Data breach: Website uploads voter info, Comelec downplays leak | ABS-CBN
ADVERTISEMENT

Welcome, Kapamilya! We use cookies to improve your browsing experience. Continuing to use this site means you agree to our use of cookies. Tell me more!
Data breach: Website uploads voter info, Comelec downplays leak
Data breach: Website uploads voter info, Comelec downplays leak
Rachel Hermosura,
ABS-CBN News
Published Apr 21, 2016 06:27 PM PHT
|
Updated Apr 21, 2016 10:32 PM PHT

A website claims to have made searchable the voter database hacked from the Commission on Elections (Comelec) website.
A website claims to have made searchable the voter database hacked from the Commission on Elections (Comelec) website.
The website only requires visitors to fill two out of the three fields: first name, last name and maternal name. If the data is included, the page would show a voter's personal data, including birth date and birth place, address, date of registration as a voter, fingerprint information and passport information.
The website only requires visitors to fill two out of the three fields: first name, last name and maternal name. If the data is included, the page would show a voter's personal data, including birth date and birth place, address, date of registration as a voter, fingerprint information and passport information.
"The database contains a lot of sensitive information, including fingerprint data and passport information," the page said. "So, we thought that it would be fun to make a search engine over that data."
"The database contains a lot of sensitive information, including fingerprint data and passport information," the page said. "So, we thought that it would be fun to make a search engine over that data."
It's unclear who is behind the site, only saying that it was done "for lulz" (for fun).
It's unclear who is behind the site, only saying that it was done "for lulz" (for fun).
ADVERTISEMENT
"It's one thing to hear news about a huge data leak and another to is see your data in a public website," the page reads. "Maybe, at least now, government will start thinking about security of citizens' personal data."
"It's one thing to hear news about a huge data leak and another to is see your data in a public website," the page reads. "Maybe, at least now, government will start thinking about security of citizens' personal data."
Comelec Chairman, Andy Bautista however downplayed the leak, saying the information made available by the site "is really public information."
Comelec Chairman, Andy Bautista however downplayed the leak, saying the information made available by the site "is really public information."
"In respect of this website, it is now out there. The information, as I said -- name, address, date of birth, as much as possible they should not be sent out. But also, this kind of information is publicly available in other government agencies," Bautista told ANC News Now.
"In respect of this website, it is now out there. The information, as I said -- name, address, date of birth, as much as possible they should not be sent out. But also, this kind of information is publicly available in other government agencies," Bautista told ANC News Now.
Bautista claimed there "was no fingerprint information that was taken" but he admitted that "there are information taken in respect of addresses."
Bautista claimed there "was no fingerprint information that was taken" but he admitted that "there are information taken in respect of addresses."
"Now I'm not trying to make excuses. The fact is our website was hacked, and that's why we're trying to find ways to minimize the damage," Bautista said.
"Now I'm not trying to make excuses. The fact is our website was hacked, and that's why we're trying to find ways to minimize the damage," Bautista said.
He admitted that details from "passports of certain overseas Filipino voters" were also leaked.
He admitted that details from "passports of certain overseas Filipino voters" were also leaked.
But Bautista also highlighted the arrest of Comelec website hacker, nabbed by members of the National Bureau of Investigation Thursday.
But Bautista also highlighted the arrest of Comelec website hacker, nabbed by members of the National Bureau of Investigation Thursday.
"The good news is we were able to arrest one of the hackers. In fact we met with him this morning, you saw him at the NBI. His computers, other paraphernalia were retrieved. At the moment, the NBI is continuing its forensic investigation in respect of the documents that are in the computer. There are two other hackers that the NBI is also looking for," he said.
"The good news is we were able to arrest one of the hackers. In fact we met with him this morning, you saw him at the NBI. His computers, other paraphernalia were retrieved. At the moment, the NBI is continuing its forensic investigation in respect of the documents that are in the computer. There are two other hackers that the NBI is also looking for," he said.
