Skip to content

DICT Calls the PPA 'Ransomware' a False Positive as DMW and DOLE Checks Find No Data Breach

DICT says the reported PPA ransomware attack was a false positive, while forensic checks at DMW and DOLE found no sensitive data exposed as sites are restored.

Argal
Argal
3 min read
Laptops on a desk
Stock image of laptops used in coverage of DICT's cyber incident updates. Photo: Technobaboy

After a week of back-to-back attacks on government websites, the cleanup phase has produced its first verdicts. The Department of Information and Communications Technology (DICT) declared the reported ransomware attack on the Philippine Ports Authority (PPA) a false positive, and said forensic checks at the Department of Migrant Workers (DMW) and the Department of Labor and Employment (DOLE) found no sensitive databases or personal information exposed.

The PPA scare that wasn't

The PPA alarm began when the Qilin ransomware group listed the agency as a victim on its dark-web leak site, a claim detected on September 5 by threat-intelligence firm SOCRadar. Ransomware groups publish these lists to pressure victims into paying, but a listing is a claim, not proof — groups have been known to post exaggerated or recycled "victims" precisely because the announcement itself causes damage. That is what makes independent verification, rather than the leak-site post, the fact that matters.

DICT's joint verification with PPA personnel found no ransomware activity, no system compromise, and no data breach in the agency's infrastructure. In short: the extortion listing did not match anything actually happening inside PPA's systems.

DMW and DOLE: real intrusions, but no stolen data so far

The two labor agencies were hit by genuine incidents. Unauthorized access was detected on the DMW website, and a DOLE web host was defaced with unauthorized modifications. DICT activated emergency protocols through its National Computer Emergency Response Team, isolated the affected systems, and tightened access controls, according to Back End News.

Preliminary forensic reviews at both agencies reached the same conclusion: no sensitive databases and no personally identifiable information were compromised. Both websites were taken offline as a precaution while root-cause investigations ran, with restoration work under way. DICT has committed to issuing public updates as the DMW and DOLE websites reach recovery milestones, rather than waiting for the investigations to close.

DICT Secretary Henry Aguda said most attack attempts against government systems have been prevented, though some incidents — including an earlier attack on the Maritime Industry Authority (MARINA) — remain under investigation.

Why OFWs were watching this one

The DMW and DOLE findings matter well beyond IT circles. Overseas Filipino workers file contracts, complaints, and personal documents with the DMW, and jobseekers transact with DOLE directly — so the open question all week was whether that data had leaked. DICT's initial answer is no. The caveat: these are preliminary findings, and forensic conclusions can change as investigations go deeper. Anyone who transacts with either agency should still treat unexpected "verification" calls, texts, or emails invoking DMW or DOLE with suspicion, since attackers exploit exactly this kind of news cycle even without stolen data.

The readiness audit continues

The attack wave has already changed standing policy. The 24-hour cyber-readiness reporting order issued to every government agency remains in effect, and the episode adds urgency to the newly opened National Cybersecurity Center, the ₱1.6-billion hub built to monitor government agencies around the clock. Aguda also flagged what comes next on DICT's plate: pending legislation to restrict social media access for minors, which he expects the Senate to pass within about two months.

The wave's real legacy may be less the incidents themselves — so far contained — than the readiness audit they forced on every agency at once. A false positive at PPA is the good outcome; the process that verified it, and the round-the-clock monitoring now standing up, are what get tested by the next real one.

Argal

Argal

@clurky

Clurky is a Philippine tech news site owned and run by Argal, a Philippines-born software developer based in Singapore with a Computer Science background. He covers Philippine tech, fintech, and digital services - from gadgets and AI to software and security - along with evergreen guides and explainers, all with a builder's eye for how these systems actually work. Every article is fact-checked against primary sources.

371 posts

Comments

Join the conversation

Sign in to leave a comment and reply to others.

Sign in
Loading comments...