Business & Policy

DICT probes alleged data exposure at EMB’s company registry

DICT says it's investigating a reported unauthorized access to EMB's Company Registration System, which holds Philippine business records.

Share
The Department of Environment and Natural Resources (DENR) is the Philippine government agency mandated to conserve, manage, and ensure the sustainable use of the country's environment and natural resources.

The Department of Information and Communications Technology (DICT) said on September 27 that it is investigating a reported unauthorized access to the Environmental Management Bureau’s (EMB) Company Registration System (CRS), an online platform used to register and maintain records of companies operating in the Philippines.

The EMB, an agency under the Department of Environment and Natural Resources (DENR), requires companies to register through the CRS before they can access its permitting systems for environmental compliance certificates, hazardous waste manifests, and self-monitoring reports.

The system has processed tens of thousands of company registrations since it went live in 2020.

DICT said the alleged exposure may involve personal and corporate information kept in the system, and that this could carry privacy and security risks if confirmed.

The department has not verified the authenticity of the exposed information, the extent of the alleged exposure, or how, or whether, unauthorized access to the CRS actually took place.

The CRS is currently offline for maintenance while EMB’s incident responders carry out an assessment, DICT said.

The National Computer Emergency Response Team (NCERT), DICT’s incident-response unit, is coordinating with EMB and will assist with the investigation. But the DICT gave no timeline for when it expects to confirm its findings.

The reported EMB incident is at least the third Philippine government system DICT has had to respond to this month. CTRL+PH reported earlier this week that DICT confirmed a possible leak tied to its own D-TAP cybersecurity accreditation program, later putting the claimed scope at 48 firms and 410 files.

That followed a separate, earlier breach at the Land Transportation Franchising and Regulatory Board, whose LESS platform was taken offline after unauthorized access was confirmed in September.

DICT said it will release more information once the relevant facts have been validated.

Source: DICT/Facebook

Leave a Reply

Your email address will not be published. Required fields are marked *