Deep Web Konek flags alleged Philippine Red Cross data breach
-
Courtesy of PRC
The Philippine Red Cross (PRC) is investigating an alleged data breach after cybersecurity site Deep Web Konek reported that a threat actor claimed to have compromised information linked to the humanitarian organization.
Deep Web Konek reported that a group identifying itself as Infrastructure Destruction Squad/BLACKNET-00 claimed to have obtained a database associated with the PRC and offered approximately 34.7 GB of data for sale for US$600.
In an official statement, the PRC acknowledged online reports concerning the supposed unauthorized access but stressed that the claims remain unverified.
“Unverified and anonymous social media posts surfaced online regarding the supposed unauthorized access and alleged breach of certain private and confidential data servers of the Philippine Red Cross organization (‘PRC’),” the organization said.
The PRC said the matter is now subject to internal and external investigation, while precautionary measures have been implemented to protect its information and systems.
“While this matter is presently the subject of an ongoing internal and external investigation, the PRC has undertaken precautionary measures to protect and safeguard the sanctity of its private data and integrity of its systems,” it said.
According to Deep Web Konek, the threat actor identified the allegedly compromised information as the “Philippines Red Cross (PRC) Donor Database.”
However, the cybersecurity site said the fields advertised by the threat actor suggest the purported database could contain information beyond donors, potentially covering volunteers and first aid training participants.
The allegedly exposed information includes names, gender, age and location details such as street addresses, barangays, provinces, ZIP codes and GPS coordinates. Contact information, including telephone numbers, mobile numbers and email addresses, was also allegedly included.
Deep Web Konek said the listing also contained fields associated with donation records, including payment dates, donation amounts, donation types and check numbers.
Other alleged information includes PRC chapter or branch details, categories and donor identification numbers.
Screenshots cited by Deep Web Konek showed what appeared to be a large tabular dataset, with file metadata indicating a size of 37,366,057,753 bytes, or approximately 34.7 GB. The displayed metadata indicated that the file was created on Sept. 14, 2026 and modified later that evening.
The threat actor further claimed that the compromise involved an unauthenticated file-upload vulnerability that allegedly allowed arbitrary files to be uploaded and used to establish a backdoor. These claims have not been independently verified.
The PRC said it would directly contact affected individuals or entities if its investigation determines that private or confidential information had been compromised.
“Once it is determined that private or confidential data may have been compromised by this alleged intrusion, the PRC shall directly contact and promptly alert the affected individuals and/or entities,” PRC said.
The organization also reminded the public that unauthorized access, theft and illegal trade of private and confidential information may constitute criminal violations of Philippine laws, including the Data Privacy Act of 2012.
“If the alleged data breach did indeed occur, the PRC shall not hesitate to have the full force of the law bear upon all persons involved and responsible for the same,” PRC said.
