DICT probes alleged data breach involving 410 files from 48 companies
-
Photo courtesy of Pixabay
The Department of Information and Communications Technology (DICT) is investigating an alleged data breach involving its Trusted Assessment Provider (D-TAP) accreditation program, with around 410 files linked to 48 companies reportedly exposed.
In a statement, the DICT said the incident is being handled by the National Computer Emergency Response Team (NCERT) under its Cybersecurity Bureau.
Based on initial information received by the agency, the files comprise approximately 600 MB of data, or around 770 MB when uncompressed.
The reported files may include corporate registration records, permits, certifications, cybersecurity credentials, employment documents, and DICT performance evaluations.
DICT said it is currently verifying the reported exposure, including the authenticity, source, nature, and extent of the data involved.
NCERT is also coordinating with the concerned D-TAP and other relevant parties to establish the facts, determine the scope of the incident, and provide appropriate assistance.
Should the investigation confirm that personal or other protected data has been compromised, DICT said it will take appropriate action, including notifying affected parties when applicable, in accordance with the Data Privacy Act of 2012 and other relevant policies.
βDICT assures the public and its accredited assessment providers that the matter is being actively managed,β the agency said.
The department also urged the media and the public to exercise caution when sharing or reporting unverified information while the investigation remains ongoing.
DICT said further updates will be issued once information has been verified and validated.
Cybersecurity research group Deep Web Konek earlier reported that a threat actor using the alias βcore849β allegedly leaked documents linked to the D-TAP accreditation program in a forum post published on Sept. 24.
According to the report, the alleged dataset contains 410 files involving 48 companies, with a total size of around 600 MB and approximately 770 MB when uncompressed.
The alleged dataset reportedly includes corporate and legal documents such as Securities and Exchange Commission and Bureau of Internal Revenue registrations, business permits, PhilGEPS certifications, notarized applications and attestations, clearances, and employment certificates.
It also reportedly contains cybersecurity-related records, including CREST certifications, SOC 2 audit documentation, ISO 27001 and ISO 9001 certificates, and individual cybersecurity certifications.
Other files reportedly include company profiles, service portfolios, and DICT performance evaluations containing information related to the capabilities, qualifications, and previous assessments of cybersecurity service providers participating in the accreditation process.
Deep Web Konek noted that the presence of an organization’s documents in the alleged dataset does not necessarily mean the organization itself was breached, as the records may have been submitted as part of the D-TAP accreditation process.
