CSIDB logo
Incident

University of the Philippines Visayas

Incident posture

Attack window
Jun 2020
Location
Philippines
Status
Historical
CIA posture
Available to members
Updated
2025-10-30 00:00

Linked entities

Victim
University of the Philippines Visayas
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jun 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The University of the Philippines Visayas experienced a website defacement incident, prompting the institution to temporarily take its web server offline to mitigate further harm. A technical team conducted a security audit of all systems and initiated repairs on the affected infrastructure. This event occurred amid a broader pattern of cyberattacks targeting educational institutions, including compromises at other universities that resulted in unauthorized access to sensitive student data. The organization committed to providing updates as additional details became available following the investigation.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On June 11, 2020, the University of the Philippines Visayas (UPV) confirmed through its official Facebook page that its primary website, upv.edu.ph, had been defaced. The institution immediately took the web server offline upon discovering and verifying the unauthorized alteration. This action was implemented to contain the incident and prevent additional damage while their technical team initiated a comprehensive security audit of all institutional systems. UPV communicated directly with its constituents via the social media announcement, stating the temporary takedown was necessary to facilitate forensic examination and system remediation. The technical team prioritized securing other infrastructure components to mitigate potential lateral movement by threat actors, though no evidence of further compromise was disclosed. No specific details regarding the defacement’s content, the attackers’ identity, or the initial detection method were provided in the public statement.

The incident disrupted access to UPV’s official online resources, though the duration of the outage remained unspecified. The university committed to providing updates as the investigation progressed, emphasizing transparency within the constraints of ongoing remediation. This attack occurred amid a broader pattern of cyber incidents targeting Philippine educational institutions in mid-2020, including a separate defacement at UP Cebu and a data breach at San Beda University that exposed sensitive student records. UPV’s response focused on containment through infrastructure isolation, system hardening, and procedural reviews to restore operational integrity. The public advisory did not indicate whether user data or internal systems beyond the webserver were affected, nor did it specify a timeline for full restoration of services.

Sources

Sources available to members: 1 source.

CSIDB