Skip to content

DICT Investigates Claimed Leak of 410 Files From Its D-TAP Cybersecurity Accreditation Program

DICT is investigating a claimed leak of 410 files tied to 48 firms in its D-TAP cybersecurity accreditation program, posted by a threat actor called core849.

Argal
Argal
••3 min read
Rows of server racks lining an aisle inside a data center
A server aisle inside a data center.

The Department of Information and Communications Technology (DICT) is investigating a hacker's claim that internal files from its Trusted Assessment Provider program, known as D-TAP, have been exposed online. D-TAP is the accreditation scheme that vets cybersecurity firms before government agencies are allowed to hire them — which is exactly why a leak claim against it carries weight even while it remains unverified.

What was claimed

A threat actor using the alias "core849" posted the claim on September 24. The collection is described as roughly 600 MB of data — about 770 MB uncompressed — containing 410 files linked to 48 companies, according to ASTIG.ph, which cited monitoring by the cybersecurity watchers at Deep Web Konek. The same alias was linked to a claimed breach of LTFRB records on September 19, which pushed the transport regulator to take its records system offline.

Based on DICT's own description, the files may include:

  • Corporate registration records and permits
  • Certifications and cybersecurity credentials
  • Employment documents
  • DICT performance evaluations of accredited firms

Documents in the alleged dump reportedly reference well-known names, including Globe, KPMG Philippines, Netrust, Radenta, and Make Technology. One caution matters here: appearing in the collection does not establish that any of those companies' own systems were breached. The files describe them because they went through, or dealt with, the accreditation process.

What DICT has confirmed — and what it has not

DICT acknowledged the report on September 25. "The incident is currently being handled by the National Computer Emergency Response Team (NCERT)," the department said in a statement, referring to the response unit under its Cybersecurity Bureau. Investigators are still verifying whether the documents are authentic, where they came from, and how far the exposure goes. DICT has not confirmed that its own systems were compromised, and it has pledged to notify affected parties under the Data Privacy Act (Republic Act 10173) if a real compromise is established.

Independent reporting on the incident is still limited — as of publication, only a small number of outlets have covered the claim, and the authenticity of the files has not been established by anyone outside the actor who posted them. That uncertainty cuts both ways: the dump could be overstated, or the full extent could still be unknown.

Why a leak claim against a trust program stings

D-TAP exists so that government agencies can trust the security firms they hire. If files from that vetting process were exposed, the damage is less about the file sizes and more about confidence in the pipeline itself — the paperwork of the very companies certified to protect government systems. It also lands at an awkward moment: DICT has been actively building out its security-assurance machinery, from a centralized portal for verifying accredited cybersecurity testing labs to the new Korea-funded National Cybersecurity Center that monitors 25 agencies around the clock.

For the named companies, the immediate exposure is reputational rather than technical. For agencies that rely on D-TAP accreditation when contracting security services, the practical question is whether any credentials or evaluation details in the dump could be abused for social engineering — impersonating an accredited firm is an obvious follow-on risk if the documents are genuine.

What to watch next

Three things will define how serious this becomes: whether NCERT confirms the files are authentic, whether the point of exposure was a DICT system or a third party, and whether affected firms receive formal breach notifications under the Data Privacy Act. Until then, this remains a claimed exposure under active investigation — worth taking seriously, but not yet a confirmed government data breach.

Argal

Argal

@clurky

Clurky is a Philippine tech news site owned and run by Argal, a Philippines-born software developer based in Singapore with a Computer Science background. He covers Philippine tech, fintech, and digital services - from gadgets and AI to software and security - along with evergreen guides and explainers, all with a builder's eye for how these systems actually work. Every article is fact-checked against primary sources.

455 posts

Comments

Join the conversation

Sign in to leave a comment and reply to others.

Sign in
Loading comments...