DICT responds to cyber threats hitting DMW, DOLE; PPA ransomware claim ruled false positive
- DICT, DMW, DOLE, PPA
The Department of Information and Communications Technology (DICT) said it is responding to multiple cyber threats involving government agencies following unauthorized access to the Department of Migrant Workers (DMW) website and a web defacement incident involving the Department of Labor and Employment (DOLE).
The incidents surfaced alongside claims that the Philippine Ports Authority (PPA) had been targeted by ransomware. DICT, however, said its technical assessment found no ransomware activity or system compromise within PPA’s infrastructure.
Hacktivist group claims deeper DMW access
The DMW incident came amid claims by hacktivist group HappyGoLuckyPH that it had gained access beyond the agency’s public-facing website.
According to the report of cybersecurity advocate Deep Web Konek, the HappyGoLuckyPH group claimed responsibility for the DMW website defacement and alleged it maintained access to the agency’s Active Directory environment for more than a month before eventually compromising a Domain Controller.
The group further alleged that it gained access to internal systems, security management consoles, databases and server directories, including repositories containing worker, recruitment, contract, financial, legal and other administrative information.
It also claimed to have discovered stored data and database backups containing identity-verification records and scanned identification documents.
Following the detection of unauthorized access, the agency said emergency incident protocols were activated in coordination with the DMW Management Information Technology Service.
Joint technical teams implemented access-control hardening and system isolation measures to support the ongoing forensic investigation and system recovery.
DMW’s affected web services were also temporarily taken offline as a precaution while NCERT and agency technical teams continued investigating the incident.
DICT also confirmed detecting an unauthorized modification on DOLE’s web host.

The department said DOLE IT administrators were immediately notified and coordinated response protocols were initiated.
Primary system and access-control measures were enforced to isolate the affected node, support digital forensic work and facilitate system restoration.
Affected DOLE web services were also temporarily taken offline as a precaution.
DICT, meanwhile, said initial technical assessments found that no sensitive databases or personally identifiable information (PII) were compromised.
PPA reportedly appeared on Qilin leak site
Separately, reports emerged that PPA had allegedly been listed as a victim of the Qilin ransomware group.
Deep Web Konek reported that a listing purportedly appearing on Qilin’s alleged leak site identified the Philippine Ports Authority under the “business services” category.
The listing carried a publication date of Sept. 5, 2026 and reportedly included a company URL, but no photos were attached.
At the time the report surfaced, it was unclear whether any PPA information had actually been accessed or stolen. A listing on an alleged ransomware leak site alone does not independently establish that an organization’s systems were successfully compromised.
DICT said NCERT subsequently alerted PPA administrators through an official incident report and conducted a technical assessment with the agency’s designated personnel.
According to DICT, an examination of joint logs determined that the ransomware report was a false positive.
The department said “no ransomware activity or system compromise occurred within PPA infrastructure.”
The finding directly counters the implication of the alleged Qilin leak-site listing, although DICT’s statement did not elaborate on why PPA appeared on the site or what led to the listing.
DICT said investigation and mitigation efforts involving the other incidents remain underway in coordination with affected agencies and partner technical teams.
The department said further verified technical updates will be released as recovery milestones are completed.
