The “Not In Use” Bullshit, We Demand to End Government Digital Negligence

We are hacked again

As an ordinary taxpayer, I am exhausted and outraged. Every other week, we wake up to news that another Philippine government website has been defaced, breached, or hijacked. We saw it when 19 government websites were hacked during the September 21 protests , and we see it constantly with groups like Deathnote Hackers exposing our vulnerabilities.

And every single time, agencies like the Department of Information and Communications Technology (DICT) and the Cybercrime Investigation and Coordinating Center (CICC) roll out the exact same, infuriating public relations script. They tell us, “Don’t worry, no sensitive data was stolen,” or “That system is inactive and not in use.” In one particularly absurd incident involving the breach of a disaster response unit, a government official actually defended the exposed system by claiming it was intentionally “designed to be porous”.

Let us call this exactly what it is: a lazy, bullshit defense. It insults our intelligence, completely misunderstands modern cybersecurity, and ultimately puts every Filipino’s digital and financial safety at severe risk.

The System Development Life Cycle (SDLC) and the Forgotten RULE of Takedowns

In the professional IT world, there is a fundamental, non-negotiable framework known as the System Development Lifecycle (SDLC). It dictates how software should be planned, built, tested, securely maintained, and crucially—retired.

When a government project ends, a promotional campaign finishes, or a third-party vendor contract expires, the final mandatory step of the SDLC is decommissioning. You take the server offline, revoke the administrative passwords, and delete the DNS (Domain Name System) records that link the web address to the server. Forgetting to take down an obsolete site is not a minor oversight; it is gross administrative negligence. By leaving these digital ghosts plugged into the internet, the government is needlessly expanding its attack surface, giving cybercriminals a massive, unmonitored playground to test their exploits.

The Devastating Impact on Security and Trust

What actually happens when you leave an obsolete, unmaintained system online? It becomes a ticking time bomb.

Hackers actively hunt for these forgotten subdomains because they know no one is applying software updates or watching the digital alarms. A primary threat here is a “subdomain takeover”. If a government agency stops paying for a temporary cloud hosting service but forgets to delete the official routing record pointing to it, an attacker can simply register with that cloud provider, claim the abandoned space, and hijack the legitimate .gov.ph subdomain.

Worse yet, these forgotten servers act as unguarded backdoors. Look at the humiliating breach of a subdomain belonging to the Armed Forces of the Philippines, which was defaced with a cartoon ferret simply because it was left unmonitored. Or look at the breach of an eGov PH subdomain, where attackers exploited an unrestricted file upload vulnerability on what the government claimed was just an “inactive” file storage bucket.

Once hackers break into these unpatched, ignored systems, they utilize a technique called “lateral movement”. This means they use the internal network connections of the forgotten server to quietly crawl sideways through the government’s intranet, bypassing external firewalls, until they reach the highly secured core databases where our actual, sensitive data lives. The breach of a “useless” server is very often the first step in a catastrophic data leak.

Destroying Public Trust and Fueling Threat Actors

Every day, countless people receive emails, texts, or direct messages that seem to be from a bank, a government agency, or a popular company. These messages look real. They often contain urgent requests and dire warnings designed to make you act quickly. They are the tools of phishing scams, and they are a major reason why public trust in digital communication is eroding.

Phishing is a form of cybercrime where attackers pretend to be a trustworthy source to trick you into revealing sensitive information. This can include:

– Passwords
– Credit card numbers
– Social Security numbers
– Bank account details

The goal is simple: to steal your money, your identity, or both. The impact, however, is far-reaching. When people are deceived by these scams, they don’t just lose money; they lose faith in the organizations being impersonated. A single convincing phishing attack can make someone doubt every future email from their bank, even legitimate ones. This breakdown in trust is damaging for everyone.

How Phishing Attacks Work

These scams succeed because they exploit human psychology. Attackers use several key tactics:

1. Creating a Sense of Urgency: The message will say your account will be closed, a payment is overdue, or a package cannot be delivered unless you act immediately. This pressure makes you less likely to think critically.
2. Imitating Authority: Scammers use official-looking logos, email addresses that are almost identical to real ones, and language that mimics real companies. This makes the fake message seem authentic.
3. Providing a Malicious Link or Attachment: The message will include a link to a fake website that looks real or an attachment that, once opened, can install malware on your device.

The High Cost of Lost Trust

The consequences of widespread phishing extend beyond individual victims. When public trust is damaged, it creates a ripple effect:

– Increased Costs for Businesses: Companies must spend more on customer support to handle fraud reports and on security measures to protect their brand.
– Slower Adoption of Useful Services: People may avoid signing up for convenient online banking or government services because they fear being scammed.
– A Culture of Fear: Constant warnings about scams can make people overly cautious or completely avoid digital communication, hindering progress and connection.

How to Protect Yourself

You can defend against phishing by staying alert and following a few simple rules:

– Be Skeptical of Urgent Requests: Legitimate organizations rarely ask for sensitive information via email or text under extreme time pressure.
– Verify the Source: Don’t click links in suspicious messages. Instead, go directly to the company’s official website by typing the address into your browser yourself.
– Check for Errors: Look for spelling mistakes, poor grammar, or email addresses that are slightly off (e.g., `[email protected]` instead of `[email protected]`).
– Enable Multi-Factor Authentication (MFA): This adds an extra layer of security to your accounts, making it much harder for attackers to get in even if they steal your password.

Phishing is not just a technical problem; it is a direct attack on the trust that holds our digital world together. By understanding how these scams work and taking proactive steps to protect yourself, you can help stop the cycle and rebuild that essential trust.

The overall impact of this digital sprawl goes far beyond bruised political egos; it results in the complete erosion of public trust and massive financial losses for ordinary Filipinos.

An abandoned subdomain still carries the highly trusted .gov.ph name. When threat actors hijack these inactive sites, they use the government’s own authority to host fraudulent phishing pages or distribute malware. According to recent threat intelligence, the Philippines experienced a massive 423% surge in phishing websites in 2025, heavily driven by SMS-based scams that manipulate our trust.

To the average citizen, a link originating from an official government domain looks perfectly safe and will easily bypass telecom spam filters. When they click it, they are tricked into handing over their digital banking credentials. The CICC themselves reported that victims lost nearly PHP 198 million to cybercrimes in 2024, with consumer and online fraud leading the charge. When the state leaves its digital doors unlocked and allows cybercriminals to weaponize official infrastructure against the public, it destroys our confidence in every digital initiative—from the eGov app to the National ID system.

Stop Making Excuses

Defending a breach by claiming the system was “not in use” does not inspire confidence; it broadcasts total incompetence. An inactive system is actually far more dangerous than an active one precisely because nobody is guarding it.

We deserve better than lazy excuses and reactionary PR spin. It is time for the CICC, the DICT, and every government IT department to stop treating cybersecurity like a game of optics. Clean up your digital sprawl, follow proper SDLC protocols, permanently turn off the systems you are no longer using, and start taking the digital security of the Filipino people seriously. Do better.

Tzar C. Umang is a technology leader with over 15 years of experience making new technologies work for different industries. As the Chief Technology Officer at Makerspace Innovhub OPC and the Lead Developer for SUI Philippines, he leads projects that create growth and opportunities for everyone. With a strong background in blockchain development, AI engineering, and cybersecurity, Tzar has worked with organizations like the DOST Smarter Philippines Project Management Office and US startup Auto Genie. He is committed to helping the next generation of tech professionals, serving as a cybersecurity instructor at the University of Luzon and a mentor for the Saleng Mentors Group. In his free time, Tzar focuses on building practical solutions for education, healthcare, and new businesses.

Site Footer