If you’re trying to process an online transaction with the Land Transportation Franchising and Regulatory Board (LTFRB) and the system isn’t working, this time it isn’t just a normal website outage.
The LTFRB has temporarily taken its LTFRB Electronic Support System, better known as LESS, offline following a confirmed security breach involving the platform’s data environment.
As a result, services and transactions handled through LESS have been suspended until further notice while government cybersecurity specialists investigate the incident and determine when the system can safely be restored.
For public utility vehicle operators, transport companies and other clients who rely on the system for LTFRB-related transactions, this means some online processes may have to wait until the agency issues another advisory.
Here’s what we know so far.
Content
LTFRB Confirms Security Breach Affecting LESS
The LTFRB confirmed that a security incident affected the data environment of its Electronic Support System.
According to the agency, the specific information involved and the full extent of the incident are still being technically validated.
In other words, LTFRB has confirmed that a breach occurred, but officials have not yet publicly established exactly what information was affected or how extensive the compromise was.
Because the investigation is still ongoing, it is important not to assume that every piece of information stored within the system has been compromised.
That is one of the major questions cybersecurity specialists are now trying to answer.
LESS System Taken Offline
As a precaution, LTFRB temporarily placed LESS on offline status.
This means all services and transactions involving the platform have been suspended until further notice.
LTFRB offices and personnel have also been instructed not to access or process transactions through LESS until the agency officially announces that the system is safe to use again.
For users, the important thing to remember is that repeatedly trying to access the platform probably won’t solve the problem.
This isn’t simply a case of heavy website traffic or scheduled maintenance. The shutdown is part of the agency’s cybersecurity response.
When Will LTFRB LESS Be Back Online?
As of September 20, 2026, there is no announced date or time for the restoration of LESS.
LTFRB said the system will remain offline while technical assessments and security measures are being completed.
The agency has not provided a definite restoration schedule.
So if you have an upcoming LTFRB transaction, it would be best to monitor official LTFRB advisories rather than relying on unofficial posts saying that the system has already returned.
The suspension remains in effect until LTFRB officially announces otherwise.
What Transactions Are Affected?
The suspension applies to services and transactions processed through LESS.
The electronic system is used in connection with LTFRB’s digital processes involving transport operators and regulatory transactions.
Reports on the outage indicate that online franchise-related applications, renewals and other transactions handled through the platform may be affected while LESS remains unavailable.
However, not every LTFRB service necessarily runs through LESS.
If you have an urgent transaction, it may be worth checking directly with the relevant LTFRB office to determine whether an alternative procedure is available.
The agency has not yet announced a general alternative online platform replacing LESS during the suspension.
DICT and CICC Helping Investigate
LTFRB isn’t investigating the incident on its own.
The agency said it is coordinating with information technology and cybersecurity specialists from the Department of Information and Communications Technology or DICT and the Cybercrime Investigation and Coordinating Center or CICC.
The National Privacy Commission or NPC is also involved in the response.
Their work includes determining the scope of the incident, identifying what information may have been affected and helping ensure that the system is secure before it is brought back online.
Taking the system offline during this process can help prevent further unauthorized activity while investigators examine what happened.
Was Personal Information Exposed?
This is probably the biggest question for anyone who has previously submitted information through an LTFRB system.
For now, the answer isn’t completely known.
LTFRB has acknowledged that the LESS data environment was affected, but the agency has not yet publicly identified the exact information involved.
It also hasn’t announced how many records may have been affected.
That distinction is important.
There have been reports making much larger claims about allegedly exposed LTFRB records, but those claims should not automatically be treated as confirmed facts.
What About Reports of 16 Million LTFRB Records?
Before LTFRB confirmed the LESS security breach, a transport-sector coalition had already called for an investigation into reports of possible cybersecurity incidents involving the agency.
Coalition 169 asked the Department of Transportation and LTFRB to provide a technical report after reports circulated about alleged unauthorized access to agency information.
According to Newsbytes.PH, cybersecurity news site Deep Web Konek reported on September 12 that a threat actor using the name “core849” claimed to have obtained around 7.7 gigabytes of LTFRB data.
The allegedly obtained information was said to include personnel records, vehicle registration information, and franchise and operator records. A figure of around 16 million records was also reported in connection with the claim.
But there is a very important caveat here.
The authenticity and origin of the allegedly exposed data had not been independently verified when the reports were published.
More importantly, LTFRB has not confirmed that 16 million records were compromised.
The agency’s advisory also did not establish whether its confirmed LESS breach is the same incident described in those earlier claims.
So for now, “16 million records exposed” should be treated as an allegation rather than a confirmed number.
An Earlier Cybersecurity Incident Was Also Reported
The September claim wasn’t the first cybersecurity allegation involving LTFRB.
Coalition 169 also referred to an earlier alleged incident in August involving a group identified as “Quantum Security Group.”
Again, the details surrounding that reported incident were not independently established.
The coalition said it was not itself declaring that a breach had occurred at the time. Instead, it was asking government agencies to investigate the claims and provide an authoritative technical explanation.
