The Department of Information and Communications Technology (DICT) is investigating separate cyber incidents involving the websites of the Department of Migrant Workers (DMW) and the Department of Labor and Employment (DOLE).
The affected web services were temporarily taken offline while government cybersecurity teams investigated the attacks, removed possible threats, strengthened security, and worked to safely restore the websites.
The DICT Cybersecurity Bureau, through the National Computer Emergency Response Team (NCERT), said it detected unauthorized access to the DMW website and the defacement of a DOLE web page. Website defacement happens when an attacker changes the content or appearance of a website without permission.
For the DMW incident, the DICT activated its emergency response procedures and coordinated directly with the agency’s Management Information Technology Service (MITS).
Technical teams tightened controls over who could access the system and isolated affected parts of the website. These steps were taken to prevent the attack from spreading and to allow investigators to determine how the breach happened.
The DICT also informed DOLE’s IT administrators after detecting unauthorized changes to the agency’s web host. The department and DOLE then isolated the affected system, strengthened access controls, and began examining the incident.
Initial checks found no evidence that sensitive databases or personally identifiable information were compromised in the DOLE incident, according to the DICT.
Personally identifiable information includes data that can be used to identify a person, such as a full name, address, contact details, government identification number, or financial information.
The temporary shutdown of the DMW and DOLE web services is a precautionary step meant to make sure any remaining threat is removed before public access is restored. NCERT and the agencies’ technical teams are continuing their investigations and recovery work.
Meanwhile, the DICT said a reported ransomware attack against the Philippine Ports Authority (PPA) was a false positive.
NCERT sent an official incident report to PPA administrators following reports that the agency’s systems had been hit by ransomware. A joint review of system logs later found no ransomware activity or evidence that PPA’s infrastructure had been compromised.
Ransomware is malicious software that locks files or systems and typically demands payment to restore access.
The DICT said its technical teams and partner agencies would continue investigating and managing the incidents. It will issue additional verified updates as the DMW and DOLE websites reach recovery milestones.
The incidents highlight the continued threat of cyberattacks against government websites, which can disrupt public services even when attackers fail to reach sensitive databases.