SchoolBreach.org
BreachesTrendsToolsLearnAbout
Free Security Check
Security Check
SchoolBreach.org

A public resource tracking data breaches in Philippine schools. Helping administrators protect student data through awareness, education, and free security tools.

© 2026 SchoolBreach.org · A community service by OceanEd

Navigate

  • Breaches
  • Trends
  • Tools
  • Learn
  • Methodology

Company

  • About
  • Privacy Policy
  • Terms of Service
  • Contact Us

Disclaimer: This tracker is maintained for educational and awareness purposes. Incidents are documented using threat intelligence monitoring, Philippine media reports, NPC filings, and responsible disclosures. Social media platforms are monitored for leads and are corroborated before publication or naming — never through active scanning or exploitation. Severity ratings and summaries are prepared with AI assistance and reviewed editorially. Full methodology →

Back to Learn
explainer

Cybersecurity Incidents in the Philippines Nearly Doubled: What the NPC Data Means for Schools

Official National Privacy Commission figures show reported incidents rose 89% from 2019 to 2025. Here's what's driving the increase, and why schools should expect to see more of it.

6 min readNPC, statistics, trends

The Numbers

Data obtained from the National Privacy Commission (NPC) via a Freedom of Information request shows that reported cybersecurity incidents across the Philippines nearly doubled between 2019 and 2025 — rising from 183 cases to 345, an increase of roughly 89%.

Breaking down the NPC's cause categories:

  • Human Error: 78 cases in 2019 vs. 126 cases in 2025 (+62%)
  • Malicious Attack: 73 cases in 2019 vs. 149 cases in 2025 (+104%)
  • Combined (Malicious Attack + Human Error): 0 cases in 2019 vs. 41 cases in 2025 (new category)
  • System Glitch: 26 cases in 2019 vs. 10 cases in 2025 (-62%)

Two trends stand out. First, malicious attacks more than doubled and are now the single largest cause of reported incidents — overtaking human error, which had historically topped the list. Second, the NPC began tracking a combined cause category (incidents where human error created the opening a malicious actor then exploited), which didn't exist as a reporting category in 2019 and accounted for 41 cases by 2025. That category alone is a signal: a growing share of "attacks" only succeed because of a preventable mistake first — a reused password, an unpatched plugin, a misconfigured database left open.

Meanwhile, System Glitch incidents fell by more than half, suggesting organizations have gotten better at basic system reliability even as they've gotten worse (or attackers have gotten better) at exploiting people and processes.

Why This Matters for Philippine Schools

The NPC's national figures aren't broken out by sector in the reporting we've reviewed, but the pattern matches exactly what we've observed tracking incidents against Philippine schools directly on SchoolBreach.org:

  • Malicious, credential-driven attacks are rising. Hacktivist groups (Nullsec Philippines, Quantum Security Group, and others) have repeatedly targeted DepEd offices, state universities, and private schools — see our Common Attack Vectors breakdown.
  • Human error keeps opening the door. Misconfigured cloud databases, unsecured enrollment portals, and reused passwords are recurring root causes in the breaches we track — not just at the school level, but at the DepEd regional level, where a single office's data exposure can affect an entire region's worth of students and teachers.
  • The "combined cause" pattern is the school pattern. Nearly every major DepEd or school incident we've documented follows the same shape: an ordinary mistake (no authentication on an API, a plaintext password, an unpatched CMS) that a malicious actor later found and exploited. The NPC's new combined-cause category is effectively naming what school IT teams already live with.

What Rising National Numbers Should Prompt Schools to Do

An 89% national increase doesn't mean your school is 89% more likely to be breached this year — but it does mean the reporting environment is catching more incidents, and that attackers are increasingly organized around finding the human-error openings schools tend to leave. Two practical takeaways:

  1. 1Assume the gap between "reported" and "actual" is shrinking. More incidents are surfacing not just because more are happening, but because reporting culture (and NPC enforcement) has matured since 2019. If your school hasn't had a documented incident, that's not the same as having a clean security posture — see our 10-Point School Cybersecurity Checklist.
  2. 2Prioritize the human-error fixes first. Since combined and human-error causes still make up the majority of reported incidents, the highest-leverage work is often the least technical: MFA enforcement, access reviews, and vendor vetting — not just firewalls. See our MFA Setup Guide and How to Choose Secure School Software.

Resources

  • Common Attack Vectors in Philippine Schools
  • 10-Point School Cybersecurity Checklist
  • Data Privacy Act 101 for Philippine Schools
  • SchoolBreach.org tracker — documented incidents against Philippine schools and DepEd offices

Sources

  • Cybersecurity Incidents in the Philippines Nearly Doubled, Official NPC Data Shows — Deep Web Konek, based on National Privacy Commission data obtained via Freedom of Information request (December 2025)
More ArticlesTry Free Tools