Skip to content
DICT Confirms Defacement of Development Website by 4HMDOS4

DICT Confirms Defacement of Development Website by 4HMDOS4

First seen 4 Oct 2026, 04:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 4, 2026 at 06:06 UTC
  • •DICT confirmed a defacement incident on a development website on October 2, 2026.
  • •The threat actor 4HMDOS4 claimed responsibility, criticizing government practices.
  • •The affected site was a staging environment, not the final public version.

On October 2, 2026, the Department of Information and Communications Technology (DICT) confirmed the defacement of a test website used for development. The incident involved unauthorized access to a staging environment, not the final version intended for public use. Cybersecurity group Deep Web Konek reported that the threat actor 4HMDOS4 claimed responsibility, posting a message criticizing government spending and calling for public oversight. DICT stated that the affected site was taken down immediately and is reviewing security controls to prevent future incidents. The department did not disclose how the breach occurred or if any data was accessed. An assessment is underway to identify any vulnerabilities in the system before the website's official deployment.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-02
DICT confirms website defacement
The Department of Information and Communications Technology confirmed the defacement of a test website used for development by the threat actor 4HMDOS4.
Newsbytes.Ph
2026-10-02
Deep Web Konek reports incident
Cybersecurity group Deep Web Konek reported that the defaced page contained messages criticizing government spending and called for greater public oversight.
Newswav

More articles in this cluster (3)

Following this threat?

Track 4HMDOS4 and Department Of Information And Communications Technology in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What type of website was affected?
The affected website was a staging environment used for development and testing, not the final public version.
What actions is DICT taking after the incident?
DICT is conducting an assessment of the affected environment to identify vulnerabilities and improve security controls before the website's official deployment.
Was any sensitive data compromised?
The articles do not confirm if any data was accessed or compromised during the defacement incident.