The COMELEC Data Breach From 2016 Is Still Leaked Online Today
HEROIC's threat intelligence team has catalogued a breach tied to COMELEC, the Philippines Commission on Elections, stemming from a security incident dated March 26, 2016. The dataset in HEROIC's breach database contains 74,971 records, each including an email address tied to the comelec.gov.ph domain. No passwords were included in this particular dataset, but the email addresses alone remain useful to attackers nearly a decade later.
Why the COMELEC Email Leak Is Dangerous
Even without passwords attached, a confirmed, government-verified email address is a valuable tool for attackers. It proves the address is real, active, and tied to a specific government system, which makes it a prime target for phishing emails designed to look like official election or government communications. Because the source is a national election body, phishing attempts built on this list can carry extra credibility with recipients who are used to receiving legitimate correspondence from COMELEC.
What Was Exposed in the COMELEC Breach
- Email addresses tied to the comelec.gov.ph domain
- 74,971 total records
- No passwords or password hashes included
Why This Matters
A leaked email address rarely stays isolated. Attackers combine it with data from other breaches to build a fuller picture of a person, then use that picture to run targeted phishing, business email compromise, or account recovery attacks. If any of these addresses were reused as a login for other accounts, they become a starting point for credential stuffing attempts even without an accompanying password, since attackers often try common or previously breached passwords against known email addresses.
How Database Breaches Like This Happen
This incident is classified as a database breach, meaning attackers gained direct access to a backend system, such as through a website vulnerability or exposed server, and extracted records in bulk rather than harvesting them one at a time. Database breaches like this one are often tied to a specific triggering event, in this case a reported website compromise, and the exported data can circulate quietly for years afterward, resurfacing in new compilations long after the original incident fades from the news.
Check If You Are Affected
If you believe your email address may be tied to a government system in the Philippines or elsewhere, it is worth checking. HEROIC's free breach scanner searches your email against more than 400 billion breached records, including this COMELEC dataset, so you can find out in seconds whether your information has been exposed and take action to protect your accounts.
Breach Breakdown
74,971 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds