Skip to content

Try

post thumbnail

DICT, Hello? Anybody Home?

COMMENTARY: What we need for the long haul: Pass the National Cybersecurity Agency and Critical Information Protection Bill now.But do not, under any circumstances, place it under the administrative control and supervision of the DICT.

By Francisco Ashley Acedillo

Sep 8, 2026

8-minute read

Share This Article

:

When government agencies get hacked, we’re used to a familiar script: a statement from the DICT announcing that “emergency protocols” were activated, systems were “isolated,” and everything is “under control.” It sounds reassuring. It’s supposed to.

But look closely at the recent incidents at the Department of Migrant Workers (DMW), the Department of Labor and Employment (DOLE), and the Philippine Ports Authority (PPA), and a more worrying picture emerges — not of a cyber command in control, but of a fire brigade showing up after the house has burned down.

Here’s the uncomfortable bottom line: a hacktivist group called HappyGoLuckyPH claims it sat inside DMW’s network — inside its Active Directory, the digital master key system for the whole agency — for over a month. Over a month! During that time, nobody in the government noticed. The breach became known when the hackers themselves announced it publicly.

Meanwhile, the DICT’s main containment strategy, by all appearances, was to unplug the server. Services went dark “as a precautionary measure.” That’s not sophisticated cyber defense; that’s pulling the fire alarm and closing the building. The gap between the press statements (“seamless coordination,” “immediate response”) and the operational reality (a small, under resourced team doing postbreach archaeology with logs handed over by the victim agency) is the real story. And it’s a story about structural blind spots, not just one bad week.

What happened?

Three agencies, three different incidents — and they tell us a lot about where the vulnerabilities are.

𝐃𝐌𝐖 — the serious one. Officially described as “unauthorized access.” In practice, far worse. The group HappyGoLuckyPH claims it compromised a domain controller — the crown jewel of any Windows network — and held access to internal databases for more than a month. When a domain controller falls, the attacker essentially owns the agency’s entire digital identity system. Every password, every account, every permission becomes theirs to abuse. That this went undetected for weeks points to catastrophic gaps in identity monitoring and lateral-movement detection. The attack likely reached the final stage of the kill chain — access to objectives, possibly data theft — before anyone knew it was happening.

𝐃𝐎𝐋𝐄 — the defacement. The agency’s website was modified by unauthorized hands. Web defacements usually come from boring but lethal causes: unpatched content management systems, exposed admin panels, misconfigured hosting. Less dramatic than a month-long intrusion, but still an embarrassing failure of basic hygiene.

𝐏𝐏𝐀 — the false alarm. Rumors of a ransomware attack at PPA turned out, after log analysis (by the DICT’s own admission), to be untrue. Reassuring, in a way — but it also reveals a noisy intelligence pipeline where unverified external reports can trigger emergency responses before anyone has properly filtered them.

Perhaps the most telling detail: the technical indicators of compromise in the DMW case are withheld by the DICT. Much of what we know comes from dark web monitoring and the hackers’ own brags — not from the government’s own security telemetry. When the opposition knows more about your breach than your defenders do, that says something.

DICT claims vs. reality

Strip away the official language and compare it to what the evidence suggests.

𝐓𝐡𝐞 𝐜𝐥𝐚𝐢𝐦: “Direct coordination and on-site technical response” with the affected agencies.

𝐓𝐡𝐞 𝐫𝐞𝐚𝐥𝐢𝐭𝐲: Philippine government IT is deeply siloed. The DICT’s response team functions less like a unified command and more like an outside consultant called in after the fact — dependent on each agency’s “designated focal personnel” to piece together what even happened.

𝐓𝐡𝐞 𝐜𝐥𝐚𝐢𝐦: Elite responders conducting immediate digital forensics.

𝐓𝐡𝐞 𝐫𝐞𝐚𝐥𝐢𝐭𝐲: The national CERT (NCERT) is notoriously under-resourced, losing talent to the private sector and overseas, and triaging multiple national-level breaches at once with a skeleton crew. These are overworked analysts, not a standing army.

