DICT A.I CyberSecurity Scoring
DICT
Company Information
Website:https://dict.gov.ph/
Employees number:901
Number of followers:503,175
NAICS:92
Industry Type:Government Administration
Homepage:dict.gov.ph
DICT Risk Score (AI oriented)
Between 600 and 649
DICTGovernment Administration
Updated:
26/09/2026
26/09/2026
638/1000
Poor
Caa
DICT Global Score (TPRM)
xxxx
DICTGovernment Administration
Score locked

DICTPoor
Current Score
638Caa (POOR)
01000
3 incidents
-74 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
OCTOBER 2026
639
SEPTEMBER 2026
712
Breach
25 Sep 2026 • DICT
DICT Trusted Assessment Provider: DICT probes possible data breach involving 48 firms in accreditation program
Potential Data Breach Exposes Sensitive Information of 48 Firms in DICT Accreditation Program
638
CRITICAL-74
DIC1790404037
Potential Data Breach Exposes Sensitive Information of 48 Firms in DICT Accreditation Program
The Department of Information and Communications Technology (DICT) has reported a possible data breach involving 48 companies enrolled in its DICT Trusted Assessment Provider (DTAP) program. The incident, disclosed on Friday, may have exposed approximately 410 files totaling 600 MB (770 MB uncompressed) containing sensitive corporate and security-related data.
The DTAP program partners with local cybersecurity service providers to assess and fortify digital systems before public deployment. The compromised files may include corporate registration records, permits, certifications, cybersecurity credentials, employment documents, and DICT performance evaluations.
The National Computer Emergency Response Team (NCERT), under the DICT Cybersecurity Bureau, is leading the investigation to determine the breach’s source, nature, and scope. While the exposure remains unverified, the DICT has assured stakeholders that the matter is being actively addressed. If confirmed, the agency will take corrective action and notify affected parties in compliance with the Data Privacy Act of 2012 (Republic Act 10173).
Authorities have urged caution in sharing unverified details as the probe continues. The incident highlights risks in third-party accreditation processes and the potential exposure of critical infrastructure data.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
AUGUST 2026
709
JULY 2026
708
JUNE 2026
707
MAY 2026
706
APRIL 2026
705
MARCH 2026
702
FEBRUARY 2026
702
JANUARY 2026
701
DECEMBER 2025
698
NOVEMBER 2025
697
SEPTEMBER 2025
765
Breach
22 Sep 2025 • DICT
Department of Information and Communications Technology (DICT)
Potential Data Exposure in DICT's eComplaints System (Isolated from eGov PH Platform)
695
MEDIUM-70
DIC3833538092225
The DICT reported an incident involving its eComplaints system, a third-party service linked to the eGov PH platform, where over 30,000 complaint records were allegedly exposed. The department clarified that the eGov PH app itself was not compromised, and the breach was isolated to the eComplaints system, which operates separately from the main infrastructure. DICT emphasized that no personal data on the eGov platform was leaked, as it remains encrypted and protected by cybersecurity measures. While the exact nature of the exposed records (e.g., whether they contained sensitive personal or financial details) was not confirmed, the incident raised concerns about third-party vulnerabilities in government digital services. DICT committed to providing updates as further verified information becomes available, reiterating its priority to safeguard citizen privacy. The incident did not result in a full-scale breach of the primary eGov PH system, but the exposure of complaint records—even if non-sensitive—could still undermine public trust in digital governance platforms.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JUNE 2016
773
Breach
16 Jun 2016 • DICT
Department of Information and Communications Technology (DICT) - Philippines
DICT Internal Audit Reveals 'Significant Non-Compliance' in eGov eLGU Platform Rollout Without Contracts
702
CRITICAL-71
DIC2762527111925
The DICT’s eGov ‘super app’ and its eLGU platform—used by 14 million Filipinos and 924+ local government units (LGUs)—were deployed without signed contracts (MOAs/MOUs) defining data protection responsibilities, breach reporting, or liability. An internal audit (2025) revealed 40 out of 85 eLGU-adopted LGUs had no agreements, while 474 out of 973 iBPLS-adopted LGUs lacked complete MOAs, exposing unclear accountability for data breaches. The system collects excessive personal data upfront (government IDs, live photos, signatures, addresses) even for basic services like viewing health centers, raising proportionality concerns under privacy laws. The absence of Data Sharing Agreements (DSAs) or formal policies leaves no clear recourse for citizens in case of breaches, despite routine hacking incidents (e.g., 19 government sites hacked in September 2025 protests). DICT claims no data is stored or shared via eGovDX APIs, but experts warn this creates legal ambiguity, risking COA disallowances for irregular spending (e.g., ₱377.64M in contracts without enforceable agreements). Former NPC officials highlight the government’s poor track record in breach accountability, citing unresolved cases like the 2016 Comelec hack. The platform’s lack of transparency and unmitigated risks undermine trust in a system handling sensitive citizen data at scale.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for DICT ??
What was DICT's A.I Rankiteo Cyber Score in September 2026 ??
What was DICT's A.I Rankiteo Cyber Score in August 2026 ??
What was DICT's A.I Rankiteo Cyber Score in July 2026 ??
What was DICT's A.I Rankiteo Cyber Score in June 2026 ??
What was DICT's A.I Rankiteo Cyber Score in May 2026 ??
What was DICT's A.I Rankiteo Cyber Score in April 2026 ??
What was DICT's A.I Rankiteo Cyber Score in March 2026 ??
What was DICT's A.I Rankiteo Cyber Score in February 2026 ??
What was DICT's A.I Rankiteo Cyber Score in January 2026 ??
What was DICT's A.I Rankiteo Cyber Score in December 2025 ??
What was DICT's A.I Rankiteo Cyber Score in November 2025 ??
What is the average per-incident point impact on DICT's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with DICT ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view DICT's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?