Black Lotus Ransomware Claims City Government of Navotas Data Breach

The Black Lotus Ransomware Group has claimed responsibility for an alleged cyberattack against the City Government of Navotas, Philippines, claiming that it obtained a large volume of citizen identification records from the city's systems. In a post dated August 24, the threat actor claimed to have obtained the city's citizen ID database, allegedly containing 62.5 GB of scanned identification documents and related personal information. According to the group, the alleged data includes names, addresses, birthdates, identification numbers, and photographs. The threat actor also provided samples that it claimed were taken from the allegedly compromised database. The samples containing 25,813 PNG files with a total size of approximately 3.60 GB. The DWK team independently reviewed and validated the samples provided by the threat actor and found that the dataset contains identification cards and selfies belonging to citizens of Navotas. This validation provides additional indication that the samples are connected to citizen records, although it does not independently establish the full scope of the alleged 62.5 GB dataset or confirm how the data was obtained. The file-properties screenshot alone does not establish that all of the files originated from the City Government of Navotas. However, the combination of the directory naming, the threat actor's claim, and the team's review of the provided samples raises significant concerns regarding the potential exposure of personal information belonging to Navotas residents. Black Lotus further claimed that the alleged data was extracted from the city's systems "days ago" and issued a deadline of August 30 for the city government to contact the group regarding payment. The claimed 62.5 GB total and the 3.60 GB sample shown in the first image should be treated separately, as the screenshot only demonstrates the size of the particular collection displayed and does not independently verify the threat actor's claimed overall dataset size. As of this report, the full extent of the alleged breach remains unclear. No official statement from the City Government of Navotas confirming or denying the ransomware group's claims was available in the information reviewed for this report.

Other contents

New Home For Deep Web Konek

New Home For Deep Web Konek

Suspected Chinese-Speaking Operator Targeted Philippine Nuclear Agency, Naval Contractor

Suspected Chinese-Speaking Operator Targeted Philippine Nuclear Agency, Naval Contractor

Black Lotus Ransomware Claims City Government of Navotas Data Breach

Black Lotus Ransomware Claims City Government of Navotas Data Breach

When Violence Becomes Content: We Must Look Beyond the Classroom

When Violence Becomes Content: We Must Look Beyond the Classroom

Emperador Ransomware Claims Baguio City Government Data

Emperador Ransomware Claims Baguio City Government Data

After Every Conversation, We Need More Than a Platform to Blame

After Every Conversation, We Need More Than a Platform to Blame

Cybersecurity Incidents in the Philippines Nearly Doubled, Official NPC Data Shows

Cybersecurity Incidents in the Philippines Nearly Doubled, Official NPC Data Shows

Alleged Data Breach Targets DENR's Mines and Geosciences Bureau

Alleged Data Breach Targets DENR's Mines and Geosciences Bureau

Alleged NTC Data Breach Claimed by DeathNote Hackers

Alleged NTC Data Breach Claimed by DeathNote Hackers

House of Representatives Website Defaced, Attackers Post Anti-Corruption Message

House of Representatives Website Defaced, Attackers Post Anti-Corruption Message