BRIEFGov / MilitaryhighP58
Data leak of Argentina's Undersecretary of Management and Public Employment
Subsecretaría de Gestión y Empleo Público (Argentina)
Detected23 September 2026 · 08:29 UTC
A dataset claiming to hold Argentine public-employment records, including staff photos and home addresses, was posted on a RaidForums clone. If authentic it exposes government-employee PII that enables targeting, spear-phishing and physical-address risk. AR public-sector defenders should verify the leak and warn affected personnel.
CategoryGov / Military
Severityhigh
Priority score58
Detected23 September 2026 · 08:29 UTC
Gov / Military● 66
Base de datos de la Dirección de Tránsito y Transporte expuestaA second posting advertises the same government transit and transport directorate database, suggesting the data is being actively circulated. Exposure of citizen and vehicle records from a public agency is high-impact for privacy and for follow-on fraud. The recency of the post makes it a live alert worth monitoring.Gov / Military● 68
Filtración de base de datos de la Dirección de Tránsito y TransporteA threat actor posted a database attributed to a government transit and transport directorate on DarkForums, a Latin American government entity. Records likely include citizens', drivers' and vehicle data, meaning PII and official identifiers are exposed. Defenders in the region should treat this as a real government data exposure enabling identity theft and targeted phishing against the agency.Gov / Military● 85
Filtración de archivos internos del IMSS de México (31 GB)An actor claims to have exfiltrated 31 GB of internal IMSS files, released in two parts with Part 1 already available for download. IMSS is Mexico's public health and social-security agency, holding medical records and personal data for tens of millions of citizens. A breach of this scale exposes sensitive health and identity data and enables fraud and follow-on attacks against .gob.mx infrastructure.Gov / Military● 55
Base de datos del registro de automotores DNRPA de Argentina filtradaA leak advertised as the DNRPA (Argentina's national vehicle-property registry) database has been filtered and posted on BreachForums. This is government data covering vehicle ownership records of Argentine citizens. If authentic it is highly sensitive for identity and fraud; Argentine defenders should assess exposure.Gov / Military● 84
Filtración de base de datos de la ESE Cartagena de IndiasA mirrored posting confirms the leak of a database from esecartagenadeindias.gov.co, the state health enterprise of Cartagena de Indias, Colombia, exposing regional, municipal, name and identifier fields. Posted minutes ago, the data is fresh and circulating across multiple forums, raising re-use risk. Operators should prioritize notification and credential-hygiene actions for the affected Colombian public entity.Gov / Military● 84
Filtración de base de datos de la ESE Cartagena de IndiasA threat actor is leaking a database belonging to esecartagenadeindias.gov.co, the state health enterprise of Cartagena de Indias, Colombia, containing regional, municipal, first and last names and other personal identifiers. The post is only minutes old, so the dump is fresh and likely still unsold. Defenders should treat Colombian public-health and municipal PII as actively weaponizable for phishing, identity fraud and follow-on intrusions against public services.