LTFRB’s subsequent announcement confirmed a security breach involving LESS, but it did not say whether the confirmed incident was directly connected with either of those previously reported cybersecurity claims.
That connection remains one of the things to watch as the investigation develops.
What Should LTFRB Users Do?
If you’ve previously used LESS, there is no need to panic, but this is a good time to be more careful about suspicious messages.
Cybersecurity incidents involving government databases can sometimes be followed by phishing attempts in which scammers pretend to represent the affected agency.
Be cautious if you receive unexpected emails, text messages or social media messages claiming that you need to “verify” your LTFRB information.
In particular, avoid giving passwords, one-time PINs or financial information to anyone contacting you unexpectedly.
Also be suspicious of links claiming to offer an unofficial way to access LESS while the official platform is offline.
For actual LTFRB transactions, rely on official LTFRB announcements and recognized government channels.
Do You Need to Change Your Password?
If you use the same password for LESS and another online account, changing the password on those other accounts is a sensible precaution.
Using unique passwords for different online services reduces the damage that can happen if credentials from one service are ever compromised.
However, LTFRB has not publicly confirmed at this point that LESS account passwords were among the information affected.
Users should therefore avoid spreading claims that usernames, passwords or specific personal documents were exposed unless authorities confirm this through the ongoing technical investigation.
Why Did LTFRB Shut Down the Entire System?
Taking a compromised or potentially compromised system offline is a common containment measure during a cybersecurity investigation.
Investigators need to examine systems, logs, access records and other technical information without allowing potentially malicious activity to continue.
LTFRB said its own IT personnel are working with specialists from other government agencies before LESS is restored.
The goal is not simply to get the website running again as quickly as possible.
The agency also needs to determine that it can safely bring the platform back online without exposing the system to the same vulnerability that may have contributed to the incident.
What Happens to Pending LTFRB Applications?
This is another important concern for operators who may already have transactions inside LESS.
LTFRB has not yet released detailed instructions covering every type of pending application affected by the shutdown.
For now, transactions dependent on LESS cannot proceed normally while the platform remains offline.
Applicants with deadlines or urgent cases should keep copies of receipts, reference numbers, screenshots, confirmation emails and other documentation related to transactions already submitted.
These records may be useful once LTFRB provides instructions on how interrupted or pending applications will be handled.
Will LTFRB Notify People Whose Data Was Affected?
That hasn’t been announced yet.
The investigation first needs to determine what information was actually affected and whether identifiable individuals were placed at risk.
Under Philippine privacy rules, organizations may be required to notify the National Privacy Commission and affected individuals in qualifying personal data breach cases where prescribed conditions are met and there is a real risk of serious harm.
LTFRB has already said it is coordinating with the National Privacy Commission.
Further information about notifications will likely depend on what investigators discover.
LTFRB Apologizes for the Disruption
LTFRB acknowledged the inconvenience caused by the temporary suspension and said the incident is being addressed urgently.
The agency said necessary measures are being taken to protect LESS and information entrusted to LTFRB.
Additional advisories are expected once verified information becomes available.
Until then, the LESS system remains offline.
What We Know So Far
As of September 20, 2026, these are the important confirmed details:
- LTFRB has confirmed a security breach involving the LESS data environment.
- LESS has temporarily been taken offline.
- Services and transactions handled through LESS are suspended until further notice.
- LTFRB has not announced when the system will return.
- The exact information affected is still undergoing technical validation.
- LTFRB is coordinating with DICT, CICC and the National Privacy Commission.
- Reports claiming that around 16 million records were exposed have not been confirmed by LTFRB.
- LTFRB has not confirmed whether its acknowledged LESS breach is connected to the earlier reported hacking claims.
What to Watch Next
There are several important developments to monitor in the coming days.
The first is the restoration of LESS. LTFRB will need to issue an official advisory before normal transactions can resume.
The second is the result of the technical investigation. This should provide a clearer picture of what systems and information were affected.
The third is whether LTFRB or the National Privacy Commission will issue notices to specific individuals whose information may have been compromised.
And finally, authorities may eventually clarify whether the confirmed security breach is connected with the previously reported claims involving millions of LTFRB records.
Until those findings are released, separating confirmed information from allegations will be especially important.

Final Thoughts
For now, LTFRB clients will have to deal with the temporary suspension of online services while cybersecurity authorities investigate the LESS security breach.
It is certainly inconvenient, especially for operators who have applications, franchise-related transactions or other time-sensitive matters to process. But restoring the platform safely is more important than bringing it back online before the security assessment is finished.
If you’re currently trying to transact through LESS, monitor official LTFRB announcements for the restoration notice and any instructions regarding pending transactions.
And if you’ve used the platform before, be particularly careful with unexpected emails, messages or links pretending to come from LTFRB.
As of September 20, 2026, LESS remains offline, the investigation is ongoing, and LTFRB has not yet announced when online transactions will resume.



