SendTech Times
News
MARKET SIGNAL:

Philippine Cyber Teams Take DMW and DOLE Sites Offline After Intrusions

Newsroom brief

The DICT response covered unauthorized access at the migrant workers department, a defaced labor department page and a false-positive ransomware alert at the ports authority.

Verified against source materialEdited by SendTech Times Cybersecurity DeskSource: Back End News
Philippine Cyber Teams Take DMW and DOLE Sites Offline After Intrusions
Image source: Back End News

Philippine cybersecurity teams took two national government web services offline after separate incidents hit the Department of Migrant Workers and a Department of Labor and Employment page, Back End News reported from a DICT update.

The immediate effect was operational rather than theoretical: public-facing services were removed from access while responders checked the systems, cut off affected components and worked through restoration.

The Department of Information and Communications Technology put its Cybersecurity Bureau and the National Computer Emergency Response Team on the response, creating one command path for incidents that touched two agencies.

At the migrant workers department, investigators found unauthorized access to the DMW website.

DICT activated emergency procedures and coordinated with the agency’s Management Information Technology Service, then tightened access controls and isolated parts of the site so the activity could not spread while the breach path was being examined.

The labor department incident followed a different pattern.

NCERT detected changes to a DOLE web host that amounted to page defacement, a lower-level but public form of compromise in which an attacker alters what visitors see.

DOLE administrators were notified, the affected host was isolated and access rules were hardened while the joint review continued.

The most important limit in the DOLE case is what investigators did not find.

Initial checks showed no evidence that sensitive databases or personally identifiable information had been compromised.

That finding keeps the incident in the category of service disruption and public-site tampering for now, rather than a confirmed exposure of citizen or employee records.

The temporary shutdown still matters because it shows how defensive recovery can interrupt government access even when databases remain intact.

Taking a service offline gives responders room to remove remaining threats before reopening the site, but it also leaves users waiting for agencies to restore normal web functions.

A third alert involving the Philippine Ports Authority ended differently.

After reports of a possible ransomware attack, NCERT sent an incident report to PPA administrators and reviewed system logs with the agency.

That check found no ransomware activity and no evidence that the authority’s infrastructure had been compromised.

Ransomware would have raised the stakes because it can lock systems and demand payment before access is restored.

In this case, the PPA warning was treated as a false positive, while the DMW and DOLE incidents remained under active investigation.

DICT’s next task is to move from containment to verified restoration.

NCERT and agency technical teams are continuing recovery work, and further updates are expected when the DMW and DOLE sites reach new milestones rather than simply when the first attack traces are removed.

Share this article
inXf

Related articles

More
OpenAI Widens Cyber AI Access Through Vetted Security Partners
Cybersecurity

OpenAI Widens Cyber AI Access Through Vetted Security Partners

OpenAI is giving approved security vendors and services firms access to cyber AI models while keeping Astra under tighter review for potential misuse risk.

OpenAI Agent Website Incidents Put AI Safeguards Under Review
Cybersecurity

OpenAI Agent Website Incidents Put AI Safeguards Under Review

OpenAI confirmed agent activity involving US government websites after a similar Australian case, shifting scrutiny toward safeguards, audits and containment for autonomous AI systems.

AI-Assisted SharePoint Chain Reaches Unauthenticated Code Execution
Cybersecurity

AI-Assisted SharePoint Chain Reaches Unauthenticated Code Execution

The Hacker News reported that Rapid7 disclosed a SharePoint exploit chain combining unauthenticated user impersonation with a separate remote-code-execution flaw on on-premises Microsoft servers.

Metabase Zero-Day Forces Patch And Breach Checks
Cybersecurity

Metabase Zero-Day Forces Patch And Breach Checks

BleepingComputer reported active exploitation of a critical Metabase SQL injection zero-day affecting cloud and self-hosted deployments, with Framework and Tally disclosing customer data exposure.

UAE Breach Shows $5 Million Ransom Pressure Behind Cyber Threats
Cybersecurity

UAE Breach Shows $5 Million Ransom Pressure Behind Cyber Threats

The National reports that a hacker demanded more than $5 million after breaching a UAE private-sector company, as officials warn that AI, ransomware and misinformation are expanding the country’s cyber risk.

AI Attack Speed Puts Identity Governance At Center Of APAC Security
Cybersecurity

AI Attack Speed Puts Identity Governance At Center Of APAC Security

Frontier Enterprise analysis says AI-assisted attacks are compressing response windows, pushing zero trust, privileged-access controls and non-human identity governance into operational security.

OpenAI Astra Crosses Critical Cyber Threshold Before Restricted Launch
Cybersecurity

OpenAI Astra Crosses Critical Cyber Threshold Before Restricted Launch

OpenAI’s forthcoming Astra model is its first to cross the company’s Critical cybersecurity threshold, with advanced cyber access limited to selected Daybreak organizations.

