The Department of Information and Communications Technology (DICT) and the Cybercrime Investigation and Coordinating Center (CICC) have ordered government agencies and critical infrastructure operators to assess their security risks and take urgent protective measures within 24 hours amid reported cyberattacks on government systems.
The joint cybersecurity advisory followed confirmed unauthorized access to the Department of Migrant Workers (DMW) website and the defacement of a Department of Labor and Employment (DOLE) web host.
Hacktivist group HappyGoLuckyPH claimed that it had maintained access to the DMW’s Active Directory environment for more than a month before compromising a domain controller and gaining entry to internal systems, databases, security-management consoles, and server directories.
The group also alleged that repositories containing worker, recruitment, contract, financial, legal, and administrative information were accessible from the compromised environment.
The DMW and DICT have yet to issue a detailed technical assessment confirming the extent of the intrusion or whether information was viewed, copied, or extracted. Joint technical teams have isolated affected systems and tightened access controls while conducting forensic and recovery work.
The DICT is separately investigating the unauthorized modification of a DOLE web host, although its initial assessment found no compromise of sensitive databases or personally identifiable information.
It also investigated a reported ransomware attack against the Philippine Ports Authority but said a review of system logs found no evidence of ransomware or a breach.
Against this backdrop, the DICT and CICC placed national government agencies, government-owned and controlled corporations, local government units, and operators of Critical Information Infrastructure on “heightened cyber vigilance.”
Within 24 hours of receiving the advisory, covered organizations must provide their agency head or chief executive with a one-page cyber readiness assessment identifying their most serious risks, immediate actions taken, and assistance required.
Priority measures include fixing critical vulnerabilities, enforcing multi-factor authentication for critical and privileged accounts, removing unnecessary internet exposure, strengthening security monitoring, checking whether backups can be restored, reviewing third-party access, and testing incident-response and service-continuity procedures.
“The Filipino people deserve more than assurances. They deserve reliable public services, clear and verified information, and accountable action,” the DICT and CICC said in a joint statement dated Sept. 8.
The agencies acknowledged that reminding employees and the public to exercise caution does not reduce the government’s responsibility to secure its systems and the information entrusted to it.
“Cybersecurity is an institutional responsibility. Reminding employees and the public to exercise caution does not diminish the government’s obligation to protect the systems and information entrusted to it,” they said.
Cyber readiness will be classified under a green-amber-red framework. Red conditions require immediate reporting and response, while amber conditions require remediation and monitoring. A green classification calls for continued vigilance and does not indicate the absence of risk.
Suspected serious incidents must be reported immediately, without waiting for the 24-hour assessment period to end.
“The 24-hour requirement is a deadline for urgent action and assessment — not an assurance that every cybersecurity risk has been eliminated,” the agencies said. “This exercise must produce protective action, not merely another compliance report.”
Agency heads and chief executives were directed to lead implementation. The DICT and CICC said employee awareness cannot replace proper system maintenance, effective security controls, and leadership accountability.
The agencies also committed to providing verified public updates on incidents affecting government services. They said the updates would distinguish confirmed findings from preliminary assessments, identify available service alternatives, and indicate when further information would be released.
The commitment comes as the government has yet to confirm or refute key allegations about the depth and duration of the reported DMW network intrusion.
“Sensitive technical details will be protected without using the needs of an investigation as a blanket reason to withhold basic public-service information,” the DICT and CICC said.
They added that any attribution to individuals, organizations, or foreign actors would be based on validated evidence and not speculation.


