The Router Is There. The Internet Isn’t. And the DICT Is Very Sorry You Noticed.

By Louis “Barok” C. Biraogo — September 21, 2026

ONLY in the Philippines!. A country where we can launch a rocket to Mars before we can launch a functional Wi-Fi router in a public school.

The Office of the Ombudsman announced this week that it has uncovered a scheme so profoundly stupid, so breathtakingly brazen, that it could only have been conceived in a government procurement office: the “ghost internet” project. Contractors deliver the hardware—routers, machines, the plastic boxes that look convincing in inspection photos—then install cheaper, outdated, or completely fake software while billing the government for the premium stuff.

And nobody notices. For years.

Assistant Ombudsman Mico Clavano explained the loophole with the weary tone of a man who has seen too many routers that do absolutely nothing:

“Once the hardware — the machines, the routers — are delivered and passes inspection, everyone assumes the software that’s supposed to run on it is there as well. But nobody actually checks.”

Nobody checks.

Let that sink in. The Philippine government, an entity that requires three signatures, two notarized affidavits, and a blood sample to replace a lightbulb in a provincial office, apparently accepts “the router arrived, therefore the internet works” as a valid procurement verification protocol.

“We Welcome This Investigation” — Said the Ghost in the Machine

The Ghost That Haunts Us All

The investigation centers on the Department of Information and Communications Technology (DICT), an agency whose name contains the word “Communications” but apparently struggles to verify whether communication is actually occurring. The Ombudsman’s four questions are elegantly simple:

  1. Were the contracted sites actually installed and working?
  2. Was the government billed for connectivity that never existed?
  3. Were the prices reasonable?
  4. Who approved, certified, or released payments for this nonsense?

Question four is the money question. Literally. Because somewhere in the bowels of the bureaucracy, a human being with a salary grade and a pension signed off on a payment voucher certifying that the government received functional internet services. That human being either (a) knowingly facilitated fraud, (b) is functionally illiterate in basic IT concepts, or (c) has discovered a way to sign documents without reading them that would make a notary public weep with envy.

A Pattern So Familiar It’s Boring

If this sounds like déjà vu, that’s because it is. In 2021, the Commission on Audit (COA) flagged the DICT for purchasing P170 million worth of laptops, tablets, and pocket Wi-Fi devices from a company registered as a general construction firm. Lex-Mar General Merchandise and Contractor had current assets of P44 million—about a quarter of the contract value—and no demonstrable capacity to supply ICT equipment. COA noted that the company’s Bureau of Internal Revenue (BIR) registration didn’t show it was engaged in the ICT supply business at all.

The DICT’s response at the time? The supplier was “technically, legally, and financially capable.” Sure. And I’m technically, legally, and financially capable of performing brain surgery. I just haven’t tried yet.

The 2021 COA report also noted that the DICT’s mandate does not include distributing gadgets to students and teachers, making the purchase potentially an “illegal expenditure.” The DICT’s defense was essentially “but we were helping during COVID.” A noble sentiment, undermined by the fact that the “help” came from a construction company that had never supplied ICT equipment in its corporate life.

The DICT’s Response: “We Welcome This”

The DICT’s public response to the Ombudsman’s investigation has been a masterclass in bureaucratic non-admission. The agency “welcomes” the probe, will “cooperate fully,” and has already implemented “stronger service-level enforcement, contract management, internal audits, and performance validation.”

Translation: “We definitely didn’t do anything wrong, but if we did, we’ve fixed it now, and also we were underfunded.”

The DICT also noted that it has upgraded its Network Monitoring System to “Version 2.” One hopes Version 2 includes the radical innovation of checking whether the software installed on government-purchased hardware actually exists. Perhaps Version 3 will include a feature where someone physically visits the site and verifies the router is, in fact, on.

The agency said it would “formally convey to the Ombudsman its full cooperation.” This is the procurement equivalent of saying “I’ll gladly testify” while your lawyer quietly shreds documents in the background. Not that the DICT is shredding documents. The DICT would never. The DICT is a beacon of transparency. The DICT is also, apparently, an agency where no one thought to check if the software matched the contract specifications.

The Verification Gap: Where Ghosts Are Born

Here is where the story stops being funny and starts being genuinely alarming.

The “ghost internet” scheme works because of a structural flaw in how government verifies technology procurement. The flaw isn’t corruption at the bidding stage, though that may exist too. The flaw is that verification stops at the physical layer.

Consider what a typical connectivity contract actually requires:

Component What the contract specifies What inspection actually verifies
Routers Specific model, throughput capacity Router exists; serial number matches
Servers Specified processing power, memory Server exists; looks correct
Operating system Specified version, licensed Nothing
Security software Specified product, current version Nothing
Internet service Specified bandwidth, uptime SLA Nothing
Configuration Specified network architecture Nothing
Actual connectivity Working internet for end users Nothing

The router arrives. The box is opened. The serial number is checked against the delivery receipt. A photograph is taken. Someone signs an Inspection and Acceptance Report. Payment is released.

And the software? The license? The actual functionality? The bandwidth that was supposed to be delivered to a remote barangay? Nobody checks. Because checking software requires technical expertise that procurement officers don’t have, and the system was never designed to require it.

This isn’t a loophole. It’s a chasm.

Why Software Verification Is Genuinely Hard

To be fair to the bureaucrats, verifying software is not like counting routers. It’s structurally difficult.

