
Table of Contents
🔐 THE BOARD — Tuesday, September 29, 2026 → Cyber Tuesday: incident-verification mode. Group: “DeathNote Hackers” (DNH) · Target: DENR-Environmental Management Bureau’s Integrated Information System (EMB IIS / CRS) · Claims: ~3.83M company records + 973,610 client records + 22,465 personnel files, up to 17M lines · Method claimed: unsecured API endpoints, “authenticated scrape” · Status: DICT says unconfirmed — NCERT coordinating · System under maintenance · No NPC report logged · Crossing data: EMB was defaced ~11 months ago.
Key Takeaway
- 🏦 A claims ledger, not a confirmed EMB data breach: the DeathNote group claims ~3.83M company records and 973,610 client records from DENR’s Environmental Management Bureau — but DICT’s official line is that nothing is verified yet, and the difference between claim and confirmation is where every decision in this piece lives.
- 🔌 The alleged vector is boring and that’s the lesson: an “authenticated scrape” of unsecured API endpoints — the same class of sloppy-API exposure that’s been the dominant gov-system vector worldwide — with personnel files claiming 22,465 records.
- 📊 The register math doesn’t lie around the edges: a full EMB register would be ~1.3-1.4M registered facilities nationally — the claim of 3.83M “company rows” alone suggests scraped join-tables and duplicates, which is exactly how the claim should be read: as a dump’s shape, not a verified population.
- 🛡️ What a business owner does today (not after confirmation): log in and rotate every credential you hold in any EMB/DENR-linked system, and re-register API-integrated connections — pre-confirmation credential rotation is free; post-confirmation identity fraud is not.
- ✅ What a citizen does today: assume the personnel-file claim is true until proven false for your own hygiene: unique passwords, MFA everywhere, a dedicated email for government registrations, and the NPC breach-reporting form as your verification channel — the playbook below is 6 moves and 20 minutes.
The most disciplined thing to say about the EMB data breach claim that surfaced Monday is that it is a claim. A group styling itself “DeathNote Hackers” has posted dumps it says were extracted from the Environmental Management Bureau’s Integrated Information System — the Company Registration System inside DENR-EMB that holds official corporate records for businesses nationwide — via what the group describes as an authenticated scrape of unsecured API endpoints, with the EMB data breach headline numbers (3.83 million company-list records, 973,610 client-list records, 34,344 “extras,” 22,465 personnel-related records, a total claim approaching 17 million lines) attached to JSON-format samples. The government’s response is exactly what it should be at this stage: DICT’s statement confirms an investigation is running, the National Computer Emergency Response Team is coordinating with EMB, the authenticity of the exposure remains unverified, and the system is under maintenance. This is Cyber Watch #002 in its verification-week duty: Cyber News sells you the biggest number in the leak (17 million!), we price the decision — here is what each claimed component means, the register math that tests it, and the 6 moves every Filipino business owner and citizen executes this week regardless of which way the verification lands. The claim will either be confirmed (and the moves will already be done), or it will be downgraded (and the moves still protected you against every other dump currently circulating in Filipino breach markets). There is no version of this week where doing nothing is the winning play.

WorldNgayon Analysis: A claim this size with API-endpoint mechanics is plausibly a real scrape — but “3.83M companies” is a register-shaped impossibility for EMB alone, and treating dump-arithmetic as a fact-check tool is now a core citizen skill.
Bottom Line: EMB data breach claim: millions of records from EMB’s IIS via unsecured APIs; status: unconfirmed with NCERT running; your move: execute the playbook now, not after the press release.
The Claim Ledger — What DNH Actually Posted, Component by Component
The dump’s own metadata is the most useful artifact in circulation. The claimed components: 3,825,465 records from a company list; 973,610 from a client list; 34,344 “extras”; 22,465 personnel-related files — all presented as JSON-format rows, with the group’s total-system claim reaching 17 million lines they “refrained from scraping entirely.” The fields allegedly included: full names, usernames, contact numbers, emails, employee tokens, client IDs, EMB IDs, company names, and project names. Two details push the credibility needle upward: the field list is boringly real (employee tokens and client IDs are the kind of internal plumbing a real scrape captures and a fabricated leak rarely bothers to mimic), and the alleged vector — “authenticated scrape” of API endpoints — describes a system that was technically accessible with valid credentials but architecturally unsecured, which is precisely the failure mode EMB’s own 11-month-old defacement history hinted at. One detail pushes it down: the scale claim (17M lines) outruns EMB’s actual register — the bureau’s own published counts of registered facilities and permitted companies sit far below 3.83M unique corporate entities — meaning the “company list” is functionally certain to include join-table rows, repeated client-side entries, or scraped relationship tables rather than 3.83M distinct companies. That is not debunking the breach; that is reading it: the EMB data breach dump may be real while the “millions of companies” headline is a scraper’s row-count, not a census of Philippine business.
WorldNgayon Analysis: Real EMB data breach dumps often ship with inflated or duplicated counts — the shape of the data (tokens, IDs, plumbing fields) is a stronger authenticity signal than the headline number.
Bottom Line: 3.83M “company rows” is a scrape-arithmetic claim that outgrows EMB’s actual register — the credible core is smaller, but the personnel files (22,465) are the component every reader should act on.
Why EMB Specifically — the 11-Month Echo and the API Reality
The bureau is not a random target: DNH’s own statement taunts EMB for being defaced by a foreign actor roughly eleven months ago and left unfixed — the leak’s credibility sales pitch is literally “we told you they were soft,” and the claim gets its plausibility partly from that history. The vector claim adds the operational detail: “authenticated scrape” means the endpoints required no exploit to enumerate — just valid credentials and a script — which is why “millions of lines” moves quietly: there is no loud exploit, no deface-claim, no defacement headline; there is just a system that answers API calls with data it should never have returned. The Philippine government-database context makes the pattern structural rather than personal: the defacement wave Cyber Watch #001 covered last Monday (19 sites in one day), the DMW breach before it, and now an IIS/CRS scrape claim — three incidents in a single month, each in a different failure mode (defacement, personal-data breach, API over-exposure), against an architecture where environmental permitting (EIA system), pollution compliance, and corporate registration interlink. The interlink is the exposure: a company registered in EMB’s CRS intersects with its permits, its projects, and its personnel — and those JSON fields allegedly captured all three at once. For the MSME owner whose entire compliance file lives in that system, the question is not “did 3.83M companies leak” — it’s “did my company’s row, with my contact details and my tokens, leave the building with it.” That question only the NPC-verified investigation will settle, and it is why verification discipline — waiting for confirmation on the big number while protecting the small personal rows now — is the only coherent response posture.
WorldNgayon Analysis: DNH’s EMB data breach claim is a marketing document aimed at a bureau with a prior breach — the group needs the echo to be plausible, and EMB’s 11-month-old defacement gave it that echo for free.
Bottom Line: Vector claim (authenticated API scrape) + prior-history echo + internal-plumbing field names = a claim pattern that’s been confirmed as real in most prior leaks — treat it as probable until DICT says otherwise.
The MSME Owner’s Playbook — 6 Moves for Anyone in the EMB Universe
The moves that matter for anyone whose business registers with EMB (or any government integrated system in the same class): Move 1 — rotate every credential now: log in to any EMB/DENR-integrated portal you use and change passwords today; if the dump’s “employee tokens” claim is real, those tokens live in scraped dumps and reuse is what converts leaked tokens into account takeovers. Move 2 — kill the shared password: any password reused between government registries and business email dies today — a password manager generating unique strings per system is the ten-minute fix that makes every future dump a non-event for your accounts. Move 3 — re-register API integrations: if your firm’s compliance software or consultant connects to EMB endpoints, rotate those API keys and confirm the connection scopes are minimum-required — the “authenticated scrape” vector means your own tokens may have been the ones walked out the door. Move 4 — verify your row’s exposure in the verified channels: don’t hunt dump-links (that’s where the secondary scams live — Cyber Watch #001’s verified-channel rule applies); instead, request written confirmation from EMB/DENR’s official channels, and if your company’s data confirms exposed, file the NPC breach notification form as the concerned party. Move 5 — brief the team on phishing that will quote this: the predictable second wave uses real-looking details (“EMB records show your registration is flagged — confirm here”) and the defense is the same as always: never re-verify through emailed links, always through bookmarked portals; the 5-move playbook Monday’s #001 shipped covers this in depth. Move 6 — document everything: save timestamped screenshots of your system logins, note every EMB/DENR communication you receive this month — if identity complications surface later, the paper trail is what NPC complaints and bank fraud desks actually run on.
Bottom Line: Six moves, twenty minutes, executed pre-confirmation: rotate credentials, kill reuse, rotate API keys, verify via official channels, brief the team, document — the playbook makes the confirmation day a formality instead of a crisis.
