ADVERTISEMENT

LTO raises data security concerns over lack of control on online platform

Published Aug 5, 2026 03:33 pm
The continuous refusal of the foreign administrator of the online platform of the Land Transportation Office (LTO) to turn over source codes and other encryption keys is making it difficult for the agency to secure the driver's license and vehicle registration data of millions of its clients, an official said.
LTO executive director Martin P. Ontog said that despite the expiry of the contract that gave birth to the Land Transportation Management System (LTMS), the agency could only view at its own data and could not administer it.
The LTMS was designed to integrate all LTO services like issuance of driver’s license, registration of motor vehicles, and issuance of transport permits into a single database and digital platform.
Ontog said the helplessness of the LTO was evident during the June 3 nationwide outage of the LTMS when the agency’s IT experts were unable to address the issue since the supplier was still managing the system's firewall.
He said the LTO investigation revealed a login activity tied to a vendor-linked account a day before the nationwide outage and that firewall logs also showed repeated connection attempts through a VPN account geolocated to a telecom connection within Metro Manila.
Ontog said the LTO has since disabled the accounts it identified and its management information division has formally recommended replacing the firewall entirely so that the agency, not the vendor, controls it,.
The nationwide outages, which the LTO said happened six times in seven weeks from June to July this year, raised the issue of data privacy of the agency clients.
It was recalled that this was one of the arguments raised by two petitioners who asked the Supreme Court to end the contract between the government and the LTMS supplier. The High Court is yet to settle the issue.
"If LTMS is compromised, and the personal data of millions of Filipino motorists and licensed drivers is leaked, who is accountable?" Ontog said during a congressional hearing.
He argued that the LTO cannot be held responsible for defending a system it has been denied the means to control, while the vendor holding that control has no active contract obligating it to do so.
"This is a liability gap [the vendor] manufactured through its own withholding. It is not a failure of LTO stewardship,” said Ontog.
Currently, the LTO has no budget line dedicated to LTMS cybersecurity and no active funded contract covering the system's cloud infrastructure and with the present arrangement of the agency having no full control of the online platform, license renewals, vehicle registration continue to be occasionally operational but are not stable.
The agency’s hands are also tied to address the issue after the Ombudsman ordered the LTO to only use the LTMS, and not its backup system through its old system.
Ontog said LTO will not seek any extension or renewal of its relationship with the vendor and will continue pressing for complete, unconditional turnover of system control, including through blacklisting proceedings already in preparation.

Related Tags

LTO digitalization
ADVERTISEMENT
.most-popular .layout-ratio{ padding-bottom: 79.13%; } @media (min-width: 768px) and (max-width: 1024px) { .widget-title { font-size: 15px !important; } }

{{ articles_filter_1561_widget.title }}

.most-popular .layout-ratio{ padding-bottom: 79.13%; } @media (min-width: 768px) and (max-width: 1024px) { .widget-title { font-size: 15px !important; } }

{{ static_articles_1562_widget.title }}

.most-popular .layout-ratio{ padding-bottom: 79.13%; } @media (min-width: 768px) and (max-width: 1024px) { .widget-title { font-size: 15px !important; } }

