[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f29joj4xmre1up":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":22,"affectedCountUnit":23,"hasEnglishDescription":4,"severity":24,"dataClasses":25,"description":38,"seoTitle":39,"seoTitleEn":40,"seoDescription":39,"seoDescriptionEn":41,"logoUrl":42,"isVerified":4,"isSensitive":4,"isSpamList":43,"isMalware":43,"company":44},"68e3266eda11adda48825154","comelec-philippines-voters","COMELEC (Philippines Voters) Data Breach","comelec.gov.ph","2016-03-27T00:00:00.000Z","2016-04-14T02:24:32.000Z","2026-07-09T19:02:21.493Z","2026-07-18T23:48:10.063Z","Third party breach","https:\u002F\u002Fprivacy.gov.ph\u002Fprivacy-commission-finds-bautista-criminally-liable-for-comeleak-data-breach\u002F",[15,17,18,19],"https:\u002F\u002Fwww.troyhunt.com\u002Fwhen-nation-is-hacked-understanding\u002F","https:\u002F\u002Fwww.wired.com\u002Fstory\u002Fphilippines-data-breach-fingerprint-data\u002F","https:\u002F\u002Fwww.theguardian.com\u002Ftechnology\u002F2016\u002Fapr\u002F11\u002Fphilippine-electoral-records-breached-government-hack",228605,"known",null,"unknown","High",[26,27,28,29,30,31,32,33,34,35,36,37],"Biometric data","Dates of birth","Email addresses","Family members' names","Genders","Job titles","Marital statuses","Names","Passport numbers","Phone numbers","Physical addresses","Physical attributes","\u003Cp>The COMELEC (Philippines Voters) data breach is a highly sensitive incident associated with the targeting of the Philippine election commission in March 2016 and the dissemination of large datasets of voter records online. The overall incident is linked to approximately 55 million Filipino voter records; however, the number of affected accounts tracked in this record is calculated based on the 228,605 unique email addresses included in the leak. This distinction is important: although the number of email matches is 228,605, the overall personal data impact of the incident is much greater than this.\u003C\u002Fp>\n\u003Cp>Verified data categories are biometric data, birth dates, email addresses, names of family members, gender information, occupational information, marital status, names, passport numbers, phone numbers, physical addresses, and physical characteristics. When these types of fields are combined, they pose a serious risk in terms of identity theft, targeted fraud, fake official notifications, and long-term privacy loss. In particular, fields such as biometric information and passport numbers are not like changeable passwords; therefore, the impact of the incident can continue even years later.\u003C\u002Fp>\n\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The types of data in the COMELEC case are far more sensitive than an ordinary account data breach. Names, date of birth, gender, marital status, occupation, phone number, and physical address information can describe a person's identity and life context in detail. Names of family members, particularly fields such as parents' names, can be misused as additional security elements in certain identity verification and official transaction processes. Passport numbers and physical characteristics are also among the high-value information targeted in identity fraud and profile verification attacks.\u003C\u002Fp>\n\u003Cp>Biometric data is one of the most sensitive aspects of the incident. A password can be changed, but data associated with a fingerprint or permanent physical characteristics cannot be easily altered. For this reason, the disclosure of such data creates long-term risk. The presence of email addresses in only 228,605 unique records does not reduce the overall sensitivity of voter data. Users with email addresses can be directly targeted online; voters without an email address can be exposed to different fraud scenarios through their name, address, date of birth, family information, and physical characteristics.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The number of affected accounts visible in the system for this record is 228,605, and this number is limited to unique email addresses. The overall incident, however, is associated with approximately 55 million voter records. Therefore, when explaining the record, a narrow comment such as 'only 228 thousand people were affected' should not be made. The correct interpretation is that the queryable scope based on email is 228,605; however, the impact of the leak on the general voter database is much larger.\u003C\u002Fp>\n\u003Cp>Data classes are biometric data, dates of birth, email addresses, names of family members, gender, occupation information, marital status, names, passport numbers, phone numbers, physical addresses, and physical characteristics. In this record, passwords, payment cards, bank accounts, usernames, or online account passwords are not verified data classes. It concerns the incident selection system and voter records; a separate technical incident claim aimed at voting or result infrastructure is not within the verified scope of this record. Data breach and election result security are separate issues.