Data Breach Hits DENR’s Environmental Management Bureau Integrated Information System
The group, DeathNote Hackers (DNH) has claimed responsibility for a new data breach affecting the Department of Environment and Natural Resources’ Environmental Management Bureau (DENR-EMB) Integrated Information System (IIS).
In a forum post published, DNH said they were able to exploit unsecured API calls within EMB’s IIS platform, leading to the exposure of millions of lines. According to the group, the breach was made possible through what they described as an “Authenticated Scrape” attack, targeting unprotected endpoints in the system.
The hackers shared multiple JSON-format dumps allegedly extracted from EMB’s IIS, including:
• 3,825,465 records from a company list
• 973,610 records from a client list
• 34,344 records from an “Extras” file
• 22,465 records from personnel-related files
In total, the attackers claimed there are as many as 17 million lines in the system, although they said they refrained from scraping the entirety of the data.
The exposed information reportedly includes sensitive details such as full names, usernames, contact numbers, emails, employee tokens, client IDs, EMB IDs, company names, and project names.
DNH criticized EMB for allegedly leaving its system “unsecured,” despite a previous incident where EMB’s IIS was defaced by a foreign hacker around eleven months ago. In their statement, the group mocked the bureau for failing to strengthen its cybersecurity posture and warned that critical data should not be left vulnerable.
The Environmental Management Bureau (EMB) is tasked with enforcing pollution prevention and control measures across the Philippines. It also manages the Environmental Impact Assessment (EIA) system, toxic and hazardous waste regulations, and environmental partnership programs. EMB plays a crucial role in promoting compliance and sustainability in industries nationwide.
As of this writing, neither EMB nor the Department of Environment and Natural Resources (DENR) has issued an official statement regarding the alleged breach.
Other contents