CSIDB logo
Incident

Armed Forces of the Philippines

Incident posture

Attack window
Feb 2025
Location
Philippines
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 17:34

Linked entities

Victim
Armed Forces of the Philippines
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Feb 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A local hacking group called Exodus Security claimed responsibility for a cyberattack on the Philippine Army, asserting it had breached military systems and accessed approximately 10,000 records belonging to active and retired service members. Army spokesperson Col. Louie Dema-ala confirmed the incident as an "illegal access attempt" that was quickly contained, reporting no confirmed damage or data theft at the time of disclosure. The allegedly compromised information includes names, ranks, addresses, medical records, financial data, and criminal histories, though the authenticity and full scope remain unverified. The breach was initially reported by the digital security advocacy group Deep Web Konek. Separately, authorities had recently arrested a Chinese national and two Filipino citizens accused of surveilling critical infrastructure, including military sites, though it is unclear whether this arrest is connected to the cyberattack.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

The Philippine Army confirmed that it had been targeted in a cyberattack after a local hacking group publicly claimed responsibility for breaching its systems and accessing sensitive documents. Army spokesperson Colonel Louie Dema-ala acknowledged the incident, characterizing it as an "illegal access attempt" that was quickly contained. According to the spokesperson, the group behind the attack had been identified, and at the time of the official statement, no damage or data theft had been reported. The acknowledgement followed earlier reporting by the Philippine digital security advocacy group Deep Web Konek, which disclosed that the hacker group Exodus Security had claimed responsibility for the intrusion.

According to the claims made by the group, the breach allegedly compromised approximately 10,000 records belonging to both active and retired service members. The leaked information was reported to include a wide range of personal and military data, such as names, ranks, addresses, medical records, financial information, and criminal histories. The authenticity and the precise scope of the alleged data exposure had not been independently verified at the time of reporting. The breach was brought to wider public attention earlier in the same week through the disclosure from Deep Web Konek, which cited the hacking group's assertions about the scale and nature of the compromised records.

In response to the incident, the Philippine Army stated that it had taken countermeasures to contain the unauthorized access. The spokesperson's description of the event as an "illegal access attempt" indicated that the intrusion was detected and addressed before the attackers could complete their objectives, at least according to the Army's official account. The group's identity was established, though no further details regarding the individuals involved, their potential motives, or any ongoing investigative actions against them were disclosed in the available reporting. The Army's confirmation came alongside broader concerns about foreign involvement in surveillance activities targeting critical infrastructure in the Philippines. Earlier in January, authorities had arrested a Chinese national along with two Filipino citizens who were accused of surveilling critical infrastructure, including military sites. This prior enforcement action reflected ongoing attention to threats against military and strategic facilities in the country, providing broader context for the Army's investigation into the cyberattack claimed by Exodus Security.

Sources

Sources available to members: 1 source.

CSIDB