Last updated as on September 9, 2026: Taxumo is monitoring this developing incident. We will update this article as new information comes out.
The website of the Bureau of Internal Revenue (BIR), the Philippine government agency in charge of collecting taxes, was hacked in the early hours of September 9, 2026.
A hacker group called “3Musketeerz,” gained unauthorized access to the site and replaced its content with the message “3Musketeerz was here,” a “troll face” meme image, and a message about the country’s ongoing flood control issues.

💡 “3Musketeerz” is A Filipino hacker group known for defacing Philippine government websites to post political messages, operating in the same space as Anonymous Philippines, ph1ns, and other hacktivist groups targeting public institutions.
The incident was first spotted by cybersecurity observer DWK. From there, word spread quickly across Filipino online communities, including a thread on Reddit’s r/taxPH and several Facebook groups focused on Philippine taxes and personal finance.
The BIR took its website offline for a short time as a safety measure. It has since been brought back up. As of writing, the BIR has not released any official statement about what happened.
This Incident is Not Unfamiliar
It is part of a long and growing list of attacks on Philippine government websites. Some of those past attacks directly involved taxpayer documents, tax forms, and personal financial records.
In April 2023, cybersecurity researchers discovered an online storage folder containing over 1.2 million files totaling 817 gigabytes of data sitting completely unprotected. Anyone with the link could access them without a password.
The records included scanned BIR tax forms, Tax Identification Number (TIN) cards, and personal tax filings, alongside National Bureau of Investigation (NBI) records and Philippine National Police (PNP) job applications.
The National Privacy Commission (NPC) launched an investigation. The Department of Information and Communications Technology (DICT) confirmed the leak happened because a PNP recruitment and clearance database was accidentally left unprotected online. Addressing the situation, BIR Commissioner Romeo Lumagui Jr. stated: “No data breach whatsoever. The bureau has initiated response protocols to keep its database protected.”
While technically true because the BIR’s central servers were not directly breached, the incident resulted in public access to sensitive taxpayer financial information.
Similar Cybersecurity Incidents from the Past
The BIR breach is one piece of a much larger problem. According to the DICT, over 3,000 serious cyberattacks hit Philippine government systems between 2020 and 2022 alone. The attacks have continued through 2026.
Here is a quick look at what has happened:
- PhilHealth (September 2023) – The Medusa Ransomware Group encrypted PhilHealth systems and took over 700 gigabytes of member data after the agency’s antivirus software expired.
- House of Representatives (October 2023) – 3Musketeerz, the same group behind the BIR attack, defaced the House website by exploiting weaknesses in its content management system.
- Philippine Statistics Authority (October 2023) – A hacker called “ph1ns” broke into the Community-Based Monitoring System (CBMS) and accessed personal records including household data and government-issued identification documents.
- Department of Science and Technology (April 2024) – The #OpEDSA campaign, also linked to “ph1ns,” gave attackers full administrator access to Department of Science and Technology (DOST) systems, locking employees out and taking roughly 2 terabytes of data including patent documents.
- Coordinated Protest Attacks (September 2025) – Hacktivist groups linked to Anonymous Philippines flooded and defaced over 19 government websites at the same time, hitting the Bureau of Customs (BOC), the Anti-Red Tape Authority (ARTA), and multiple local government units (LGUs).
- Department of Labor and Employment and Department of Migrant Workers (September 2026) – Suspicious activity targeting both agencies was detected just days before the BIR incident, prompting DICT to take their web services offline.
Government systems get hit. Your personal tax records do not have to go down with them.
What Taxpayers Should Know After the Incident
Changing what a website looks like is the most visible part of an attack. What matters more for taxpayers is whether the hackers went further into BIR systems that hold filing records, Electronic Filing and Payment System (eFPS) data, or eBIRForms submissions.
There is no confirmation that taxpayer data was taken on September 8. Full impact assessments usually become clearer as investigations move forward. The National Privacy Commission has not made a statement. The DICT has not confirmed any involvement in the response. The BIR has not spoken publicly.
For now, the one habit worth keeping is simple: have your own copy of your tax records somewhere you control.
