Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The 2016 hack of the Philippine Commission on Elections (COMELEC) exposed voter-related personal information, but “55 million” does not establish that 55 million complete profiles—or fingerprint records—were all published online. COMELEC later said the material it reviewed was not its entire database and did not include actual biometric records; Trend Micro separately reported finding 15.8 million fingerprint records. The public accounts conflict on the data’s scope, while COMELEC said the affected public-information website was separate from the system used to conduct the May 2016 elections.

What happened in the 2016 COMELEC hack?

COMELEC said it became aware of the incident on 27 March 2016, after its public-information website was defaced and data presented as a copy of its database appeared online. On 28 March, a Senate resolution recorded reports that a separate hacker group had updated links to mirrors of the alleged dump. The resolution described claims of 16 databases and roughly 338–340 GB, but treated those figures as allegations being investigated, not as verified contents or a confirmed measure of what voters’ data was exposed.

On 21 June 2016, COMELEC published its account, “What Happened.” It said the uploaded material did not consist of the entire COMELEC database and described data associated with its Precinct Finder and Post Finder services. Those statements narrowed the commission’s account of the incident; they did not erase the conflicting contemporaneous report from Trend Micro.

What does “55 million voters exposed” mean?

The headline figure is tied to the National List of Registered Voters (NLRV), not a verified count of complete profiles proven to have been downloaded or published in the March 2016 incident. In its 2017 account of a separate January 2017 incident, the National Privacy Commission (NPC) said copies of the NLRV held in field offices contained personal information relating to roughly 55 million voters. The NPC’s dated count was 55,195,674 active voters and 20,703,662 deactivated voters, out of 75,898,336 records.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

That count describes records in the field-office copies discussed by the NPC; it is not evidence that all those records appeared in the March 2016 online dump. The distinction matters: “records held” and “records confirmed published” are different claims, and the available accounts do not establish the latter at a 55-million-record scale.

What information did the online material contain?

COMELEC’s account of Precinct Finder data

COMELEC listed the following types of information in the Precinct Finder material it described:

  • Names, dates of birth, gender, civil status, addresses, and birthplaces.
  • Precinct numbers, voter-identification and registration-record numbers, and registration dates.
  • Disability information and reasons for deletion or deactivation.

COMELEC said this described data did not include taxpayer-identification numbers, voter email addresses, parents’ names, or actual biometric records. This is the commission’s account of the dataset it reviewed, not an uncontested description of every file that may have circulated.

COMELEC’s account of Post Finder data

For Post Finder, COMELEC described 1,376,067 records. The percentages below are figures stated in the commission’s 2016 account; they describe the portions of those affected records that it said included each data type.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Data type COMELEC’s reported share or description
Active/current passport information 22% of affected records
Taxpayer-identification numbers 0.21% of affected records
Email addresses, without passwords 20% of affected records
Incomplete parent names Up to 5.5% of affected records
Philippine addresses 5.5% of affected records
Incomplete overseas information Up to 98.71% of affected records

Why reports about fingerprints differ

On 7 April 2016, GMA reported Trend Micro’s assessment that it had found broad personally identifiable information and 15.8 million fingerprint records. COMELEC’s June account, by contrast, said the data it described did not contain actual biometric records. These claims should be kept attributed to their respective sources: the public record presented here does not establish one uncontested account of the full dataset or settle whether fingerprint records were part of the material circulating online.

Did the hack affect the 2016 election results?

COMELEC said the hacked public-information website was separate from the election system used for the May 2016 elections and that the incident did not affect the results. In its June 2016 account, the commission wrote: “At the outset, it must be emphasized that the handling of the public information website DID NOT IN ANY WAY impact the results of the recently concluded May 2016 elections.” The supported distinction is between a serious personal-data exposure and an alleged change to vote totals: COMELEC denied the latter, and the cited material does not establish that the breach altered election results.

What did the National Privacy Commission find?

In a decision dated 28 December 2016 and summarized publicly on 5 January 2017, the NPC found that COMELEC violated Sections 11, 20, and 21 of the Data Privacy Act. The decision summary also said the commission recommended criminal prosecution of COMELEC chairman J. Andres D. Bautista. The recommendation is not, by itself, proof of a prosecution or its outcome; the available account does not establish the current legal disposition of that recommendation.

“Data privacy is more than the deployment of technical security; it also includes the implementation of physical and organizational measures, as well as regular review, evaluation, and updating of COMELEC’s privacy and security policies and practices.”

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

— National Privacy Commission decision summary quoting its 28 December 2016 finding

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How is the January 2017 stolen-computer incident different?

On 11 January 2017, a computer was stolen from the election office in Wao, Lanao del Sur. The NPC described the exposure of local copies of voter systems, including NLRV data, and the incident prompted a separate compliance investigation. The NPC’s 20 February 2017 account connected the field-office copies to the roughly 55-million active-voter figure and its dated active/deactivated record counts. This was a later, distinct physical-security incident—not the March 2016 website defacement and online data upload.

What did the NPC decide about separate 2022 allegations?

In a decision dated 22 September 2022 and summarized on 18 January 2023, the NPC found COMELEC and Smartmatic not liable for a specific concealment allegation involving survey forms and an overseas-voters list. That proceeding concerned different allegations; it does not reverse or replace the NPC’s 2016 finding that COMELEC violated the Data Privacy Act in connection with the earlier incident.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.