DOJ Domain Seizures Target QTFY Botnet Alleged To Mask Chinese Hacking
Cybersecurity

DOJ Domain Seizures Target QTFY Botnet Alleged To Mask Chinese Hacking

The U.S. Justice Department seized three domains tied to QTFY, a group accused of using QScan and QTRouter malware to compromise IoT devices and disguise malicious traffic. The case links the infrastructure to critical-infrastructure intrusions dating to 2018 and a NASA-related FBI investigation in 2019.

Keep Reading

More Stories

Latest
Kepler Targets 2027 Production for HBM Replacement MemoryCloud & Data CentersOct 6, 2026Kepler Targets 2027 Production for HBM Replacement MemoryEE Times reports that Kepler Computing is preparing 3D ferroelectric memory for 2027 production, promising higher capacity and bandwidth per watt while limiting reliance on advanced-node lithography.Yokogawa Opens Singapore Hub For Industrial Cyber ResilienceCapital & PolicyOct 6, 2026Yokogawa Opens Singapore Hub For Industrial Cyber ResilienceYokogawa Engineering Asia has launched a Singapore center focused on OT cyber resilience, training, response planning and recovery coordination for Southeast Asia, Oceania and Taiwan.ClickFix Attack Uses Browser Cache To Hide Malware PayloadCybersecurityOct 6, 2026ClickFix Attack Uses Browser Cache To Hide Malware PayloadMicrosoft Threat Intelligence traced a ClickFix cache-smuggling method that preloads malware into browser caches, then uses file size checks and a pasted Run command to launch later credential-theft stages.VOA Tests Six-Month Startup Buildout Before Funding DecisionsFintech & Digital PaymentsOct 6, 2026VOA Tests Six-Month Startup Buildout Before Funding DecisionsTechCabal’s interview with VOA Venture Partners founder Victoria Olayide Adesanya describes a six-month build programme that lets the firm work inside African financial-infrastructure startups before deciding whether to invest.Bitcoin Holds $86,000 As Dollar Index Hits 18-Month HighCrypto/Web3Oct 6, 2026Bitcoin Holds $86,000 As Dollar Index Hits 18-Month HighCoinDesk reported that bitcoin stayed near $86,000 while the U.S. Dollar Index reached about 102.5, with U.S. rate expectations and European political risks strengthening the dollar backdrop.Google Freezes OSS Bug Bounty Reports After AI Submission FloodCybersecurityOct 6, 2026Google Freezes OSS Bug Bounty Reports After AI Submission FloodGoogle has stopped accepting new product vulnerability reports in its OSS VRP after invalid automated submissions swamped reviewers, while older reports and some Cloud VRP routes remain open.Fleuret AI Raises €4M For Continuous AI Pentesting PlatformCybersecurityOct 6, 2026Fleuret AI Raises €4M For Continuous AI Pentesting PlatformTech.eu reported that French startup Fleuret AI raised €4 million in pre-seed funding to develop an agentic-AI platform that turns penetration testing into a continuous security process.GFT Analysis Says AI Documentation Can Cut Maintenance Work 30%Fintech & Digital PaymentsOct 6, 2026GFT Analysis Says AI Documentation Can Cut Maintenance Work 30%A GFT Technologies analysis says AI-linked software documentation can cut maintenance effort and speed developer onboarding when knowledge assets stay synchronized with code changes.Schneider Electric Lines Up $22.6 Billion PTC DealAIOct 5, 2026Schneider Electric Lines Up $22.6 Billion PTC DealSchneider Electric plans to buy PTC in a cash transaction valuing the US engineering software provider’s equity at about $22.6 billion, adding product-lifecycle software to its industrial AI push.Aggarwal Pledges Ola Electric Stake To Fund ₹1,000 Cr Rights IssueCapital & PolicyOct 5, 2026Aggarwal Pledges Ola Electric Stake To Fund ₹1,000 Cr Rights IssueOla Electric founder Bhavish Aggarwal pledged 20 Cr shares to finance his participation in a rights issue that forms part of a larger ₹1,500 Cr fundraising plan.Natrona Schools AI Review Puts Student Privacy Ahead Of Classroom Tool UseAIOct 5, 2026Natrona Schools AI Review Puts Student Privacy Ahead Of Classroom Tool UseNatrona County trustees questioned whether teacher AI tools expose student data, even as existing district rules already ban unauthorized generative AI use by students.AMD Prices 256-Core EPYC 9996 At $14,904 For Server BuyersChips & SemiconductorsOct 5, 2026AMD Prices 256-Core EPYC 9996 At $14,904 For Server BuyersTechRadar reports that AMD’s 6th Gen EPYC 9006 “Venice” lineup includes a 256-core EPYC 9996 with 512 threads, 1GB of L3 cache, a 600W default power rating and a $14,904 list price for 1,000-unit orders.