Skip to content

DICT and CICC Give Every Government Agency 24 Hours to Report Its Cyber Readiness After the DMW and DOLE Attacks

DICT and CICC gave all agencies, GOCCs, LGUs and critical-infrastructure operators 24 hours to file a one-page cyber readiness report after the DMW intrusion.

Argal
Argal
5 min read
Illustration representing an online scam or cyber threat
Illustration of an online threat, used with Newsbytes.PH's report on the DICT-CICC advisory. Image: Newsbytes.PH

Every national government agency, government-owned corporation, local government unit and critical-infrastructure operator in the Philippines has been given 24 hours to put a one-page cyber readiness assessment in front of its head or chief executive. The order comes in a joint cybersecurity advisory from the Department of Information and Communications Technology (DICT) and the Cybercrime Investigation and Coordinating Center (CICC), dated September 8 and first reported by Newsbytes.PH. It follows confirmed unauthorized access to the Department of Migrant Workers (DMW) website and the defacement of a Department of Labor and Employment (DOLE) web host.

What agencies must do within 24 hours

The advisory places all covered organizations on heightened cyber vigilance. Within 24 hours of receiving it, each must report to its agency head or chief executive a one-page assessment that identifies its most serious risks, the immediate actions it has taken, and the help it needs. The priority measures, as reported by both Newsbytes.PH and BusinessMirror, are:

  • Fix critical vulnerabilities.
  • Enforce multi-factor authentication (MFA, a second login step beyond a password) on critical and privileged accounts.
  • Remove unnecessary internet exposure of systems.
  • Strengthen security monitoring.
  • Verify that backups can actually be restored.
  • Review third-party access.
  • Test incident-response and service-continuity procedures.

Readiness is graded on a green-amber-red scale. Red requires immediate reporting and response, amber requires remediation and monitoring, and green calls for continued vigilance — the advisory states that green does not mean the absence of risk. Agencies must not wait for the 24-hour window to close before reporting a suspected serious incident.

The two agencies described the deadline as a trigger for urgent action, not a declaration that risks have been removed, and said the exercise “must produce protective action, not merely another compliance report.” They put responsibility on agency heads and chief executives to lead implementation, and stated that reminding employees and the public to be careful does not reduce the government's own obligation to secure the systems and data entrusted to it.

What triggered the advisory

Three incidents, one of them unfounded, set the stage:

  • DMW. A hacktivist group calling itself HappyGoLuckyPH claimed it had been inside the DMW's Active Directory environment (the system that controls logins and permissions across an organization's network) for more than a month, compromised a domain controller, and could reach internal systems, databases and security-management consoles, including repositories of worker, recruitment, contract and financial records, Newsbytes.PH reported on September 8. DICT's National Computer Emergency Response Team (NCERT) isolated affected systems and tightened access controls. As of September 10, neither the DMW nor DICT had published a technical assessment confirming how deep the intrusion went or whether data was viewed or copied.
  • DOLE. A DOLE web host was modified without authorization. DICT's initial assessment found no compromise of sensitive databases or personal information, and the affected node was isolated.
  • PPA. A reported ransomware attack on the Philippine Ports Authority was checked jointly with PPA staff. DICT said a review of system logs found no ransomware activity and no breach, and called the report a false positive. DICT Secretary Henry Aguda has said most attacks on government systems are being stopped, while acknowledging that some incidents are still being addressed.

Both the DMW and DOLE web services were taken offline for forensic work and restoration.

The Marina breach is the cautionary case

The advisory's emphasis on backups and restoration reads as a response to the Maritime Industry Authority (Marina). Its Seafarer's Identity Document and Seafarer's Record Book system was hit in mid-August: Marina reported the incident to DICT's cybersecurity bureau on August 13, confirmed the hack on August 14 and suspended issuance of the documents, which Filipino seafarers need to deploy overseas, BusinessMirror reported. As of BusinessMirror's September 10 report, that system had still not been restored, nearly a month later.

What this means for OFWs and seafarers

The two agencies most affected hold data on Filipinos working abroad. The DMW processes contracts and records for overseas Filipino workers; Marina issues the credentials seafarers must carry. The records HappyGoLuckyPH claims to have reached — identity documents, contracts and financial data — are the kind used in identity fraud, which is why the missing DMW assessment matters more than the defaced web pages. Until the agency publishes its findings, OFWs and their families should treat unexpected calls or messages that cite DMW contract or recruitment details with suspicion.

The advisory also lands while the government's own round-the-clock monitoring capacity is still being built: the Korea-funded National Cybersecurity Center that will watch over 25 agencies only broke ground this month.

What happens next

DICT and CICC committed to issuing verified public updates on incidents that affect government services, separating confirmed findings from preliminary assessments and saying when more information will follow. They also said any attribution to individuals, organizations or foreign actors will rest on validated evidence rather than speculation.

As of publication, the full text of the joint advisory had not been posted on the DICT or CICC websites; its contents are as reported by the outlets that obtained it. The DMW's detailed assessment of the intrusion is the next document to watch.

Argal

Argal

@clurky

Clurky is a Philippine tech news site owned and run by Argal, a Philippines-born software developer based in Singapore with a Computer Science background. He covers Philippine tech, fintech, and digital services - from gadgets and AI to software and security - along with evergreen guides and explainers, all with a builder's eye for how these systems actually work. Every article is fact-checked against primary sources.

366 posts

Comments

Join the conversation

Sign in to leave a comment and reply to others.

Sign in
Loading comments...