Bautista said authorities are probing the "extent of what the data leak is."
Bautista said authorities are probing the "extent of what the data leak is."
WARNING AGAINST SITE
Comelec spokesman James Jimenez meanwhile urged the public not to use the website containing leaked voter info, as this could be a phishing website.
Comelec spokesman James Jimenez meanwhile urged the public not to use the website containing leaked voter info, as this could be a phishing website.
"It can be used by the hackers to steal your information and thus expose you even further to the dangers of identity theft. We also cannot rule out at this stage that this may be an attempt by the hackers to monetize the data they claim to have," said Jimenez in a statement.
"It can be used by the hackers to steal your information and thus expose you even further to the dangers of identity theft. We also cannot rule out at this stage that this may be an attempt by the hackers to monetize the data they claim to have," said Jimenez in a statement.
He also apologized for the data leak and assured that authorities are resolving the issue.
He also apologized for the data leak and assured that authorities are resolving the issue.
"I apologize for this continuing attack on your privacy and assure the public that the Comelec is doing everything to resolve this matter at the soonest possible time," Jimenez said.
"I apologize for this continuing attack on your privacy and assure the public that the Comelec is doing everything to resolve this matter at the soonest possible time," Jimenez said.
Last March, hackers from Anonymous Philippines defaced the Comelec website, while an affiliated hacker group LulzPinas released the raw data of the poll body's voter database.
Last March, hackers from Anonymous Philippines defaced the Comelec website, while an affiliated hacker group LulzPinas released the raw data of the poll body's voter database.
Trend Micro, a global security software company, earlier said the personal data of 1.3 million overseas Filipino voters, including their passport information, as well as fingerprints of 15.8 million people were compromised in the hacking of the Comelec site.
Trend Micro, a global security software company, earlier said the personal data of 1.3 million overseas Filipino voters, including their passport information, as well as fingerprints of 15.8 million people were compromised in the hacking of the Comelec site.
It said the data dump "may turn out as the biggest government related data breach in history" and warned that criminals can use the leaked personal information of Filipino voters for extortion and other illegal activities.
It said the data dump "may turn out as the biggest government related data breach in history" and warned that criminals can use the leaked personal information of Filipino voters for extortion and other illegal activities.
"In previous cases of data breach, stolen data has been used to access bank accounts, gather further information about specific persons, used as leverage for spear phishing emails or BEC [Business Email Compromise] schemes, blackmail or extortion, and much more," Trend Micro said.
"In previous cases of data breach, stolen data has been used to access bank accounts, gather further information about specific persons, used as leverage for spear phishing emails or BEC [Business Email Compromise] schemes, blackmail or extortion, and much more," Trend Micro said.
The Comelec earlier said that the data retrieved by hackers are readily available through the poll body's website.
The Comelec earlier said that the data retrieved by hackers are readily available through the poll body's website.
ADVERTISEMENT
Pimentel wants Senate caucus to discuss Sara Duterte impeachment
Pimentel wants Senate caucus to discuss Sara Duterte impeachment
ABS-CBN News
Published Feb 20, 2025 10:13 PM PHT

Watch more on iWantTFC.com. Watch hundreds of Pinoy shows, movies, live sports and news.
Watch more on iWantTFC.com. Watch hundreds of Pinoy shows, movies, live sports and news.
The Philippine Senate Minority Leader calls for a caucus to discuss the impeachment trial of Vice President Sara Duterte. Aquilino Pimentel says this would determine if there's a consensus among his fellow senators on when the trial can begin. -ANC, The World Tonight, February 20, 2025
The Philippine Senate Minority Leader calls for a caucus to discuss the impeachment trial of Vice President Sara Duterte. Aquilino Pimentel says this would determine if there's a consensus among his fellow senators on when the trial can begin. -ANC, The World Tonight, February 20, 2025
ADVERTISEMENT
ADVERTISEMENT