DICT Trusted Assessment Provider: DICT probes possible data breach involving 48 firms in accreditation program

DICT Trusted Assessment Provider: DICT probes possible data breach involving 48 firms in accreditation program

Potential Data Breach Exposes Sensitive Information of 48 Firms in DICT Accreditation Program

The Department of Information and Communications Technology (DICT) has reported a possible data breach involving 48 companies enrolled in its DICT Trusted Assessment Provider (DTAP) program. The incident, disclosed on Friday, may have exposed approximately 410 files totaling 600 MB (770 MB uncompressed) containing sensitive corporate and security-related data.

The DTAP program partners with local cybersecurity service providers to assess and fortify digital systems before public deployment. The compromised files may include corporate registration records, permits, certifications, cybersecurity credentials, employment documents, and DICT performance evaluations.

The National Computer Emergency Response Team (NCERT), under the DICT Cybersecurity Bureau, is leading the investigation to determine the breach’s source, nature, and scope. While the exposure remains unverified, the DICT has assured stakeholders that the matter is being actively addressed. If confirmed, the agency will take corrective action and notify affected parties in compliance with the Data Privacy Act of 2012 (Republic Act 10173).

Authorities have urged caution in sharing unverified details as the probe continues. The incident highlights risks in third-party accreditation processes and the potential exposure of critical infrastructure data.

Source: https://www.gmanetwork.com/news/topstories/nation/1003779/dict-probes-possible-data-breach-involving-48-firms-in-accreditation-program/story/

DICT Trusted Assessment Provider TPRM report: https://www.rankiteo.com/company/dictgovph

"id": "dic1790404037",
"linkid": "dictgovph",
"type": "Breach",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Cybersecurity, IT Services',
                        'location': 'Philippines',
                        'name': '48 companies enrolled in DICT Trusted '
                                'Assessment Provider (DTAP) program',
                        'type': 'Cybersecurity Service Providers'}],
 'data_breach': {'number_of_records_exposed': '410 files (600 MB compressed, '
                                              '770 MB uncompressed)',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': 'Corporate and security-related '
                                             'data'},
 'date_publicly_disclosed': '2023-10-13',
 'description': 'The Department of Information and Communications Technology '
                '(DICT) has reported a possible data breach involving 48 '
                'companies enrolled in its DICT Trusted Assessment Provider '
                '(DTAP) program. The incident may have exposed approximately '
                '410 files totaling 600 MB (770 MB uncompressed) containing '
                'sensitive corporate and security-related data, including '
                'corporate registration records, permits, certifications, '
                'cybersecurity credentials, employment documents, and DICT '
                'performance evaluations.',
 'impact': {'data_compromised': 'Corporate registration records, permits, '
                                'certifications, cybersecurity credentials, '
                                'employment documents, DICT performance '
                                'evaluations',
            'identity_theft_risk': 'High'},
 'investigation_status': 'Ongoing (led by National Computer Emergency Response '
                         'Team - NCERT)',
 'lessons_learned': 'Highlights risks in third-party accreditation processes '
                    'and potential exposure of critical infrastructure data',
 'references': [{'source': 'Department of Information and Communications '
                           'Technology (DICT)'}],
 'regulatory_compliance': {'regulations_violated': 'Potential violation of '
                                                   'Data Privacy Act of 2012 '
                                                   '(Republic Act 10173)',
                           'regulatory_notifications': 'Planned if breach is '
                                                       'confirmed'},
 'response': {'communication_strategy': 'Public disclosure and stakeholder '
                                        'advisories',
              'incident_response_plan_activated': 'Yes',
              'remediation_measures': 'Corrective action and notifications to '
                                      'affected parties (if confirmed)'},
 'stakeholder_advisories': 'Urged caution in sharing unverified details',
 'title': 'Potential Data Breach Exposes Sensitive Information of 48 Firms in '
          'DICT Accreditation Program',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.