The Land Transportation Franchising and Regulatory Board (LTFRB) has confirmed a data breach involving its Electronic Support System (LESS), an online platform used by the agency for its regulatory and franchise-related transactions.
The breach was recorded on Sept. 13 at 10:58 p.m., according to the data breach notification filed through the National Privacy Commission’s Data Breach Notification and Monitoring System.
The LTFRB said the incident generally affected the LESS data environment, but the specific information involved and the full extent of the breach are still being determined.
As a precaution, the agency took LESS offline, resulting in the suspension of all services and transactions processed through the system until further notice.
The LTFRB has yet to disclose how many records may have been affected or what types of personal or other information may have been compromised.
The agency said it is coordinating with the Department of Information and Communications Technology, the Cybercrime Investigation and Coordinating Center and other technical experts as it investigates the incident.
It is also coordinating with the National Privacy Commission regarding the breach.
The LTFRB said the system will only be restored once it is determined to be safe, while assuring the public that measures are being taken to protect the information entrusted to the agency.
The breach could affect stakeholders who rely on LESS for LTFRB transactions, although the agency has yet to specify which services or users may have been directly affected.
The LTFRB said it will issue further updates once more information has been verified.
For now, the agency has not provided details on how the breach occurred, whether unauthorized parties were able to access or extract data, or the number and identity of individuals whose information may have been affected.