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The group at highest risk consists of individuals listed in the Philippines voter registration and whose personal information has been included in a large dataset, as well as users whose email addresses are included in this dataset. People with email addresses may be targeted with fake official institution messages, voter registration update requests, passport procedures, identity verification, or election notifications. Those with phone and address information should be cautious of attempts at fraud via text messages, calls, mail, or door-to-door approaches.\u003C\u002Fp>\n\u003Cp>Overseas voter registrations pose an even higher risk for individuals whose information includes passport numbers and family details. Fields such as passport number, date of birth, and address can facilitate identity fraud attempts when combined with other datasets. Names and physical characteristics of family members can be used to build trust in targeted scam messages. From a corporate perspective, such government records can trigger authentication weaknesses in public services, banking, and telecom processes.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>The user who sees a match in this record should first protect their email account and phone line against targeted fraud. A strong and unique password should be used for the email account, multi-factor authentication should be enabled, and recent sessions should be checked. Links in messages appearing to be from official institutions, voter registration, passport, ID updates, or aid applications should not be opened directly. If an action is necessary, the institution's address should be found through a reliable channel and entered directly.\u003C\u002Fp>\n\u003Cp>Unexpected messages requesting passport numbers, addresses, birth dates, or family information should be considered high risk. Even if people calling by phone claim to be official personnel, verification codes, identity document images, financial information, or account details should not be shared. Since biometric data cannot be retrieved, users should be aware that this data could be misused in future identity verification processes. If there is suspicion of identity fraud, additional protective measures should be investigated through local official channels and financial institutions.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>The COMELEC incident shows that the data recorded in government records may carry long-term and irreversible privacy risks. Users should habitually verify messages received for official transactions through official domain names and phone lines. Requests received via email or phone for 'record updates,' 'identity verification,' 'passport confirmation,' or 'voter information correction' should be treated with suspicion. Once identity information is exposed, the approach to protection must be continuous.\u003C\u002Fp>\n\u003Cp>For institutions, voter registrations, biometric fields, and passport information must be protected at the highest security level. Access control, encryption, logging, data minimization, backup security, and incident notification processes should be regularly tested. The long-term strategy for users is to develop a habit of verifying official transaction messages, strengthen email security, and use only trusted channels in authentication processes. Since data cannot be recovered in such incidents, risk management lasts for years.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>A match in this record indicates that the relevant email address appeared on an email list associated with the COMELEC voter data leak. A match does not mean that the overall incident is limited only to the people who own the email. Specifically, for this record, the queryable number is 228,605 unique email addresses; the overall voter data impact is much broader. Users should act cautiously, assuming that information associated with the email address, such as name, address, date of birth, phone number, or official ID, could be misused.\u003C\u002Fp>\n\u003Cp>The first action is to secure your email account, not to open official institution-themed messages via direct links, and to verify requests for personal information through separate channels. Messages regarding issues such as passport, voter registration, ID updates, or aid applications should not be rushed. Signs of identity theft, unexpected official transaction notifications, or suspicious financial applications should be monitored. Even if this incident is dated, the risk continues for a long time due to permanent information such as biometric and voter data.\u003C\u002Fp>","","COMELEC (Philippines Voters) Data Breach (228.6 Thousand Reported Records)","COMELEC (Philippines Voters) Data Breach. 228.6 Thousand reported records were reported. Reported data: Biometric data, Dates of birth, Email addresses…","\u002Fuploads\u002Flogo\u002Fcomelec_gov_ph.webp",false,{"name":45,"sector":46,"country":47,"website":9,"websiteArchiveUrl":39,"websiteStatus":39,"websiteCheckedAt":22},"COMELEC (Philippines Voters)","Government election commission","Philippines"]