The Department of Information and Communications Technology (DICT) is investigating a hacker's claim that internal files from its Trusted Assessment Provider program, known as D-TAP, have been exposed online. D-TAP is the accreditation scheme that vets cybersecurity firms before government agencies are allowed to hire them — which is exactly why a leak claim against it carries weight even while it remains unverified.
What was claimed
A threat actor using the alias "core849" posted the claim on September 24. The collection is described as roughly 600 MB of data — about 770 MB uncompressed — containing 410 files linked to 48 companies, according to ASTIG.ph, which cited monitoring by the cybersecurity watchers at Deep Web Konek. The same alias was linked to a claimed breach of LTFRB records on September 19, which pushed the transport regulator to take its records system offline.
Based on DICT's own description, the files may include:
- Corporate registration records and permits
- Certifications and cybersecurity credentials
- Employment documents
- DICT performance evaluations of accredited firms
Documents in the alleged dump reportedly reference well-known names, including Globe, KPMG Philippines, Netrust, Radenta, and Make Technology. One caution matters here: appearing in the collection does not establish that any of those companies' own systems were breached. The files describe them because they went through, or dealt with, the accreditation process.
What DICT has confirmed — and what it has not
DICT acknowledged the report on September 25. "The incident is currently being handled by the National Computer Emergency Response Team (NCERT)," the department said in a statement, referring to the response unit under its Cybersecurity Bureau. Investigators are still verifying whether the documents are authentic, where they came from, and how far the exposure goes. DICT has not confirmed that its own systems were compromised, and it has pledged to notify affected parties under the Data Privacy Act (Republic Act 10173) if a real compromise is established.
Independent reporting on the incident is still limited — as of publication, only a small number of outlets have covered the claim, and the authenticity of the files has not been established by anyone outside the actor who posted them. That uncertainty cuts both ways: the dump could be overstated, or the full extent could still be unknown.
Why a leak claim against a trust program stings
D-TAP exists so that government agencies can trust the security firms they hire. If files from that vetting process were exposed, the damage is less about the file sizes and more about confidence in the pipeline itself — the paperwork of the very companies certified to protect government systems. It also lands at an awkward moment: DICT has been actively building out its security-assurance machinery, from a centralized portal for verifying accredited cybersecurity testing labs to the new Korea-funded National Cybersecurity Center that monitors 25 agencies around the clock.
For the named companies, the immediate exposure is reputational rather than technical. For agencies that rely on D-TAP accreditation when contracting security services, the practical question is whether any credentials or evaluation details in the dump could be abused for social engineering — impersonating an accredited firm is an obvious follow-on risk if the documents are genuine.
What to watch next
Three things will define how serious this becomes: whether NCERT confirms the files are authentic, whether the point of exposure was a DICT system or a third party, and whether affected firms receive formal breach notifications under the Data Privacy Act. Until then, this remains a claimed exposure under active investigation — worth taking seriously, but not yet a confirmed government data breach.