𝐓𝐡𝐞 𝐜𝐥𝐚𝐢𝐦: “Coordinated response protocols” activated immediately.

𝐓𝐡𝐞 𝐫𝐞𝐚𝐥𝐢𝐭𝐲: Response is reactive and manual. The PPA false positive shows intelligence arriving unfiltered. And DMW’s earlier history — reverting to manual, paper-based processing of worker passes during a prior ransomware incident — proves there’s essentially no automated disaster recovery to speak of.

𝐓𝐡𝐞 𝐜𝐥𝐚𝐢𝐦: “Access-control hardening and system isolation measures.”

𝐓𝐡𝐞 𝐫𝐞𝐚𝐥𝐢𝐭𝐲: The hardening was, in effect, switching things off. Taking citizen services offline is the bluntest instrument available. A modern security operations center with extended detection and response tools could quarantine malicious processes surgically, without shutting down services Filipinos depend on.

None of this is meant to mock the people doing the work — they’re doing what they can with what they have. The problem is institutional: the gap between what’s being said and what’s possible in reality.

Implications 

The privacy bomb. If the hacktivists’ claims hold — access to identity-verification records and scanned IDs of Filipino workers — the government faces serious exposure under the Data Privacy Act. This isn’t just an IT incident; it’s a legal and compliance failure involving some of the most sensitive personal data the government holds.

 The credibility trap. The DICT has a habit of releasing definitive statements early — like claiming “no sensitive databases were compromised” at DOLE. We’ve seen this movie before. After earlier national breaches (PhilHealth, PSA), early assurances of containment faced humiliation weeks later when threat actors dumped terabytes of citizen data online. Every premature “all clear” that turns out wrong makes the public trust the government’s next statement less. Trust, once burned, doesn’t come back on schedule.

Who’s behind it, and why now?

The current campaign looks like a mix of opportunistic hacktivists — groups like HappyGoLuckyPH, who explicitly frame their attacks as criticism of government cybersecurity posture — and financially motivated criminals (the ransomware rumors don’t come from nowhere).

What makes the Philippines such a soft target isn’t any single vulnerability. It’s the architecture: fragmented, decentralized networks with no central visibility. An adversary who gets into one agency’s network can live in it — “living off the land,” in security jargon — completely undetected, sometimes announcing their own presence before the government does.

What now?

The incidents above should not be treated as isolated security failures but as evidence of a systemic gap in national cyber governance. The following recommendations are offered accordingly.

These need to be done ASAP

𝟏. 𝐌𝐚𝐧𝐝𝐚𝐭𝐞 𝐜𝐞𝐧𝐭𝐫𝐚𝐥𝐢𝐳𝐞𝐝 𝐝𝐞𝐭𝐞𝐜𝐭𝐢𝐨𝐧 𝐚𝐜𝐫𝐨𝐬𝐬 𝐜𝐫𝐢𝐭𝐢𝐜𝐚𝐥 𝐬𝐲𝐬𝐭𝐞𝐦𝐬. The current model — dependent on victim agencies voluntarily surrendering logs after a breach — is untenable. The Office of the President, should issue a directive compelling the deployment of centralized endpoint detection agents on all critical government endpoints, beginning with domain controllers of national-data-holding agencies such as the DMW. The objective is real-time national visibility in place of postmortem forensics.

𝟐. 𝐎𝐫𝐝𝐞𝐫 𝐚 𝐟𝐮𝐥𝐥 𝐀𝐜𝐭𝐢𝐯𝐞 𝐃𝐢𝐫𝐞𝐜𝐭𝐨𝐫𝐲 𝐫𝐞𝐛𝐮𝐢𝐥𝐝 𝐚𝐭 𝐃𝐌𝐖. Isolation of a compromised domain controller is insufficient remediation. Where a domain controller has been breached, the entire identity environment must be presumed compromised: a complete forest rebuild, resetting of all ticket-granting credentials, and mandatory multi-factor authentication for all administrative accounts, with compliance verified by the DICT rather than self-attested by the agency.

