Alleged DICT D-TAP Breach Exposes 410 Files Linked to 48 Companies
A threat actor using the alias “core849” has allegedly leaked documents linked to the Department of Information and Communications Technology’s (DICT) Trusted Assessment Provider (D-TAP) accreditation program.
https://iili.io/nRFndGf.png
The post, published on a forum on September 24, 2026, claims to contain 410 files involving 48 companies, with the threat actor mentioning organizations including Globe, KPMG Philippines, Netrust, Radenta and Make Technology. The post lists the collection at around 600 MB, while the extracted files are reportedly approximately 770 MB uncompressed.
The alleged dataset reportedly contains corporate and legal documents such as SEC and BIR registrations, business permits, PhilGEPS certifications, notarized applications and attestations, as well as clearances and employment certificates. It also allegedly includes cybersecurity-related records such as CREST certifications, SOC 2 audit documentation, ISO 27001 and ISO 9001 certificates, and individual cybersecurity certifications.
https://iili.io/nRFnJCG.png
Other files reportedly include company profiles, service portfolios and DICT performance evaluations, potentially containing information about the capabilities, qualifications and previous assessments of cybersecurity service providers participating in the accreditation process.
The appearance of an organization's documents in the alleged dataset does not necessarily mean that the company itself was breached. The records may have been submitted as part of the D-TAP accreditation process, and the available screenshots do not establish how the documents were obtained or whether DICT infrastructure was directly compromised.
DICT has yet to publicly confirm the alleged leak, the authenticity of the documents, the number of affected organizations or the source of the exposure.
Other contents