BRIEFGov / MilitarycriticalP85
Mexico's IMSS internal files leaked (31 GB)
IMSS (Instituto Mexicano del Seguro Social)
Detected23 September 2026 · 04:29 UTC
Reposts collapsed2
An actor claims to have exfiltrated 31 GB of internal IMSS files, released in two parts with Part 1 already available for download. IMSS is Mexico's public health and social-security agency, holding medical records and personal data for tens of millions of citizens. A breach of this scale exposes sensitive health and identity data and enables fraud and follow-on attacks against .gob.mx infrastructure.
CategoryGov / Military
Severitycritical
Priority score85
Detected23 September 2026 · 04:29 UTC
Gov / Military● 55
Base de datos del registro de automotores DNRPA de Argentina filtradaA leak advertised as the DNRPA (Argentina's national vehicle-property registry) database has been filtered and posted on BreachForums. This is government data covering vehicle ownership records of Argentine citizens. If authentic it is highly sensitive for identity and fraud; Argentine defenders should assess exposure.Gov / Military● 84
Filtración de base de datos de la ESE Cartagena de IndiasA mirrored posting confirms the leak of a database from esecartagenadeindias.gov.co, the state health enterprise of Cartagena de Indias, Colombia, exposing regional, municipal, name and identifier fields. Posted minutes ago, the data is fresh and circulating across multiple forums, raising re-use risk. Operators should prioritize notification and credential-hygiene actions for the affected Colombian public entity.Gov / Military● 84
Filtración de base de datos de la ESE Cartagena de IndiasA threat actor is leaking a database belonging to esecartagenadeindias.gov.co, the state health enterprise of Cartagena de Indias, Colombia, containing regional, municipal, first and last names and other personal identifiers. The post is only minutes old, so the dump is fresh and likely still unsold. Defenders should treat Colombian public-health and municipal PII as actively weaponizable for phishing, identity fraud and follow-on intrusions against public services.Gov / Military● 72
Filtración de datos personales de trabajadores de la Municipalidad de Barranca (Perú)A database of municipal workers from Barranca (gob.pe) is being shared, exposing full names and national DNI identity numbers. This is Peruvian government PII, enabling identity theft, targeted phishing and impersonation of public employees. Any LATAM public-sector leak of government staff identifiers warrants immediate verification and notification.Gov / Military● 35
Base de datos del Ejército de Venezuela publicada en foro clandestinoA thread claiming to hold a Venezuela Army database has been circulating on a dark forum, which would involve military personnel data of a LATAM country. However, the post is dated April 2023, so it is an old leak rather than a fresh compromise and its current accuracy is uncertain. Still relevant for background on military PII exposure but not an actionable alert today.Gov / Military● 35
Sitio gubernamental iraquí ngoao.gov.iq vulnerado y filtradoThe Iraqi government portal ngoao.gov.iq was breached and its data leaked in June 2025 by an actor using the handle henrymans0n. Government records of this kind can expose citizen data and internal systems. It is dated and outside Latin America, so it is lower priority but useful as regional government-leak context.