DOLE-NCR Systems Allegedly Exposed in 10GB Leak

The National Capital Region office of the Department of Labor and Employment (DOLE-NCR) is the subject of an alleged data breach after a threat actor claimed to have obtained approximately 10GB of data from the agency's systems. The claim was posted on September 7, 2026, by a forum user identified as “chaos76.” A screenshot accompanying the post was titled “Philippine Department of Labor and Employment NCR Region SRC + DB Leak (10GB)” and was marked as a breach or leak involving DOLE-NCR. The screenshots show what appears to be a directory listing, containing numerous folders associated with DOLE-NCR applications and systems. Among the visible directories are AIMS, ATS, CaseTracker, CRTHDB, DMS, DNCC, GIP, HRIMS, HRIMS_old, and DOLE-NCR-related identifiers. Several directories shown in the screenshot are relatively large. For example, the displayed listing includes CRTHDB at approximately 1.7GB, GIP at 3.6GB, DNCC at 382.4MB, HRIMS at 537.4MB, DOLE-NCR ID at 744.3MB, and other application directories ranging from several megabytes to hundreds of megabytes. The screenshot therefore appears to show a substantial amount of data stored within the alleged compromised web-hosting environment. The apparent system names nevertheless indicate potentially significant exposure. DOLE-NCR's official applications portal lists systems including Asset Inventory Monitoring System (AIMS), Attendance Tracking System (ATS), Case Tracker, Complaints Monitoring System (CRTH), Document Management System (DMS), DOLE-NCR Command Center (DNCC), Government Internship Program (GIP), and Human Resource Information Management System (HRIMS). The presence of similarly named directories in the leaked directory listing could indicate that the compromised environment hosted multiple DOLE-NCR applications. However, directory names alone do not prove that the corresponding databases or records were successfully exfiltrated. The alleged breach follows a separate DOLE-NCR web defacement reported several days earlier. On September 6, 2026, users reported that the DOLE-NCR client portal had been compromised and displayed offensive and explicit material. Online reports also described the defacement as containing hateful and offensive comments, including antisemitic material. The incident affected a publicly accessible DOLE-NCR web presence. DOLE-NCR operates several online systems and identifies its Client Portal as a platform through which users can submit requests, applications and reports. It is not yet established that the earlier defacement and the newly claimed 10GB leak were carried out through the same intrusion or by the same actor.

Other contents

New Home For Deep Web Konek

New Home For Deep Web Konek

DOLE-NCR Systems Allegedly Exposed in 10GB Leak

HappyGoLuckyPH Group Claims Massive Network Breach and Defacement Targeting DMW

HappyGoLuckyPH Group Claims Massive Network Breach and Defacement Targeting DMW

Philippine IDs for Sale: DWK Tracks More Than 9,000 Suspected Fraudulent Document Offers

Philippine IDs for Sale: DWK Tracks More Than 9,000 Suspected Fraudulent Document Offers

MyBusybee Allegedly Exposed 60GB of SMS Data

MyBusybee Allegedly Exposed 60GB of SMS Data

Law Firm Website Defaced as Hacktivist Invokes Vice President Impeachment Trial

Law Firm Website Defaced as Hacktivist Invokes Vice President Impeachment Trial

Suspected Chinese-Speaking Operator Targeted Philippine Nuclear Agency, Naval Contractor

Suspected Chinese-Speaking Operator Targeted Philippine Nuclear Agency, Naval Contractor

Black Lotus Ransomware Claims City Government of Navotas Data Breach

Black Lotus Ransomware Claims City Government of Navotas Data Breach

When Violence Becomes Content: We Must Look Beyond the Classroom

When Violence Becomes Content: We Must Look Beyond the Classroom

Emperador Ransomware Claims Baguio City Government Data

Emperador Ransomware Claims Baguio City Government Data