.

76%
14%
University / College68 (76%)
DepEd13 (14%)
Other9 (10%)

Breach Status

Resolution status of all tracked breaches. Click to filter.

Resolved46 (51%)
Confirmed21 (23%)
Investigating10 (11%)
Unconfirmed13 (14%)

Most Exposed Data Types

What kinds of data are leaked most often across all breaches. Shows the top 15 categories.

Website content20
Student personal information13
Email addresses12
Student portal data11
Student names9
Full names6
Usernames5
Student numbers4
Birth dates4
Student ID numbers3
Gender3
Section3
Phone numbers3
Personal data3
Database contents3

+ 261 more data types

By Region

Hover to see each region's share of total incidents.

National Capital Region20
CALABARZON14
Central Visayas7
Central Luzon7
National6
Davao Region6
Bicol Region5
Western Visayas5
Caraga3
Northern Mindanao3
Ilocos Region3
Eastern Visayas3
National Capital Region (NCR)2
MIMAROPA2
CAR2
Nationwide1
NCR1
Cagayan Valley1
BARMM1

Timeline Highlights

2012

First Documented Incident

Chinese hackers defaced the University of the Philippines System website amid the Scarborough Shoal standoff — the earliest known cyberattack on a Philippine educational institution.

2013

First Multi-Target Attack

Two schools and a municipal government in Bohol were hacked and defaced — an early sign that educational institutions were becoming regular targets.

2014

Hacktivism Hits Higher Education

Ateneo Law School's Student Access Module was hacked by AnonCalapan (AnonGhost Philippines), leaking student credentials. The politically motivated attack was part of a broader wave of Philippine hacktivism tied to Typhoon Yolanda criticism.

2015

Geopolitical Hacktivism Continues

Chinese hacker group 1937 CN Team defaced the Philippine Public Safety College website over the South China Sea dispute — continuing a pattern of politically motivated attacks on Philippine institutions.

2019

First Major Data Breach

University of the East breach — 1,572 records exposed via unauthorized access. An early warning sign of data-focused attacks.

2020

Mass Hacking Wave

28 breaches in a single year — by far the worst on record. Hacktivist groups like Pinoy Grayhats targeted university portals nationwide in a mass hacking wave hitting 20+ institutions. San Beda saw 400,000+ plaintext credentials exposed.

2022

Ransomware Arrives

University of Perpetual Help hit by ransomware — marking a shift to more destructive, monetized attacks.

2023

Major University Targeted

De La Salle University experienced a cyberattack, showing even well-resourced institutions are vulnerable.

2024

DepEd Under Fire

DepEd OVAP database exposed 210,000+ records. A separate 750GB alleged breach surfaced, targeting government education systems.

2025

Explosion in Scale

13 breaches with millions of records. DepEd Laguna (7M+), DepEd CAR (6M+), and DepEd Ilocos Norte/Aurora (3M+) leaks show systemic vulnerability. Database leaks replace unauthorized access as the dominant attack type.

2026

Hacktivist Campaign Escalates Against Schools

37 breaches recorded in 2026 — on pace to overtake 2020 as the worst year on record. The Nullsec Philippines / Fawkes Pilipinas / Crypt0nymz collective has driven a sustained, near-daily campaign against Philippine schools spanning DepEd offices, state universities, private colleges, K-12 institutions, and technical institutes. Attack patterns now include shared-hosting compromises, shared-vendor (SIS) supply-chain exposures, and a claimed 685K-record leak — with attackers explicitly stating they have access to additional sister schools they have not yet posted.

The Silence Problem

The proportion of breaches we cannot publicly attribute to a named institution has grown sharply. In 2020, the previous record year for incident volume, every documented breach was independently confirmed by media, the National Privacy Commission, or the affected institution itself — 0% were anonymized. In 2026, that figure is 76%. The shift is structural, not stylistic: an increasing share of the public record is now sourced solely from threat-actor posts, and our methodology requires those incidents to be anonymized until an independent source corroborates the claim.

2020 (prior worst year)
0%
of 28 documented breaches were anonymized — every incident was independently corroborated and the institution could be named
2026 (year-to-date)
76%
of 37 documented breaches are anonymized — sourced only from threat-actor posts, with no school statement, no NPC finding, and no media coverage to corroborate

Why this matters

Anonymization is a methodological floor, not an editorial preference: when the only public evidence is a threat actor's own post, naming the institution would amplify an unverified claim. But the consequence at scale is that 33% of all entries on this tracker are currently shadow records — incidents we know about internally but cannot publicly attribute, because the affected school has not acknowledged them.

The downstream effects are concrete. Students and parents cannot reset reused passwords or watch for targeted phishing tied to data they don't know is circulating. Other schools in the same vendor cluster cannot harden against vulnerabilities they cannot identify. The National Privacy Commission cannot enforce the 72-hour notification obligation under RA 10173 on incidents it has not been informed of. And the public record of Philippine school cybersecurity is, increasingly, written by the attackers rather than by the institutions they target.

Don't Wait for a Breach

These free tools and guides can help your school close the gaps these trends reveal.

DPA Compliance Checker

Score your school's Data Privacy Act compliance in minutes.

School Security Scorecard

Rate your school's cybersecurity across 8 domains and get an action plan.

Understanding Ransomware

How ransomware works and what school admins need to know before it hits.

View all free security tools →|Browse all guides & articles →