After a week of back-to-back attacks on government websites, the cleanup phase has produced its first verdicts. The Department of Information and Communications Technology (DICT) declared the reported ransomware attack on the Philippine Ports Authority (PPA) a false positive, and said forensic checks at the Department of Migrant Workers (DMW) and the Department of Labor and Employment (DOLE) found no sensitive databases or personal information exposed.
The PPA scare that wasn't
The PPA alarm began when the Qilin ransomware group listed the agency as a victim on its dark-web leak site, a claim detected on September 5 by threat-intelligence firm SOCRadar. Ransomware groups publish these lists to pressure victims into paying, but a listing is a claim, not proof — groups have been known to post exaggerated or recycled "victims" precisely because the announcement itself causes damage. That is what makes independent verification, rather than the leak-site post, the fact that matters.
DICT's joint verification with PPA personnel found no ransomware activity, no system compromise, and no data breach in the agency's infrastructure. In short: the extortion listing did not match anything actually happening inside PPA's systems.
DMW and DOLE: real intrusions, but no stolen data so far
The two labor agencies were hit by genuine incidents. Unauthorized access was detected on the DMW website, and a DOLE web host was defaced with unauthorized modifications. DICT activated emergency protocols through its National Computer Emergency Response Team, isolated the affected systems, and tightened access controls, according to Back End News.
Preliminary forensic reviews at both agencies reached the same conclusion: no sensitive databases and no personally identifiable information were compromised. Both websites were taken offline as a precaution while root-cause investigations ran, with restoration work under way. DICT has committed to issuing public updates as the DMW and DOLE websites reach recovery milestones, rather than waiting for the investigations to close.
DICT Secretary Henry Aguda said most attack attempts against government systems have been prevented, though some incidents — including an earlier attack on the Maritime Industry Authority (MARINA) — remain under investigation.
Why OFWs were watching this one
The DMW and DOLE findings matter well beyond IT circles. Overseas Filipino workers file contracts, complaints, and personal documents with the DMW, and jobseekers transact with DOLE directly — so the open question all week was whether that data had leaked. DICT's initial answer is no. The caveat: these are preliminary findings, and forensic conclusions can change as investigations go deeper. Anyone who transacts with either agency should still treat unexpected "verification" calls, texts, or emails invoking DMW or DOLE with suspicion, since attackers exploit exactly this kind of news cycle even without stolen data.
The readiness audit continues
The attack wave has already changed standing policy. The 24-hour cyber-readiness reporting order issued to every government agency remains in effect, and the episode adds urgency to the newly opened National Cybersecurity Center, the ₱1.6-billion hub built to monitor government agencies around the clock. Aguda also flagged what comes next on DICT's plate: pending legislation to restrict social media access for minors, which he expects the Senate to pass within about two months.
The wave's real legacy may be less the incidents themselves — so far contained — than the readiness audit they forced on every agency at once. A false positive at PPA is the good outcome; the process that verified it, and the round-the-clock monitoring now standing up, are what get tested by the next real one.