{{ articles_filter_1563_widget.title }}

{{ articles_filter_1564_widget.title }}

.mb-article-details { position: relative; } .mb-article-details .article-body-preview, .mb-article-details .article-body-summary{ font-size: 17px; line-height: 30px; font-family: "Libre Caslon Text", serif; color: #000; } .mb-article-details .article-body-preview iframe , .mb-article-details .article-body-summary iframe{ width: 100%; margin: auto; } .read-more-background { background: linear-gradient(180deg, color(display-p3 1.000 1.000 1.000 / 0) 13.75%, color(display-p3 1.000 1.000 1.000 / 0.8) 30.79%, color(display-p3 1.000 1.000 1.000) 72.5%); position: absolute; height: 200px; width: 100%; bottom: 0; display: flex; justify-content: center; align-items: center; padding: 0; } .read-more-background a{ color: #000; } .read-more-btn { padding: 17px 45px; font-family: Inter; font-weight: 700; font-size: 18px; line-height: 16px; text-align: center; vertical-align: middle; border: 1px solid black; background-color: white; } .hidden { display: none; }
function initializeAllSwipers() { // Get all hidden inputs with cms_article_id document.querySelectorAll('[id^="cms_article_id_"]').forEach(function (input) { const cmsArticleId = input.value; const articleSelector = '#article-' + cmsArticleId + ' .body_images'; const swiperElement = document.querySelector(articleSelector); if (swiperElement && !swiperElement.classList.contains('swiper-initialized')) { new Swiper(articleSelector, { loop: true, pagination: false, navigation: { nextEl: '#article-' + cmsArticleId + ' .swiper-button-next', prevEl: '#article-' + cmsArticleId + ' .swiper-button-prev', }, }); } }); } setTimeout(initializeAllSwipers, 3000); const intersectionObserver = new IntersectionObserver( (entries) => { entries.forEach((entry) => { if (entry.isIntersecting) { const newUrl = entry.target.getAttribute("data-url"); if (newUrl) { history.pushState(null, null, newUrl); let article = entry.target; // Extract metadata const author = article.querySelector('.author-section').textContent.replace('By', '').trim(); const section = article.querySelector('.section-info ').textContent.replace(' ', ' '); const title = article.querySelector('.article-title h1').textContent; // Parse URL for Chartbeat path format const parsedUrl = new URL(newUrl, window.location.origin); const cleanUrl = parsedUrl.host + parsedUrl.pathname; // Update Chartbeat configuration if (typeof window._sf_async_config !== 'undefined') { window._sf_async_config.path = cleanUrl; window._sf_async_config.sections = section; window._sf_async_config.authors = author; } // Track virtual page view with Chartbeat if (typeof pSUPERFLY !== 'undefined' && typeof pSUPERFLY.virtualPage === 'function') { try { pSUPERFLY.virtualPage({ path: cleanUrl, title: title, sections: section, authors: author }); } catch (error) { console.error('ping error', error); } } // Optional: Update document title if (title && title !== document.title) { document.title = title; } } } }); }, { threshold: 0.1 } ); function showArticleBody(button) { const article = button.closest("article"); const summary = article.querySelector(".article-body-summary"); const body = article.querySelector(".article-body-preview"); const readMoreSection = article.querySelector(".read-more-background"); // Hide summary and read-more section summary.style.display = "none"; readMoreSection.style.display = "none"; // Show the full article body body.classList.remove("hidden"); } document.addEventListener("DOMContentLoaded", () => { let loadCount = 0; // Track how many times articles are loaded const offset = [1, 2, 3, 4, 5, 6, 7, 8, 9, 10]; // Offset values const currentUrl = window.location.pathname.substring(1); let isLoading = false; // Prevent multiple calls if (!currentUrl) { console.log("Current URL is invalid."); return; } const sentinel = document.getElementById("load-more-sentinel"); if (!sentinel) { console.log("Sentinel element not found."); return; } function isSentinelVisible() { const rect = sentinel.getBoundingClientRect(); return ( rect.top < window.innerHeight && rect.bottom >= 0 ); } function onScroll() { if (isLoading) return; if (isSentinelVisible()) { if (loadCount >= offset.length) { console.log("Maximum load attempts reached."); window.removeEventListener("scroll", onScroll); return; } isLoading = true; const currentOffset = offset[loadCount]; window.loadMoreItems().then(() => { let article = document.querySelector('#widget_1690 > div:nth-last-of-type(2) article'); intersectionObserver.observe(article) loadCount++; }).catch(error => { console.error("Error loading more items:", error); }).finally(() => { isLoading = false; }); } } window.addEventListener("scroll", onScroll); });

Sign up by email to receive news.