Compliance · · 3 min read
DICT investigates possible exposure of data from 48 companies
The Philippine communications department is checking whether hundreds of files linked to accredited firms were exposed in a possible data breach.
The Philippines’ Department of Information and Communications Technology is examining a possible data breach involving 48 companies enrolled in its accredited trust assessment provider program, according to reporting by qa.philstar.com.
The department said about 410 files connected with the companies may have become accessible. Together, the material represents roughly 600 megabytes of data, or about 770 megabytes in uncompressed form.
DICT has not established that the information was definitively compromised. Its inquiry is intended to determine whether an exposure occurred and, if so, what information was involved, where it came from and how extensive it was.
Records potentially involved
The files under review may include a broad range of corporate and workplace documents. The list includes company registration records, permits and certifications, as well as cybersecurity-related credentials.
Employment documents may also be among the material that was exposed. The department’s own performance assessments of the companies are included in the group of files being examined.
The possible presence of these records has prompted the department to focus on both the authenticity of the data and the circumstances surrounding its reported exposure. The investigation will also assess the nature of the material, rather than treating all files as having the same level of sensitivity.
At this stage, the department has not said that every file was accessed or that all 48 companies were affected in the same way. The figures released describe the number and approximate size of files that may have been exposed, while the investigation is expected to establish what actually happened.
Possible privacy obligations
If the review confirms that personal information or other protected data was compromised, DICT said it would respond under the country’s Data Privacy Act, also known as Republic Act 10173.
That response would include notifying the companies concerned, the department said. The statement indicates that any action will depend on the investigation’s findings and on whether the material is determined to fall within relevant privacy or protection requirements.
The law matters because the files may extend beyond ordinary corporate paperwork. Employment records can contain information about individuals, while credentials and evaluation documents may reveal details about a company’s security arrangements or compliance position. The article does not establish which specific records contain protected information, making the department’s verification process central to determining the consequences.
Assurance to accredited providers
DICT also sought to reassure the assessment providers participating in the program that it is addressing the reported incident. The department said it remains committed to protecting information entrusted to it and preserving the integrity of the accreditation system.
Its investigation will therefore serve two purposes: finding out whether data was actually exposed and assessing whether affected organizations must be informed or other measures taken. Until those questions are answered, the reported incident remains a potential breach rather than a confirmed compromise.
The inquiry also places attention on the documents gathered through an accreditation process. Corporate records, permits, certifications, cybersecurity credentials, employee-related files and departmental evaluations can together provide a detailed picture of the companies involved. Determining how those materials may have been exposed, and limiting any further risk, will be among the issues DICT must resolve.
qa.philstar.com reported that the department had launched the investigation and had not yet released a final determination about the source, authenticity or full scope of the data in question.