The Department of Information and Communication Technology (DICT), responsible for overseeing the planning, development, and promotion of the national ICT agenda, has reported a “minor” data breach within its systems.
Hackers managed to exfiltrate less than 5 megabytes of employee data during the incident. The breach was confirmed by DICT Assistant Secretary Renato Paraiso, who revealed that the department’s Disaster Risk Reduction Management Division (DRRMD) was defaced by a group identifying themselves as “ph1ns.”
Vulnerabilities and warnings
The DRRMD, an external unit of the DICT, is particularly susceptible to such attacks due to its design, which prioritizes accessibility. Assistant Secretary Paraiso noted that the group warned of potential future attacks, urging the department to strengthen its cybersecurity measures.
This attack is part of a larger wave of cyber threats targeting private and public entities across the country. Recently, the Department of Science and Technology (DOST) and the Bureau of Customs (BOC) have also fallen victim to similar breaches. These incidents highlight a growing trend and underscore the need for heightened cybersecurity defenses within government agencies.
In response to the breach, the DICT has notified the National Privacy Commission, the country’s privacy watchdog, ensuring that appropriate measures are taken to address the data exposure and mitigate further risks.

