news.mlab.sh
Back to the feed
threat-intel

Fuite présumée de données électorales dominicaines

High
Summary

A purported leak is claiming that the Dominican Republic’s electoral authority, the Junta Central Electoral (JCE), has been compromised, with 7.1 million citizen records and nearly 5.8 million IDs potentially exposed. A hacker, using a Half-Life character pseudonym, claims direct access and has released a sample of data. While the claim is unverified, the sheer volume of data – including names, birthdates, professions, and photographs – presents a significant risk for identity theft and fraud, particularly in sectors relying on remote identity verification.

A purported leak is claiming that the Dominican Republic’s electoral authority, the Junta Central Electoral (JCE), has been compromised, with 7.1 million citizen records and nearly 5.8 million IDs potentially exposed. A hacker, using a Half-Life character pseudonym, claims direct access and has released a sample of data. While the claim is unverified, the sheer volume of data – including names, birthdates, professions, and photographs – presents a significant risk for identity theft and fraud, particularly in sectors relying on remote identity verification. The hacker has published a sample containing 500,000 records, and ZATAZ has confirmed the existence of a second dataset of 5,758,124 JPEG files, indexed by cédula number – the Dominican Republic’s national identification number. The data includes details such as names, birthdates, sex, civil status, place of birth, blood type, and profession, alongside official photographs for millions of individuals. This association of a photograph with a cédula number and identity creates a highly exploitable dataset for fraudulent activities. The leak is linked to potential MITRE ATT&CK techniques T1530 (data from a cloud storage) and T1567 (exfiltration via web service). The JCE’s architecture and methods for protecting this sensitive information are currently unknown. The potential impact stems from the persistence of the information – a compromised password cannot be easily replaced, and a photograph cannot be readily updated. The data could be used to bolster targeted fraud scenarios, such as opening bank accounts or accessing telecommunications services. The event highlights vulnerabilities in identity verification processes and raises concerns about the security of systems relying on digital identification.

Read the full article at ZATAZ