DICT probes alleged EMB system breach, possible exposure of personal, company data
-
Photo from Pixabay
The Department of Information and Communications Technology (DICT) is investigating alleged unauthorized access involving the Environmental Management Bureauβs (EMB) Company Registration System (CRS), which may have exposed personal and corporate information.
In a statement Sunday, Sept. 27, the DICT said the incident was reported at around 2 p.m. and involved the CRS, a system used to register, manage, and maintain official business records, including company ownership, registration status, and other corporate information.
The agency said the reported data exposure allegedly involves personal and corporate information maintained within the system.
If validated, the exposure could pose privacy and information security risks, according to the DICT.
However, the agency stressed that the reported incident has not yet been confirmed.
The authenticity of the exposed information, the extent of the alleged exposure, the source and method of access, and whether the information originated from the EMB CRS remain subject to further verification.
Authorities are also assessing whether unauthorized access occurred and whether any EMB systems or databases were compromised.
The CRS is currently under maintenance while incident responders conduct assessment and response activities.
The DICT, through the National Computer Emergency Response Team (NCERT), said it continues to coordinate with the concerned organization and will provide assistance for the investigation and remediation as necessary.
The agency said further information will be released once the relevant facts and findings have been validated.
The latest report comes two days after the DICT said it was investigating a separate alleged data breach involving 410 files linked to 48 companies.
READ:
DICT probes alleged data breach involving 410 files from 48 companies
The files reportedly included corporate registration records, permits, certifications, cybersecurity credentials, employment documents, and DICT performance evaluations.
The DICT said NCERT was also working to verify the authenticity, source, nature, and extent of the reported exposure in that separate incident.
