The Department of Information and Communications Technology (DICT) is investigating unauthorized access to the Department of Migrant Workers (DMW) website and the defacement of a Department of Labor and Employment (DOLE) web host.
Cybersecurity monitoring page Deep Web Konek reported that hacktivist group HappyGoLuckyPH had claimed responsibility for defacing the DMW website and alleged that it maintained access to the agency’s Active Directory environment for more than a month.
The group claimed it eventually compromised a domain controller and gained access to internal systems, security-management consoles, databases and server directories.
It also alleged that repositories containing worker, recruitment, contract, financial, legal and administrative information were accessible from the compromised environment. These supposedly included database backups, identity-verification records and scanned identification documents.
The DMW and DICT have not released a detailed technical assessment confirming whether the attackers reached these systems or whether any information was viewed, copied or extracted.
HappyGoLuckyPH accompanied its claim with a manifesto criticizing the government’s cybersecurity measures and its protection of overseas Filipino workers. The group also warned that other unauthorized parties could have accessed or copied the information before the intrusion was detected.
In a statement issued Monday, Sept. 7, the DICT said its National Computer Emergency Response Team (NCERT) coordinated with the DMW Management Information Technology Service after detecting unauthorized access to the agency’s website.
Joint technical teams isolated affected systems and tightened access controls as part of the forensic investigation and recovery process. The DICT did not address the group’s specific claims about the duration or extent of the alleged network intrusion.
The department is separately investigating the unauthorized modification of a DOLE web host. The affected node was isolated while digital forensics and restoration work continued.
“Initial technical assessments confirm that no sensitive databases or Personally Identifiable Information (PII) were compromised,” the DICT said, referring to the DOLE incident.
The affected DMW and DOLE web services were temporarily taken offline while technical teams investigated the incidents, removed possible threats and strengthened security.

The DICT also investigated reports of a ransomware attack against the Philippine Ports Authority (PPA). A review of system logs with PPA personnel found no evidence of ransomware or a system breach.
“During a subsequent technical assessment, joint logs with the agency’s designated focal personnel verified that the report was a false positive, confirming that no ransomware activity or system compromise occurred within PPA infrastructure,” the agency said.
The DICT said investigations and mitigation measures remain underway and that it would release further technical information as recovery milestones are completed.


