Philippine authorities are investigating a possible exposure of 410 files linked to 48 cybersecurity firms participating in DICT’s Trusted Assessment Provider programme.

Philippines Probes Possible Data Exposure Affecting 48 Cybersecurity Firms

The420 Web Correspondent
6 Min Read

The Philippines’ Department of Information and Communications Technology is investigating a possible data exposure involving 48 companies participating in one of its cybersecurity accreditation programmes.

The incident concerns around 410 files associated with firms in the DICT Trusted Assessment Provider, or DTAP, programme. Authorities said the reported data amounts to about 600 MB, expanding to roughly 770 MB when uncompressed.

The National Computer Emergency Response Team, operating under the DICT Cybersecurity Bureau, has begun verifying whether the exposure occurred, where the files came from and what information may have been compromised.

Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise

Files may contain corporate and security-related records

DICT said the reported files could include corporate registration documents, permits, certifications, cybersecurity credentials, employment records and performance evaluations prepared by the department.

That combination makes the incident potentially sensitive even if no customer database or payment information is involved.

Corporate records can reveal internal contacts and organisational information, while employment documents may contain personal data. More importantly, any genuine cybersecurity credentials or internal assessment material could create follow-on security risks if misused.

However, DICT has not yet confirmed that all the reported files are authentic or that every category of information mentioned was actually exposed.

What the DTAP programme does

The Trusted Assessment Provider programme is designed to work with local cybersecurity service providers that evaluate and strengthen digital systems before those systems are made available to the public.

In practice, the programme acts as part of the government’s cybersecurity assurance process.

That means the firms involved may hold or submit documents demonstrating their technical qualifications, certifications and security capabilities.

An exposure involving records from such a programme could therefore reveal information not normally intended for public circulation.

It does not, however, mean that all 48 companies themselves were hacked.

The number refers to companies associated with the reported files. Authorities are still trying to determine which system or organisation, if any, was actually compromised.

Hacker claim triggered scrutiny

Philippine cybersecurity monitoring groups BetterGovPH and Deep Web Konek said a threat actor using the alias “core849” claimed to have leaked the 410 files.

According to ABS-CBN News, the groups said the documents were linked to companies participating in the accreditation programme and included company papers, permits, certificates and DICT review material.

That claim remains unverified.

A hacker posting files online does not by itself prove that every document is genuine, that the files came directly from a DICT system or that the threat actor actually breached the organisations named in the material.

DICT has specifically urged the media and public to exercise caution in circulating unverified information while the investigation is underway.

NCERT is checking the source and scope

The Philippine NCERT is now working to establish the authenticity, source, nature and scale of the reported exposure.

The agency is also coordinating with the provider involved and other affected parties.

Those questions are central to determining how serious the incident is.

Investigators will need to establish whether the files came from a government system, an accredited provider, another organisation holding copies of the records or some other source.

They will also need to determine whether the data was merely accessible, actually downloaded by an unauthorised party or subsequently redistributed.

Each scenario carries a different level of risk.

Privacy law notification could follow

DICT said that if investigators confirm that personal or other protected information was compromised, it will take appropriate action and notify affected parties where required under the Philippines’ Data Privacy Act of 2012.

That means a formal breach notification has not yet been triggered based solely on the public claim.

The legal response will depend on what the investigation establishes about the nature of the data, who accessed it and whether affected individuals face a real risk of harm.

If employment records or credentials are confirmed as exposed, organisations may also need to examine passwords, active sessions and access permissions.

Incident comes amid wider government cybersecurity concerns

The investigation arrives during a period of heightened scrutiny around Philippine government cybersecurity.

Earlier this month, the Land Transportation Franchising and Regulatory Board temporarily took its electronic support system offline while investigating a separate reported security breach.

DICT has also recently ordered annual security testing for government IT systems as more public services move online.

The DTAP incident is particularly notable because it involves a programme intended to assess cybersecurity providers themselves.

If the reported exposure is confirmed, investigators will likely focus not only on what data escaped but also on whether the accreditation process stores sensitive security material in ways that need stronger protection.

For now, the central fact remains that the incident is still under investigation and the breach has not been conclusively established.

What this means for you: Companies involved in cybersecurity accreditation should watch for official DICT notices and avoid relying on leaked-file claims alone. If credentials or employee records are confirmed exposed, affected organisations may need to rotate access credentials and warn staff about targeted phishing.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected