Fullscreen view

Quantum Security Group

(root㉿quantumsec)-[~]$ Hello World

Logo

logo

About the group

Hacktivist / Grey Hat

A Brief Overview

Quantum Security Group Est. 2024.

banner

Quantum Security Group (QSG) is a collective of gray hat, black hat, and hacktivists from different regions of the Philippines.

It was originally formed in October 2024 under the name Quantum Security. Before it officially became what it is today, the organization was founded by Admiral_Luna and Zeu$, a pioneer from PCA. When new members Ch4nc3ll0rX_1337 and BalutP3Noy joined, the name was changed to Quantum Security Group. Admiral_Luna is no longer very active, so Zeu$ currently leads the group. Other members include Cyber Frost, who also takes part in their activities.

We are the threat actor group that exposed Philippine government and other websites through data leaks, breaches, web defacements, and other kinds of cyber actions. In 2025, QSG conducted a series of coordinated attacks targeting government, private, and educational websites. We were able to breach systems belonging to DICT, DWPH, VIVA, DEPED, and other entities that are supposed to protect the data of every Filipino. Up to this current year 2026, we are still proving that no system is completely safe and that security is often just an illusion.

The procurements of DICT and CICC meant to strengthen digital infrastructure for government websites were built only on paper. They are not implemented as they should be, and the DICT Cyberdome has proven useless. DICT claims that their websites are 101% hack proof, but every digital facade is built on lies. Every breach, every defacement, and every leak is a mirror held up to those who sit on power. The hard-earned taxes of Filipinos did not buy real security. Instead, those in power bought incompetence, neglect, and the arrogance of men who believed no one is watching.

We continue our work today, listening closely and watching the actions of those in politics who abuse their authority and are greedy for money. We are ready to risk everything for the country and ready to face whatever comes. We do not fear!

Not all records from this breach archive are listed here

Total Incidents: 0
Data Breaches: 0
Defacements: 0
Other 0
Marinduque Electric Cooperative, Inc.
Data Breach 2026 July 27, 2026
Breach

Greetings, Marinduque Electric Cooperative, Inc.

Let's break it down:

• 66,958 citizens – names, addresses, birthdays, contacts. All public now.
• 77,032 consumer accounts – every household's power usage, mapped.
• 62,594 bills – who paid what, and when.
• 10,844 TINs
• 190 employees – TIN, SSS, PhilHealth, Pag-IBIG. Their whole HR folder.
• 190 SHA1 passwords – straight out of 2005.

So MARELCO's security is about as reliable as a fuse during a typhoon. You've got enough data to run a small city, but zero protection to keep it safe.

And SHA1 in 2026? Bro, even your grandmother knows that's crackable. Next time, maybe hash with something this century.

All compromised data is uploaded and publicly accessible at the following link

Best regards,
QSG Team

Facebook: facebook.com/quantumsecph
Telegram: t.me/QuantumSecPH
X: x.com/QuantumSecPH

Department of Information and Communications Technology (eGovPay & eGovDocs)
Other 2026 July 25, 2026
Other Other Other Other Other Other Other Other Other

Greetings, Department of Information and Communications Technology

Usec. David Almirol Jr. keeps telling everyone eGovPH is "secured and safe," but let's be real, your dashboards are the only thing that's secure in that whole system. Your UI team is killing it, clean layouts, smooth graphs, everything looks premium. But then we peek under the hood and find hardcoded MFA secrets just sitting there, API tokens half‑exposed like they're on display in a museum, and IDOR that lets us scroll through 60+ user accounts like a digital yearbook. And the cherry on top? We can change settlement amounts with a single request, no questions asked. Your entire financial backend is basically a "set your own price" store.

You call that safe? I call it a luxury hotel with all the doors unlocked and the security cameras pointed at the floor. The "Pay" button works great though, we know, we tested it. Keep polishing that UI, Sir. We'll keep finding the doors you forgot to lock.

Special Greetings,
DNH Klammer

Best regards,
QSG Team

Facebook: facebook.com/quantumsecph
Telegram: t.me/QuantumSecPH
X: x.com/QuantumSecPH

Jollibee
Data Breach 2026 July 15, 2026
Breach Screenshot Breach Screenshot

Greetings, Jollibee

JOLLIBEE DEVS: TAKE A BOW, YOU JUST GOT ROASTED BY 3.12 GB OF YOUR OWN MESS.

Found this gem while scrolling the digital dumpster Jollibee’s audit trail is as secure as a paper napkin in a typhoon. 214 files, 3.12 GB of sensitive database data, created just yesterday. To the developer who left this open: congrats, you served up the juiciest fried chicken receipts ever. Maybe spend less time on gravy and more on firewalls.

Since sharing is caring, here is the full dump for everyone to fact-check.

Let this be a lesson: your audit logs are only as safe as your intern’s password hygiene.

Best regards,
QSG Team

Facebook: facebook.com/quantumsecph
Telegram: t.me/QuantumSecPH
X: x.com/QuantumSecPH

Department of Information and Communications Technology (vpms.dict.gov.ph)
Data Breach Defacement 2026 July 3, 2026
Breach Screenshot

Greetings, Department of Information and Communications Technology

Your precious CYBERDOME is a joke. We already slipped inside one of your subdomains while your so-called '101% UNHACKABLE' defenses sat there blind. That 101% you're flaunting? Already dropped to 99%. And dropping. So tell me where exactly did your web security budget go? Looks like it was spent on PR spin, not actual protection. How's that working out for you? Not so good right? Henry Agudacakes, statements full of LIES. Just to tell people, nahh everything is okayyy. FUCK THAT AND FUCK YOU.

Casually laughing at your security.

Best regards,
QSG Threat Actor Group.

Greetz: DNH Klammer - Rodel Lablab

Facebook: facebook.com/quantumsecph
Telegram: t.me/QuantumSecPH
X: x.com/QuantumSecPH

GULLAS COLLEGE OF MEDICINE, INC.
Data Breach 2026 July 1, 2026
Breach Screenshots Breach Screenshot

Greetings!
Gullas College of Medicine, Inc.

On June 24, we defaced your websites including all subdomains. and now We have now successfully exfiltrated your data records.

All compromised data is uploaded and publicly accessible at the following link: aHR0cHM6Ly9nb2ZpbGUuaW8vZC8ybWpWejQ=

Just decode it into base64.

Facebook: facebook.com/quantumsecph
Telegram: t.me/QuantumSecPH
X: x.com/QuantumSecPH

Best regards,
QSG Team

MASS DEFACE GOVERNMENT WEBSITES
Defacement 2026 June 14, 2026
Breach Screenshot

Greetings!
A message from Quantum Security Group.
The D1CT & C1CC thought banning our pages would silence us. You were wrong.

Millions in taxpayer money wasted while government systems remain a joke. Where is the Cyberdome now?

Deface Links

We are everywhere.
We are watching.
Expect Consequences. Expect Us.

Best regards,
QSG Team
Stay COLD.

BAGUIO CITY GOVERNMENT
Data Breach 2026 June 12, 2026
Breach Screenshot Breach Screenshot Breach Screenshot Breach Screenshot

Greetings! City Government of Baguio. As part of our ongoing operations, #QuantumSec has successfully exfiltrated your data — and you have an exposed API endpoint. Is this how #DICT protects the governments and the SPI data of every Filipino?

You are using the taxes of every Filipino workers with your BIG procurements for security and other shits. But every government is still prone to cyber-attack? Do you really use the funds correctly, or does the budget allocated go directly to your pockets?

For the file information, a total of 1.5 GB data consisting of 1,004 images will be released. This is proof that Filipino taxes were not used as supposed to be. Where's the fucking Cyberdome BTW? All you got is to brag and make threats.

Just imagine that the senate website was defaced. And DICT is talking like nothing happened? and posted an early statement that everything is fine? WTF? Have you even really conducted an investigation properly?

Best regards,
QSG Team

DEPARTMENT OF SOCIAL WELFARE AND DEVELOPMENT (DSWD)
Data Breach 2026 January 9, 2026
Breach Screenshot

QSG HAD GAINED ACCESS WITH SUPER USER OR ADMIN ACCOUNT OF SOME DOMAINS OF THE DSWD

ncddpdb.dswd.gov.ph — 7,000 Records

  • REGION
  • OFFICE_LEVEL
  • ASSIGNREGION
  • ASSIGNMUNI
  • FUNCTIONAL_TITLE
  • POSITION
  • EMPLOYMENT_STATUS
  • HIRING_STATUS
  • SALARY_GRADE
  • SALARY
  • FUND_SOURCE
  • FIRST_NAME
  • MIDDLE_NAME
  • LAST_NAME
  • EXTENSION_NAME
  • SEX
  • MARITAL_STATUS
  • BIRTHDAY
  • BIRTHPLACE
  • EMAIL
  • CONTACT_NUMBER
  • TELEPHONE
  • CURRENTREGIONADDRESS
  • CURRENTPROVADDRESS
  • CURRENTCITYADDRESS
  • CURRENTBRGYADD RESS
  • STREET
  • ZIP_CODE
  • GSIS
  • SSS
  • PAGIBIG
  • TIN
  • PHILHEALTH
  • MAXICARE
  • CURRENT_CONTRACT_START
  • CURRENT_CONTRACT_END
  • BLOODTYPE
  • CITIZENSHIP
  • CIVIL_SERVICE
  • CIVIL_STATUS
  • DATE_OF_LAST_RENEWAL
  • DATE_OF_ORIGINAL_CONTRACT
  • EDUC_ES_START
  • EDUC_ES_END
  • EDUC_ES_SCHOOL
  • EDUC_ES_YEAR_GRAD
  • EDUC_ES_HONOR
  • EDUC_HS_ATTAIN
  • EDUC_HS_END
  • EDUC_HS_HONOR
  • EDUC_HS_SCHOOL
  • EDUC_HS_START
  • EDUC_HS_YEAR_GRAD
  • EMPLOYEE_ID
  • FATHER_EXT_NAME
  • FATHER_FIRST_NAME
  • FATHER_LAST_NAME
  • FATHER_MIDDLE_NAME
  • HEIGHT
  • WEIGHT
  • MOTHER_EXT_NAME
  • MOTHER_FIRST_NAME
  • MOTHER_MIDDLE_NAME
  • MOTHER_LAST_NAME
  • SITIO
  • SPOUSE_BUSINESS_ADDRESS
  • SPOUSE_EMPLOYER
  • SPOUSE_EXT_NAME
  • SPOUSE_FIRST_NAME
  • SPOUSE_MIDDLE_NAME
  • SPOUSE_LAST_NAME
  • SPOUSE_OCCUPATION
  • SPOUSE_TELEPHONE

geotagging.dswd.gov.ph — 19,964 Records

  • User Name
  • First Name
  • Middle Name
  • Last Name
  • Ext Name
  • Position
  • Region
SEVERAL PHILIPPINE GOVERNMENTS — 8 DOH DOMAINS
Data Breach 2025 November 5, 2025
Breach Screenshot Breach Screenshot

Affected Domains

  • pwd.doh.gov.ph — Persons with Disability (PWD) Registry and Certification System
  • gidas.doh.gov.ph — Geographic Information for Disability and Health Surveillance
  • itis.doh.gov.ph — Integrated Tuberculosis Information System
  • mndrs.doh.gov.ph — Maternal, Neonatal, Death Reporting System
  • nhfr.doh.gov.ph — National Health Facility Registry
  • pidsr.doh.gov.ph — Philippine Integrated Disease Surveillance and Response
  • rabies.doh.gov.ph — Rabies Case Monitoring System
  • uhmistm.doh.gov.ph — Unified Health Management Information System

For coverage links:

DEPARTMENT OF PUBLIC WORKS AND HIGHWAYS (DPWH)
Defacement 2025 October 8, 2025
DEPED ILOCOS NORTE
Data Breach Defacement 2025 October 6, 2025
Breach Screenshot

QUANTUM SECURITY GROUP HAS SUCCESSFULLY BREACHED YOUR SYSTEM WITH 3 MILLION RECORDS

Greetings! DepEd Tayo Ilocos Norte. Quantum Security Group has successfully breached your system with 3 MILLION records, exfiltrating a total of 17 Databases from your domain and subdomains, obtaining 155 CSV Files. This data breach includes hundreds of thousands of personal information, PI and SPI data.

PI: name, username, email, school name, contact number, address, position, etc.
SPI: birthdate, gender, civil status, TIN number, PhilHealth number, BP number, education background, etc.

17 Database List

  • u652515858_ScqSi
  • u652515858_raffle
  • u652515858_r1aa2024
  • u652515858_r1aa
  • u652515858_qualmeet
  • u652515858_lrmds
  • u652515858_invdb
  • u652515858_indaa
  • u652515858_empdb
  • u652515858_dtsv2staging
  • u652515858_dtsv2
  • u652515858_dtsdb
  • u652515858_alsdb

PASSWORD: quantum.sec  |  File Size: 200+ MB

Defacement Links

EXECUTED BY: ~QS-BalutP3n0y, ~QS-Ch4nc3ll0rX_1337, ~QS-Zeu$, ~QS-Fr0st

DEPED AURORA
Data Breach Defacement 2025 October 6, 2025
Breach Screenshot

QUANTUM SECURITY GROUP HAS SUCCESSFULLY BREACHED YOUR SYSTEM AND EXFILTRATED YOUR DATABASES

Hello, DepEd Aurora. We have exfiltrated all your databases and also your Backup File. We did not drop any database when we attacked — but we LEAK it.

List of Databases

  • depedaur_wp525
  • depedaur_wp736
  • depedaur_wp565
  • depedaur_wp964
  • depedaur_wp_v0c5b

Backup File

backup-3.26.2025_11-30-45_depedaur.tar.gz

PASSWORD: quantum.sec  |  File Size: ~1.5 GB

Defacement Links

DEPED LAGUNA
Data Breach 2025 October 4, 2025
Breach Screenshot

QUANTUM SECURITY GROUP SUCCESSFULLY BREACHED YOUR SYSTEM WITH 7 MILLION RECORDS

Good afternoon! DepEd Laguna. Quantum Security Group successfully breached your system and obtained all of your databases — accumulating 7 million records. Records include PI/SPI of employees: firstname, lastname, extension, deped_emails, position, division, username, passwords, admin credentials, etc.

Databases

  • db_stars.tar.gz
  • dcp.tar.gz
  • deped.tar.gz
  • dtd.tar.gz
  • emailsys1.tar.gz
  • information_schema.tar.gz
  • mysql.tar.gz
  • office_letter.tar.gz
  • performance_schema.tar.gz
  • phpmyadmin.tar.gz
  • sys.tar.gz
  • trackit_2025.tar.gz
  • trackit2025.tar.gz

PASSWORD: quantum.sec  |  MASS DEFACED websites directory.

DEPED CORDILLERA ADMINISTRATIVE REGION (CAR)
Data Breach Defacement 2025 October 2, 2025
Breach Screenshot

QUANTUM SECURITY GROUP HAS SUCCESSFULLY BREACHED YOUR SYSTEM — OVER 6 MILLION RECORDS, 42 DATABASES, 1,951 CSV FILES

DepEd CAR — we exfiltrated a total of 42 DATABASES including 1,951 CSV Files: PI/SPI of employees, students, coaches, financial records, payment records, government issued IDs (SSS, Pagibig, TIN, GSIS), user accounts, birthdate, and more.

Defacement Links

42 Database List

  • depedcarictdb.tar.gz
  • depedcarrewardsandrecognition.tar.gz
  • eremitDB.tar.gz
  • performance_schema.tar.gz
  • supplyhubdb_benguet.tar.gz
  • test_supplyhubdb.tar.gz
  • depedcarlearningdevelopment.tar.gz
  • depedcarsdo_abradmsDB.tar.gz
  • information_schema.tar.gz
  • staging_depedcarppmisDB.tar.gz
  • supplyhubdb_ifugao.tar.gz
  • test-depedcardsmsdb.tar.gz
  • depedcarperformancemgmt.tar.gz
  • depedcarsdo_baguiodmsDB.tar.gz
  • kmt_dmsdb.tar.gz
  • supplyhubdb.tar.gz
  • supplyhubdb_kalinga.tar.gz
  • test-sdodmsdb.tar.gz
  • depedcarphDB.tar.gz
  • depedcarsdo_benguetdmsDB.tar.gz
  • mysql.tar.gz
  • supplyhubdb_abra.tar.gz
  • supplyhubdb_mp.tar.gz
  • training_depedcarhelpdeskdb.tar.gz
  • depedcarppmisDB.tar.gz
  • depedcarsdo_kalingadmsDB.tar.gz
  • palaroDB.tar.gz
  • supplyhubdb_apayao.tar.gz
  • supplyhubdb_tabukcity.tar.gz
  • training_depedcarprofilesdb.tar.gz
  • depedcarhelpdeskdb.tar.gz
  • depedcarprofilesdb (1).tar.gz
  • depedcarwebdb.tar.gz
  • palaroDB_.tar.gz
  • supplyhubdb_baguiocity.tar.gz
  • sys.tar.gz
  • trainingdepedcardsmsDB.tar.gz

PASSWORD: quantum.sec | TOTAL DATABASES: 42 | FILE SIZE: 800 MB

DEPED SAMAR
Data Breach 2025 October 1, 2025
Breach Screenshot

NEARLY 30K RECORDS BREACHED — LEAKING 7K PARTIAL DATA

We have successfully breached your system, obtaining almost 30,000 records. Today we are leaking 7K partial data because of your negligence. This data can be used for malicious activity such as identity theft.

Exposed PI & SPI Fields

  • Employee No.
  • Last name
  • First name
  • Middle name
  • Position title
  • Level taught
  • Birthdate
  • Current age
  • Date of original appointment
  • Date of last promotion
  • Start step date
  • Years in service
VIVA COMMUNICATIONS INC.
Data Breach 2025 September 29, 2025
Breach Screenshot

Viva Max PH left sensitive information wide open. The exposed haul includes nearly 2 million records:

  • 3,635 employee personal and sensitive files
  • 300 asset records
  • ~508,000 email records
  • 111,000 COVID-related health records
  • 112,000 payment records
  • 1,048,675+ messages

All contained within a handful of Excel files. Examples of exposed employee data fields:

  • id
  • lname
  • fname
  • mname
  • mi
  • date_hired
  • regularization
  • gender
  • status
  • bday
  • civil_status
  • contact_nos
  • address
  • raw_name
  • mmaiden_name
  • email
  • local
  • deleted
  • direct_line
  • fax
  • pos_id
  • managerial
  • dept_id
  • comp_id
  • sup_id
  • HeadID1
  • HeadID2
  • HeadID3
  • username
  • password
  • suffix
  • alias
  • employee_id
  • IDNumber
  • gsis_sss
  • pagibig_id
  • tin
  • head_id2
  • tsonline
  • store
  • headoffice
  • warehouse
  • madrinian
  • vismin_vvi
  • vismin_vpi
  • last_login
  • skin
  • groupings
  • logtype
  • locationID
  • locationID_sub
  • FloorLocation, Cov19ID, schedule, shifting_sched
LAND TRANSPORTATION OFFICE (LTO)
Data Breach 2025 September 26, 2025
Breach Screenshot

On 26 September 2025, Quantum Security Group has successfully infiltrated the LTO.

Leaked Files

  • Account Details
  • Email Addresses
  • Financial and Insurance Data
  • Login Sessions and PIN Codes
  • Bank Transaction Records
Department of Information and Communications Technology (vas.dict.gov.ph)
Data Breach 2025 September 24, 2025
Breach Screenshot

Over 32,000 citizens records from #DICT have been exposed.

This is not a "technical error" — this is negligence, corruption, and betrayal of public trust. While officials line their pockets and play politics, our personal data is left unguarded, scattered, and exploited.

We will not be silenced. We will not forget. This is a war cry for justice — a demand for truth, transparency, and protection of the people.

No incidents match this filter.