Philippine Cyber Teams Take DMW and DOLE Sites Offline After Intrusions
The DICT response covered unauthorized access at the migrant workers department, a defaced labor department page and a false-positive ransomware alert at the ports authority.

Philippine cybersecurity teams took two national government web services offline after separate incidents hit the Department of Migrant Workers and a Department of Labor and Employment page, Back End News reported from a DICT update.
The immediate effect was operational rather than theoretical: public-facing services were removed from access while responders checked the systems, cut off affected components and worked through restoration.
The Department of Information and Communications Technology put its Cybersecurity Bureau and the National Computer Emergency Response Team on the response, creating one command path for incidents that touched two agencies.
At the migrant workers department, investigators found unauthorized access to the DMW website.
DICT activated emergency procedures and coordinated with the agency’s Management Information Technology Service, then tightened access controls and isolated parts of the site so the activity could not spread while the breach path was being examined.
The labor department incident followed a different pattern.
NCERT detected changes to a DOLE web host that amounted to page defacement, a lower-level but public form of compromise in which an attacker alters what visitors see.
DOLE administrators were notified, the affected host was isolated and access rules were hardened while the joint review continued.
The most important limit in the DOLE case is what investigators did not find.
Initial checks showed no evidence that sensitive databases or personally identifiable information had been compromised.
That finding keeps the incident in the category of service disruption and public-site tampering for now, rather than a confirmed exposure of citizen or employee records.
The temporary shutdown still matters because it shows how defensive recovery can interrupt government access even when databases remain intact.
Taking a service offline gives responders room to remove remaining threats before reopening the site, but it also leaves users waiting for agencies to restore normal web functions.
A third alert involving the Philippine Ports Authority ended differently.
After reports of a possible ransomware attack, NCERT sent an incident report to PPA administrators and reviewed system logs with the agency.
That check found no ransomware activity and no evidence that the authority’s infrastructure had been compromised.
Ransomware would have raised the stakes because it can lock systems and demand payment before access is restored.
In this case, the PPA warning was treated as a false positive, while the DMW and DOLE incidents remained under active investigation.
DICT’s next task is to move from containment to verified restoration.
NCERT and agency technical teams are continuing recovery work, and further updates are expected when the DMW and DOLE sites reach new milestones rather than simply when the first attack traces are removed.




















