3musketeerz
Attribution profile
- Type
- Sensationalist
- Location
- Philippines
- Known incidents
- 1 incident
- Sources
- 1 source
- First seen
- 2023-10-14
- Last seen
- 2023-10-14
- Updated
- 2026-07-31 12:12
- Aliases
- 1 alias
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor tracked under the alias 3musketeerz has been identified in open-source reporting as operating from the Philippines, with no indication of any other base of operations in the available sources. The actor first entered public awareness in October 2023 after claiming responsibility for a cyber incident that affected the official website of the Philippine House of Representatives. According to the Department of Information and Communications Technology, the compromise took place on Sunday, 14 October 2023, coinciding with the weekend period when reduced staffing may have been present. No additional aliases, alternate names, or affiliated group designations have been publicly associated with 3musketeerz in the sources examined to date. Geographic attribution beyond the Philippines is not supported by the current open‑source material, which limits location information to that country.
The known activity of 3musketeerz involves a single observed target: the congressional web property hosted at congress.gov.ph, which serves as the online presence of the House of Representatives. On the day of the incident, the threat actor replaced the legitimate homepage content with an image of a meme bearing the caption “you’ve been hacked” and signed the defacement with the moniker 3musketeerz. The Department of Information and Communications Technology announced on Monday, 15 October 2023, that it had confirmed the breach and tasked its Philippine National Computer Emergency Response Team (CERT‑PH) with conducting a forensic examination. CERT‑PH’s analysis includes a determination of whether any confidential or personal data stored on the House’s servers was accessed, copied, or exfiltrated by the intruder during the compromise. In parallel with the investigation, the DICT issued specific hardening recommendations to the House of Representatives’ information technology staff and affirmed that the identified security weaknesses would be remedied to restore the site to normal operation as soon as feasible.
Upon confirmation of the breach, the House of Representatives immediately took the congress.gov.ph domain offline to prevent any further unauthorized interaction with the compromised server. The DICT’s Cybercrime Investigation and Coordinating Center (CICC), together with national law‑enforcement entities, will undertake threat actor attribution and case‑building procedures once the technical forensic work by CERT‑PH is completed. As of the timestamp attached to the PNA article, the website remained unavailable to visitors, displaying a maintenance or offline status rather than the original legislative content. The Department of Information and Communications Technology reiterated its pledge to act as a supportive partner for government agencies seeking to strengthen the resilience of their information and communications technology infrastructures against cyber threats. No additional intrusion campaigns, ransomware deployments, data‑leak operations, or other publicly reported activities have been linked to 3musketeerz beyond the singular defacement of the House of Representatives website in October 2023.
Incidents
Attributed incidents are available to members.
1 incidentSources
Sources available to members: 1 source.