DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Bits ‘n Pieces (Trozos y Piezas)

Posted on March 10, 2023 by chum1ng0

CL: BlackCat confirms attack on Fonasa

DataBreaches recently reported a malware attack on Chile’s National Health Fund (FONASA). There is an update to report:

In a chat on Tox, BlackCat confirmed to DataBreaches that they are responsible for the attack and they say that they will announce it soon on their leaks page. A spokesperson for the group told DataBreaches that they are not giving Fonasa any more time to respond because they have not heard from them at all.

As partial proof of their claims, they provided this site with some files.  DataBreaches was shown a screenshot of a directory of files as well as some correspondence with the names, addresses, and city of Fonasa health beneficiaries.

File directory provided by BlackCat.

The correspondence below is a letter concerning a co-pay for services for a beneficiary:

File provided by BlackCat, redacted By Databreaches.net.

Other files provided to DataBreaches were from visit reports and included personal data of employees such as names, IDs, and signatures.

Neither Fonasa nor CSIRT have provided any more details about this incident since reporting on the steps and legal action they initiated.

PE: Dark Power claims attack on Peruvian reconstruction agency

Autoridad para la Reconstrucción con Cambios (ARCC) is the Peruvian entity in charge of leading and implementing the Integral Plan for Reconstruction with Changes (PIRCC) of all the physical infrastructure damaged and destroyed by the El Niño Costero phenomenon in 13 regions of the country.

This institution was listed on or about March 9  on a leak site of a new group called Dark Power.  Unlike other groups, Dark Power invites people to contact them on Tox to download files, but they were not online whenever DataBreaches attempted to contact them.

Dark Power leak site lists Peruvian reconstruction agency.

On March 9, DataBreaches sent an email to the RCC asking them about this incident. No reply was received. Because there was no notice on their website or social media, DataBreaches also alerted Peru’s National Center for Digital Security (CNSD) of the claimed attack and data offer. CNSD thanked DataBreaches for the notification, writing, hey  “Thank you for the information provided, we will coordinate with the affected entity, to provide attention to the reported security incident.”

 

EC: Data on vaccinated Ecuadorians offered for sale (Disputed)

A database called Covid-19 allegedly from the Ministry of Public Health in Ecuador has been listed for sale on a popular forum by KelvinSecurity.

The March 5 listing claims the database contains these data fields:

 Year_v Month_v Day V Hour V Vaccination Point Unicode Establishment Zone District Province Canton Surnames Names Type Identification Number Document Sex Year Nac Month Nac Day Nac Nationality Conventional Telephone Cellular Telephone Email Population Vaccinate Vaccination Phase Name Vaccine Lot Dose Applied Was Scheduled Vaccinator Ced Vaccinator Name Enterer ID Enterer Had Covid Ethnic Self-identification Ethnic Nationality Kichwa Peoples Risk Group Exterior Vaccine Exterior Lot Exterior Dose Exterior Vaccine Date Exterior Country.

In a March 6 announcement on Twitter, the Ministry of Public Health of Ecuador appeared to deny any breach (translation):

MSP confirms that there is no vulnerability to its computer systems

The Ministry of Public Health (MSP) informs that, in relation to the publications generated on social networks about an alleged leak of the institution’s database, there is NO violation of its computer systems and, therefore, the information that is hosted on The technological infrastructure is protected in accordance with governmental and international regulations and the industry’s own computer protocols.

We urge citizens not to be deceived with the delivery of information. The illegal disclosure of databases is sanctioned by the Comprehensive Organic Penal Code (COIP) as well as by the Organic Law for the Protection of Personal Data that regulates the confidentiality of data and that they are used for the purposes for which they were created.

This State portfolio maintains in force the strategies and mechanisms that guarantee the confidentiality, integrity and availability of information in strict adherence to the law.

Government of Ecuador

Guillermo lasso PRESIDENT

So where does the government believe the data came from? Are they suggesting the data is fake?  DataBreaches found real names associated with RUC in the sample data provided by KelvinSecurity but did not contact anyone to ask about their vaccination status.

DataBreaches also reached out to KelvinSecurity to ask for their response to the government’s denial or for more information about how they acquired the data. They responded, “it is better that they continue to believe that than if I can negotiate the sale of the files.”

CO: Sensitive and exposed data from  ICETEX

ICETEX is a Colombian entity that promotes higher education and facilitates access to educational opportunities offered by the international community to improve the quality of life of Colombians.

An Icetex user who discovered a bug that exposes people’s data reported it to Icetex, but got no response. The user then reported the bug to muchohacker.lol to call attention to the problem and Icetex’s failure to address it.   MuchoHacker.lol investigated the claimed vulnerability and reported:

“MuchoHacker.lol verified that the warning is true and without any kind of technical or ‘hacked’ knowledge was able to access more than 10 documents with private and sensitive information such as ID, letters of recommendation from a person with the last name Figueroa are online. There You can read your personal data as well as the information of those who confirm that the Icetex user has been doing cultural work in the town of Suba, as well as Datacredito statements, letters from international universities, among others, which are just a click away. “

According to the user who discovered the problem, there are 104,747 documents online without any type of protection. Icetex responded by saying they were going to address the problem. It is not known for how long these data have been improperly secured or whether the data have been accessed by criminals.


Edited by Dissent.


Related:

  • KT Chief to Resign After Cybersecurity Breach Resolution
  • Cyber-Attack On Bectu’s Parent Union Sparks UK National Security Concerns
  • A business's cyber insurance policy included ransom coverage, but when they needed it, the insurer refused to pay. Why?
  • Before Their Telegram Channel Was Banned Again, ScatteredLAPSUS$Hunters Dropped Files Doxing Government Employees (2)
  • Attorney General James Secures $14.2 Million from Car Insurance Companies Over Data Breaches
  • Months After Being Notified, a Software Vendor is Still Exposing Confidential and Sealed Court Records
Category: Breach Incidents

Post navigation

← 3,400 death registry records accessed in Hawaii Department of Health data security breach
UNC data leak exposes more than 1,000 Social Security numbers →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Almost two years later, Alpha Omega Winery notifies those affected by a data breach.
  • Court of Appeal reaffirms MFSA liability in data leak case, orders regulator to shoulder costs
  • A jailed hacking kingpin reveals all about the gang that left a trail of destruction
  • Army gynecologist took secret videos of patients during intimate exams, lawsuit says

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs
  • Always watching: How ICE’s plan to monitor social media 24/7 threatens privacy and civic participation

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.