Dark Web Informer@DarkWebInformer
1/2‼️🇬🇹 RENAP (Registro Nacional de las Personas) and SAT (Superintendencia de Administración Tributaria), Guatemala's national civil registry and tax authority, have allegedly been breached, with 18M citizen records and 5.6M vehicle records leaked on a popular cybercrime forum. The actor is demanding 2 BTC and threatening to put the entire country's data up for sale.
⠀
‣ Threat Actor: GordonFreeman (in coordination with Team L4TAMFUCKERS, Izanagi, cantpwn, YoSoyGroot)
‣ Category: Government Data Leak / Extortion
‣ Victim: RENAP & SAT (Government of Guatemala)
‣ Industry: Government / National Registry / Tax Authority
⠀
The actor states this is part of a coordinated wave of attacks against Guatemala's digital infrastructure. The post claims persistence has been established across all vulnerable government sites, with a direct extortion threat issued to the nation.
⠀
What's in it:
⠀
RENAP (18M records):
▪️ 18,000,000 citizen records
▪️ Birth certificates (Certificado de Nacimiento)
▪️ Marriage certificates
▪️ Death certificates
▪️ Full names and surnames (paternal and maternal)
▪️ National ID numbers (DPI / CUI)
▪️ Dates and places of birth
▪️ Parents' full data (mother and father, with photos)
▪️ Citizen photographs
▪️ Gender, place of origin, municipality
▪️ Verifier codes and registry IDs
⠀
SAT (5.6M vehicle records):
▪️ 5,600,000 vehicle records
▪️ Detailed vehicle ownership data
▪️ Current license plates
▪️ Tax ID (NIT) and CUI numbers
▪️ Owner's full name and fiscal address
▪️ Intended use, type, make, line/style, series, model
▪️ Engine number, chassis number, VIN
▪️ Displacement (CC), cylinders, tonnage
▪️ Seating capacity, watts/kilowatts, axles, doors
▪️ Fuel type and color
▪️ Solvency number and date
▪️ Franchise number and date
▪️ Customs office of liquidation
▪️ Insurance policy details
▪️ Registration date, last year paid, current status
▪️ Electronic Circulation Cards (Tarjeta de Circulación)
▪️ Electronic Ownership Certificates (Certificado de Propiedad de Vehículos)
⠀
Extortion demands:
⠀
▪️ Ransom: 2 BTC
▪️ Threat: Entire country's data put up for sale if not paid within days
▪️ Threat: Continued siege of targeted attacks against government systems
▪️ Claim: Persistence established across all vulnerable sites