Hardware is visible. Software is not. A router on a desk is evidence. A software license key in a registry file is not. An inspector can photograph a router. An inspector cannot photograph “the software is the correct version and properly licensed.”

Hardware has serial numbers. Software has license keys that can be forged. A contractor can install an unlicensed copy of expensive software, generate a fake license certificate, and unless someone independently verifies with the vendor, the forgery is undetectable. The government pays for a legitimate license. The contractor pockets the difference.

Functional testing requires expertise that procurement officers lack. Checking whether a router is “working” is not the same as checking whether it delivers the contracted bandwidth, uptime, latency, and security specifications. That requires network engineers, testing tools, and time. Procurement officers have none of these. COA auditors, as the research materials note, “may lack specialized IT expertise to verify software licenses, versions, and functionality.”

So the system defaults to what it can verify: the physical. The router is there. The box was opened. The paperwork is signed. Move on.

The Lifecycle Trap

The verification gap doesn’t end at acceptance. It extends through the entire contract lifecycle.

A typical government IT contract might include hardware delivery, software licensing, ongoing maintenance, service-level commitments, periodic upgrades, and warranty coverage. At each stage, the same verification problem recurs. Did the contractor actually provide the maintenance? Did the software get upgraded to the specified version? Is the uptime actually 99.5%, or is that just what the monthly report says?

The government typically relies on self-reporting from contractors for these metrics. The contractor says the system achieved 99.5% uptime. The contractor says maintenance was performed. Unless someone independently verifies—which requires technical capability the government often lacks—the contractor’s word is the only evidence.

This is not a system designed to detect fraud. It is a system designed to process payments.

What a Real Verification Protocol Would Look Like

If the government were serious about preventing “ghost internet,” it would require:

  1. Independent software audit before acceptance. Not a visual inspection. An actual technical audit: license key validation with the software vendor, version verification, functionality testing, configuration review. This requires hiring third-party IT forensic experts—which costs money, takes time, and creates its own procurement challenges. But it’s the only way to know whether the software the government paid for is the software the government received.
  2. Separate physical acceptance from functional acceptance. The router arriving should trigger a physical acceptance report. The router working as specified should trigger a separate functional acceptance report. Payment should be tied to the functional report, not the physical one.
  3. Performance-linked payments. Instead of “delivery → 100% payment,” the structure should be “delivery → installation → testing → operational acceptance → performance period → payment/retention.” A contractor that installs a router but never delivers functional internet should not receive full payment.
  4. Automated telemetry for connectivity projects. For thousands of public Wi-Fi sites, the government should have real-time visibility into whether each site is online, what bandwidth it’s delivering, how many users are connecting, and when outages occur. Commercial ISPs do it routinely. The government apparently does not.
  5. Vendor confirmation of licenses. For any software component above a certain value, the government should require direct confirmation from the software vendor that the license is valid, properly assigned to the government, and covers the specified version and duration.
  6. A contractor performance database. A contractor that repeatedly fails to deliver functional systems should not simply receive another contract. RA 12009 already contemplates procurement analytics and sanctions against private entities. The government should use them.

Why This Matters Beyond the DICT

The “ghost internet” scheme, if confirmed, is not just a DICT problem. It’s a template.

Every government agency that procures technology—which is now every government agency—faces the same verification gap. The Department of Health buys telemedicine systems. The Department of Education buys e-learning platforms. The Bureau of Internal Revenue buys tax processing software. The Land Transportation Office buys license processing systems. The Philippine Statistics Authority buys data management systems.

In each case, the same vulnerability exists: hardware is verified, software is assumed, functionality is self-reported, and payments are released. The “ghost internet” scheme may be the first one caught. It is unlikely to be the only one.

The Cruelest Irony

The DICT’s flagship eGovPH Super App, which supports over 100 government services, experienced a major outage in April 2026 that exposed funding and capacity issues. The National ID system, used by 91 million registered Filipinos, has suffered crashes. Free Wi-Fi sites have gone inactive because contractors went unpaid.

And now we learn that some of the “internet” the government paid for might never have existed in the first place. Not because of budget cuts or technical glitches. Because someone, somewhere, decided that a router without software is close enough for government work.

The government simultaneously claims it cannot afford to pay contractors for the Wi-Fi sites it has already built, while potentially having paid for Wi-Fi sites that were never functionally built in the first place. The money went somewhere. It just didn’t go to the internet.

The Punchline

The Ombudsman’s fact-finding investigation is ongoing. No specific contractors, officials, or amounts have been named. The DICT says it welcomes the probe. The public is told to wait for updates.

Meanwhile, somewhere in a government office, a router sits on a desk. It is plugged in. Its lights blink green. And it does absolutely nothing.

Kind of like the verification protocols that were supposed to catch this in the first place.

And kind of like the accountability mechanisms that were supposed to catch the verification protocols failing.

At some point, “ghost internet” stops being a metaphor for procurement fraud and becomes something closer to a national condition: the persistent, structural, almost supernatural ability of the Philippine government to spend money on things that do not exist, verify things that were never delivered, and then express surprise when the public notices.

The ghost isn’t in the machine.

The ghost is the machine.

Key Citations

A. Legal & Official Sources

B. News Articles

C. Official Websites


Louis ‘Barok‘ C. Biraogo

Leave a comment