What we need for the long haul

𝟏. 𝐒𝐡𝐢𝐟𝐭 𝐟𝐫𝐨𝐦 𝐚 𝐜𝐲𝐛𝐞𝐫𝐬𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐩𝐥𝐚𝐧 𝐭𝐨 𝐚 𝐜𝐲𝐛𝐞𝐫 𝐝𝐞𝐟𝐞𝐧𝐬𝐞 𝐩𝐨𝐬𝐭𝐮𝐫𝐞. Judging by these incidents, the DICT is already in over its head. Custody of the national cyber strategy should be elevated already to the Office of the Executive Secretary and the National Security Council — and conveniently, both Cabinet officials already sit as Co-Chairmen of the National Cybersecurity Inter-Agency Committee (NCIAC), the country’s highest cyber policy-making body (created by executive order under PNoy and reorganized into its current form under PRRD). The machinery exists; it simply has not been aimed at the right problem. Rather than pressing ahead with the defensive National Cybersecurity Plan, the NSC should spearhead a proactive National Cyber Defense Plan — one that assumes a cyber siege is already underway and adopts an assumed-breach mentality as its planning baseline, rather than treating intrusions as anomalies to be prevented. It should define, with dates and accountability, the transition from a reactive incident-response posture to a proactive, continuously monitoring national security operations capability. Progress should be reported against measurable milestones — mean time to detect, percentage of agencies under central telemetry — rather than activity counts.

𝟐. 𝐀𝐝𝐨𝐩𝐭 𝐙𝐞𝐫𝐨 𝐓𝐫𝐮𝐬𝐭 𝐚𝐬 𝐭𝐡𝐞 𝐠𝐨𝐯𝐞𝐫𝐧𝐦𝐞𝐧𝐭-𝐰𝐢𝐝𝐞 𝐬𝐭𝐚𝐧𝐝𝐚𝐫𝐝. Flat internal networks let a single compromised web host serve as a pivot into sensitive back-end systems, as the DOLE incident illustrates. Agency IT plans and budget requests should be conditioned on demonstrated network segmentation and identity-based access controls — and the power to verify compliance should sit where the accountability sits, not with each agency grading its own homework.

𝟑. 𝐏𝐚𝐬𝐬 𝐭𝐡𝐞 𝐍𝐚𝐭𝐢𝐨𝐧𝐚𝐥 𝐂𝐲𝐛𝐞𝐫𝐬𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐀𝐠𝐞𝐧𝐜𝐲 𝐚𝐧𝐝 𝐂𝐫𝐢𝐭𝐢𝐜𝐚𝐥 𝐈𝐧𝐟𝐨𝐫𝐦𝐚𝐭𝐢𝐨𝐧 𝐏𝐫𝐨𝐭𝐞𝐜𝐭𝐢𝐨𝐧 𝐁𝐢𝐥𝐥 𝐧𝐨𝐰. The bill answers precisely the gaps these incidents exposed: dedicated authority, dedicated resources, and dedicated accountability for protecting the country’s most critical information infrastructure. But for crying out loud — do not, under any circumstances, place it under the administrative control and supervision of the DICT. The agency we have just watched unplug servers while hackers wandered a department’s Active Directory for a month is not the institution to supervise the nation’s cyber shield. That would be an organizational decision worthy of the man who defined insanity as doing the same thing over and over and expecting a different result (and Albert Einstein would be turning in his grave).

The Philippines does not primarily lack cybersecurity talent or intent — it lacks visibility, authority, and accountability. Until the national security team can see agency networks in real time, compel rather than request cooperation, and measure itself publicly against concrete benchmarks, each future breach will be discovered the same way this one was: by the attackers announcing it. For now, the country’s cyber defense is a fire brigade with no smoke detectors anywhere in the building — and a press office that keeps telling everyone the fires are under control.

The hackers know it. The question is whether anyone in the building is listening.

Get VERAfied

Receive fresh perspectives and explainers in your inbox every Tuesday and Friday.