You are here

Marina’s SID-SRB hit by ransomware attack

Marina’s SID-SRB hit by ransomware attack
Lorenz S. Marasigan August 24, 2026 https://businessmirror.com.ph/2026/08/24/marinas-sid-srb-hit-by-ransomwa...

A RANSOMWARE attack was behind the nationwide shutdown of the Maritime Industry Authority’s (Marina) seafarer documentation system, the Department of Information and Communications Technology (DICT) confirmed, as thousands of Filipino seamen enter a second week unable to process the credentials required for their deployment abroad.

The DICT, through the Cybersecurity Bureau-National Computer Emergency Response Team (CSB-NCERT), said it is responding to a ransomware incident affecting the Marina’s Seafarer’s Identity Document (SID) and Seafarer’s Record Book (SRB) System, which was reported to the agency on August 13.

As of August 18, the Marina reported to the NCERT that the affected database and server environment were being rebuilt, while forensic investigation and validation of the affected infrastructure continued, the DICT said.

The department added that the NCERT continues to assist the Marina in validating the incident, analyzing available evidence and determining the full extent of the compromise—an indication that authorities have yet to establish how much seafarer data was accessed or taken.

The DICT said cybersecurity and recovery measures are being undertaken to restore affected services, strengthen security controls and prevent similar incidents, and that further updates will be released as verified information becomes available.

The Marina, for its part, confirmed the system was hacked on August 14—a day after the incident was reported to the NCERT.

“We have been collaborating with DICT on this matter. Ongoing pa rin ang restoration at the moment,” a Marina spokesperson said, adding that an update will be issued once the system is restored.

The agency’s own public advisory made no mention of a cyberattack, describing the outage only as “technical difficulties nationwide.” It suspended SRB and SID processing nationwide beginning August 14 “until further notice,” and advised affected applicants to await further announcements.

The suspension has frozen the pipeline of seafarer deployment. The SRB and the SID are mandatory credentials for Filipino seafarers seeking work aboard ocean-going vessels, and the affected platform is where applicants submit documents and book schedules for first-time issuance or renewal.

Appeal to Malacañang

IN an open letter addressed to President Marcos, senators and members of Congress, retired seaman Ed Flores said thousands of seafarers remain affected 11 days into the outage, with many unable to process the documents required for employment.

He said some seafarers already onboard may be forced to extend their contracts because their replacements cannot complete SID and SRB processing in time. He flagged particular concern for crews assigned to high-risk areas such as the Black Sea and the Persian Gulf, as well as those ashore who have long been on standby for their next contract.

Flores called for clear and regular updates from the agency, and said questions need to be answered on the contingency and backup systems in place for essential government services that directly affect the livelihood of thousands of Filipino families.

He described the situation as approaching a serious national maritime and employment crisis.

Repeat breach?

CYBERSECURITY expert Ashley Acedillo, former deputy director general of the National Intelligence Coordinating Agency (Nica), said the most immediate consequence is the hit to seafarers’ livelihoods, followed by the regulatory fallout.

“These documents are necessary for them to pursue their employment aboard ship,” he said.

Acedillo raised the possibility that the incident is linked to a June 2024 breach that affected four web-facing applications of the same agency.

“The first time it happens to you, one thing you have to make sure—that you have responded, remediated and restored your services—is to also make sure that the threat actor does not linger in your environment,” he said. “Is it possible this time that they were not able to remove the threat actor the last time? That’s worth looking into.”

Acedillo said the incident constitutes a data privacy breach that should draw the attention of the National Privacy Commission (NPC), alongside the DICT, and could carry fines and other legal implications for the agency.

He warned that the longer-term risk lies in what the threat actor does with the extracted data set, which could be used to perpetrate scams.

“More importantly, the security aspect of this is: they have information about our seafarers and our seafarers also man other vessels which have not just economic but security impact in the nation as well,” he said.

The Marina has not given a timeline for the restoration of the system.