Philippine Red Cross Database Allegedly Offered for Sale After Cyberattack
MANILA, Philippines — A threat actor group identifying itself as Infrastructure Destruction Squad/BLACKNET-00 claims to have compromised data associated with the Philippine Red Cross (PRC) and is offering an alleged database of approximately 34.7 GB for sale at US$600.
https://iili.io/nnzClNp.png
The threat actor identifies the dataset as the Philippines Red Cross (PRC) Donor Database. However, based on the fields advertised and additional information surrounding the alleged dataset, the records may encompass more than donors alone. The database reportedly includes information on individuals who participated in PRC activities, including first aid training participants who may subsequently be considered or classified as volunteers.
The alleged database contains extensive personal information, including full names, gender and age, alongside location details such as street address, barangay, province, ZIP code and GPS coordinates. Contact information allegedly includes telephone numbers, mobile numbers and email addresses.
https://iili.io/nnzC7UJ.jpg
https://iili.io/nnzC0DN.jpg
The listing also includes fields specifically associated with donation records, including payment date, donation amount, donation type and check number. This indicates that donor-related information may form part of the dataset advertised by the threat actor, even if the overall database potentially contains records concerning volunteers and first aid training participants as well.
Additional classification fields allegedly include PRC chapter or branch, category and donor ID numbers. Depending on how PRC internally structures its databases, these fields could potentially link individuals to particular chapters, programs or organizational classifications.
Screenshots circulated by the threat actor show a large tabular dataset and file metadata indicating a size of 37,366,057,753 bytes, or approximately 34.7 GB. The displayed metadata shows the file was created on September 14, 2026, at approximately 7:54 p.m. and modified later that evening.
The group claims that the alleged compromise involved an unauthenticated file-upload vulnerability, which allegedly allowed attackers to upload arbitrary files without authentication. The actors further claim that they used the access to establish a backdoor within the compromised environment.
The distinction is important: while the threat actor explicitly markets the material as a “Donor Database,” the additional information indicates that the database may contain a broader population of people connected with Philippine Red Cross programs. Donors, volunteers and first aid training participants should therefore be treated as potentially affected groups pending verification of the dataset.
Other contents