The Land Transportation Franchising and Regulatory Board (LTFRB) has confirmed a data breach and taken its LTFRB Electronic Support System (LESS) offline, suspending all services and transactions that run through the platform until further notice. The agency announced the shutdown on September 19, and it has not given a timetable for restoring the system.
LESS is the online platform the franchising regulator uses to process applications and transactions for public utility vehicle (PUV) operators and drivers. With it offline, transactions handled through the system are on hold while investigators work through what happened.
What the LTFRB has confirmed so far
The agency's statement is deliberately careful. "The incident generally affected the LESS data environment; however, the specific data involved and the full extent of the impact remain subject to technical validation," the LTFRB said, according to ASTIG.ph's report. In plain terms: the board knows its systems were breached, but it has not yet established which records were taken or how many people are affected.
That caution matters because the claims circulating around the incident are much bigger than what the agency has verified.
The 16-million-records claim
A threat actor using the handle "core849" claimed to have obtained 7.7 gigabytes of LTFRB data — reportedly including personnel records, vehicle registration information, and franchise and operator records. That claim was first surfaced on September 12 by Deep Web Konek, a site that monitors Philippine data leaks on underground forums.
Separately, Coalition 169, a transport-sector group, has pressed the government to investigate claims that as many as 16 million records were exposed. The group also pointed to an earlier alleged incident in August involving a group calling itself "Quantum Security Group."
The LTFRB has not confirmed that the breach it acknowledged is connected to either claim, and none of the figures above have been verified by the agency. Until the technical validation finishes, the honest answer to "how bad is it?" is that nobody outside the investigation knows.
Who is investigating
Three agencies are now involved alongside the LTFRB's own technical teams:
- DICT — the Department of Information and Communications Technology, which handles the technical response to government cyber incidents
- CICC — the Cybercrime Investigation and Coordinating Center, which pursues the criminal side
- NPC — the National Privacy Commission, which steps in when personal data may have been compromised
The NPC's involvement is worth watching. If personal data is confirmed to have been exposed, the Data Privacy Act requires notification of affected individuals — which, for a franchising regulator, could mean drivers and operators across the country.
What this means for drivers and operators
If you transact with the LTFRB through LESS, expect delays: everything that runs through the platform is suspended until further notice, and the agency has not said when it will come back. The breach also lands in an already grim year for Philippine data security — the country lost 335 million records to breaches in the first half of 2026 alone, and the government only recently ordered every agency to report its cyber readiness within 24 hours after attacks on the DMW and DOLE. Until the LTFRB says exactly what was taken, treat unexpected calls, texts, or emails that quote your vehicle or franchise details with extra suspicion — data from government leaks has a history of ending up in targeted scams.