CyberCode.ph · Philippines

DICT Investigates Possible DTAP Data Exposure: What Is Known About 410 Files

Last updated September 28, 2026 · Practical privacy, cybersecurity and technology-law guidance

What happened: The Department of Information and Communications Technology (DICT) said on September 25, 2026 that its National Computer Emergency Response Team (NCERT) is investigating a possible exposure involving companies accredited under its DICT Trusted Assessment Provider (DTAP) program. News reports of the statement refer to about 410 files, roughly 600 MB, associated with 48 companies in the accreditation program. DICT is checking the documents’ authenticity, source and extent of exposure. These figures are preliminary; DICT has not confirmed that its own systems or all 48 companies were breached. If you work for or with a DTAP company, the practical answer is: do not open or share the alleged files, watch for targeted phishing, and ask your organization’s data protection officer whether your records are involved. Newsbytes, September 25, 2026; Philstar, September 27, 2026.

Evidence and action

  • Verified in reporting: DICT publicly acknowledged a possible exposure and said NCERT, under its Cybersecurity Bureau, is handling the incident.
  • Uncertain: The authenticity, origin, full contents, number of affected people and any compromise of a particular company’s system remain under investigation.
  • Source: DICT’s September 25 statement as quoted in news coverage; the file counts and reported contents come from that coverage.
  • Timing: As of September 28, 2026, we found no further public DICT finding. No incident-specific notification deadline has been announced; the general NPC 72-hour rule applies only if its conditions are met (see below).
  • Reader action: Do not forward alleged files. If your organization or records may be affected, contact its privacy or security team through a known channel and preserve suspicious messages. See what to do next.

What DICT has said so far

DICT acknowledged a report of a possible exposure tied to its DTAP accreditation program and said NCERT, under its Cybersecurity Bureau, is verifying the data’s source, nature and extent. As reported, the materials may include corporate registration records, permits, certifications, cybersecurity credentials, employment documents and performance evaluations. DICT said that should the investigation confirm that personal or other protected data was compromised, it will take appropriate action, including notifying affected parties as applicable and in accordance with the Data Privacy Act of 2012. Newsbytes’ account of the DICT statement; Philstar.

A reported online listing is evidence of a claim, not proof that every file is genuine, that all records were publicly accessible, or that any named company’s network was penetrated. DICT has not publicly established the source of the alleged files. We are not reproducing samples or linking to an alleged leak.

What is the DTAP connection?

The DICT Trusted Assessment Provider program accredits providers of cybersecurity assessment services through DICT’s DTAP portal. The reported documents are associated with companies participating in that program. That association alone does not show whether any exposure occurred at DICT, a provider, another custodian or a third party. The investigation needs to establish the data’s provenance and which organization controlled each affected set.

Who might be affected, and what risks matter?

If authentic, corporate documents could disclose business contacts, registration details or security-related information. Employment records and evaluations may contain personal data; any included credentials would raise a more urgent account-security question. The exact fields have not been independently confirmed. The number 48 refers to companies associated with the reported collection, not a verified count of breached systems or affected individuals.

Potential follow-on harm includes targeted phishing that refers to real accreditation documents or staff roles. Treat unexpected requests to verify an account, download a document or provide a one-time code with care. Do not assume a message is legitimate because it mentions DTAP or DICT.

What should an organization do now?

  1. Check exposure through lawful channels. Ask your security or privacy lead whether the organization participated in DTAP and whether DICT or the relevant provider has sent a notice. Avoid downloading alleged files to investigate a rumor.
  2. Preserve evidence. Save original notifications, email headers, suspicious messages, logs and the dates decisions were made. Restrict access to the incident record.
  3. Assess credentials and access. If your own review identifies exposed credentials, rotate them, revoke affected sessions and examine related activity. Do not claim that all credentials in the reported set are compromised without evidence.
  4. Determine data ownership and risk. Identify whether personal data was involved, which entity is the controller or processor, the categories and approximate number of people, unauthorized access and likely harm.
  5. Make the legal notification assessment. The National Privacy Commission’s breach guidance explains when notification is mandatory and says notifications are filed through its Data Breach Notification Management System (DBNMS). A media report alone does not establish that every named company owes an NPC notification.

Does the Philippine 72-hour breach rule apply?

Possibly, but only after the facts meet the applicable notification conditions. The NPC says mandatory notification requires all three of the following: the data involves sensitive personal information or information that may enable identity fraud; there is reason to believe an unauthorized person acquired it; and the breach is likely to give rise to a real risk of serious harm. Where the duty applies, the controller must notify the NPC through the DBNMS and the affected data subjects within 72 hours upon knowledge of or reasonable belief that a breach occurred. The obligation to assess and notify belongs to the appropriate personal information controller even when processing is outsourced. A reported file count does not answer these legal and factual questions. NPC breach-reporting guidance.

What to do next if your records may be involved

Who you are Options and where to go What to keep
Employee or officer of a DTAP-accredited company Write to your company’s data protection officer and ask whether your employment or credential records were in the reported set and what the company is doing. If you receive no adequate answer, or you suffer harm, you may bring the matter to the National Privacy Commission, the agency that enforces the Data Privacy Act. Your written request and the reply, any breach notice you receive, and any suspicious messages that reference your records.
DTAP company or assessment provider Follow the organization steps above; coordinate with DICT NCERT through a known official channel; decide on NPC and data-subject notification through the DBNMS if the three NPC conditions are met. Incident log with dates and times of knowledge, list of affected data categories, containment steps and all correspondence with DICT.
Anyone who receives a phishing message or extortion attempt using the alleged files Do not reply or pay. Report it to the PNP Anti-Cybercrime Group or the NBI cybercrime unit, the law-enforcement bodies for cybercrime; our reporting directory lists the channels. Screenshots showing sender, date and URL; original email headers; any payment demands.

First action today: change nothing based on the rumor alone; instead, confirm with your own security or privacy team whether your organization is among the DTAP participants and whether a notice has been received, and preserve any suspicious message you get in the meantime.

Frequently asked questions

Was DICT hacked?

DICT has acknowledged an investigation into a possible exposure involving its DTAP accreditation program. It has not confirmed that its own systems were compromised.

Were 48 companies breached?

No such conclusion has been established. The number describes companies associated with the reported files, not 48 verified network intrusions.

Should staff change passwords immediately?

Follow your organization’s security team’s instructions. If a credential used for your account is confirmed exposed or there are signs of unauthorized access, rotate it promptly and review active sessions. Never enter a password through a link sent in an unexpected “breach notice.”

Should people share screenshots of the alleged documents?

No. Reposting unverified material can expose personal information further and disrupt verification. Send relevant evidence privately to the responsible organization or investigating authority.

Sources and update note

First reported September 26, 2026. This is a developing incident. We will update the status and impact when DICT or the responsible parties verify further findings.

Sources rechecked as of: September 28, 2026

CyberCode updates

Get practical updates on Philippine technology law, data privacy, cybersecurity, and AI.

Email activity tracking

Unsubscribe any time. See our privacy policy below.