The Citizens’ Layer — What 22,465 Personnel Files Means if Real
The EMB data breach personnel-file figure is large enough to warrant its own section because government employee files contain precisely the components identity fraud runs on: full names, emails, contact numbers, employee tokens, staff IDs. If the claim verifies, the correct posture is the DMW-breach playbook (Cyber Watch’s September standard for personal-data exposure): assume the data is in circulation until the agency says otherwise, run the breach-check routine on your own email and number (the notification letters NCERT/EMB would send are the formal channel, but proactive checking beats waiting), lock down email first (it’s the reset key to everything else), treat any contact that references internal EMB matters as hostile until verified through official channels, and monitor bank and government-portal logins for the month. The personnel-file component is also where the NPC’s statutory role activates fully: if verified, EMB carries the NPC reporting duty for personal-data exposure, and the timeline discipline from the DMW case applies — the agency’s EMB data breach notification duties to affected personnel are the compliance benchmark the NPC holds every institution to. For the general citizen not in the EMB universe, the piece’s relevance is the pattern: government systems leak EMB data breach-style through doors you never opened — the company you work for, the building you live in, the permits your employer filed — and the defense runs through the data-minimization habits #001 already shipped: don’t hand more to any government form than the form requires, keep the registration email dedicated, and never reuse the password you use for the email that receives government notices.
WorldNgayon Analysis: The personnel-file row is smaller than the corporate claim but more dangerous per record — identity-fraud economics run on exactly the fields (names + tokens + emails) those 22,465 rows allegedly carry.
Bottom Line: 22,465 personnel records is the claim that outranks the “millions of companies” headline in personal risk — government staff and MSME owners run the same protective math now, confirmation or not.
What Would Change This Reading — the Two Verification Gates
Gate one — DICT/NCERT’s validation statement: the investigation’s finding either upgrades the EMB data breach claim to confirmed (the playbook’s already executed; attention shifts to NPC compliance and remediation scope) or downgrades it to claim-dismissed (the moves still stand as breach-market hygiene). The phrase to watch for: “authenticity” — the same word DICT used in the statement is the exact determination the market is waiting on. Gate two — the dump’s circulation: if the claimed files appear in accessible leak markets with verifiable field content that matches live EMB registry rows (researchers routinely probe dumps against known entries), the confirm-or-dismiss question answers itself regardless of government tempo. Either gate moving flips a section of this analysis inside 48 hours; neither moving keeps the piece’s discipline stance exactly where it is. The monitoring posture mirrors the defacement-wave week: official statements first, verified-channel reporting second, dump-forum chatter treated as evidence only when the samples check out against known rows.
Bottom Line: Two gates — the government’s EMB data breach authenticity determination and the dump’s independent verification — decide this analysis’s final shape within roughly 48 hours.
Frequently Asked Questions
Was the EMB data breach confirmed?
No — as of September 29, DICT’s official statement says the reported incident “has not yet been confirmed” and that the authenticity of the exposed information, the extent of the exposure, the access method, and whether the data originated from EMB’s CRS all remain under verification. The National Computer Emergency Response Team is coordinating with EMB, and the system is under maintenance.
How many records did the DeathNote hackers claim?
The group’s post claims 3,825,465 company-list records, 973,610 client-list records, 34,344 “extras,” and 22,465 personnel-related records — with a total system estimate reaching 17 million lines they said they did not fully scrape. The company-list figure almost certainly includes duplicated join-table rows rather than distinct companies; EMB’s actual registered-entity count is far lower.
What should a business registered with EMB do right now?
Execute the six moves now rather than waiting for the EMB data breach confirmation: rotate portal credentials, kill password reuse, rotate API integration keys, request written exposure confirmation through official channels (and file the NPC breach form if confirmed), brief staff against phishing that references EMB records, and keep a documentation trail of all communications.
How do I verify if my company’s data was in the EMB dump?
Through official channels only: request written confirmation from EMB/DENR’s published contact points, watch DICT/NCERT statements on the EMB data breach, and — if exposure is confirmed — the NPC’s breach-reporting form at privacy.gov.ph is the formal concerned-party route. Never verify by downloading dump files from leak forums; that’s where secondary malware and scam attempts live.
Why are Philippine government systems breached so often?
It’s structural, not coincidental: a large estate of web-exposed databases, widespread API-enabled systems, thin security staffing at attached agencies, and a decade of budget cycles that under-fund backend hardening relative to front-end digitization. The defacement wave (19 sites in one day), the DMW personal-data breach, and this EMB claim are three different failure modes of the same architecture problem inside a month.
Financial Disclaimer: This article is for general information and education, not investment or financial or legal advice. Data-protection obligations and fraud-response measures depend on individual circumstances; consult appropriate professionals for specific incidents. WorldNgayon.com is not a legal or financial adviser.







