🚨 CRITICAL CYBERINTEL ALERT: MASSIVE STUDENT DATA EXFILTRATION – UNIVERSIDAD DA VINCI (GUATEMALA) 🇬🇹🎓📂🔓
A massive data leak has been detected affecting the Universidad Da Vinci de Guatemala (UDV). Threat actor "Dianna" claims to have compromised the university's systems, citing severe deficiencies in its Web Application Firewall (WAF) security.
🏢 Affected Entity: Universidad Da Vinci de Guatemala (https://t.co/DBCuBWr2dk).
👤 Threat Actor: Dianna.
📂 Leak Volume:
98,099 JSON files containing student information.
16,000 student photographs.
🛠️ Exposure Vector: APIs exposed on the university's virtual campus subdomain (https://t.co/q0tUNXsDQn).
📅 Publication Date: May 2026.
📊 Breach Scope (PII and Biometrics)
The exfiltrated information enables comprehensive and detailed profiling of the student body:
Identity and Legal: First names, surnames, ID numbers, tax ID numbers (CIF), and marital status.
Biographical Data: Date and place of birth.
Geolocation: Full residential address, department, municipality, and zone.
Direct Contact: Mobile phone numbers, landline numbers, alternative contact numbers, and email addresses.
Visual Identification: 16,000 photographs linked to student profiles.
🛡️ Immediate Response Recommendations
🔒 API Shutdown: Universidad Da Vinci must immediately identify and restrict access to the APIs on https://t.co/q0tUNXsDQn that are serving data without authentication.
🔑 WAF Audit: Review and harden Web Application Firewall rules to prevent the mass scraping of JSON and multimedia files.
👁️ Community Notification: Inform students about the data leak so they may exercise extreme caution regarding suspicious phone calls or emails. Monitor: https://t.co/wk9bZJ2Nli
#CyberSecurity #Guatemala #UniversidadDaVinci #UDV #DataBreach #HigherEducation #PII #VECERT #InfoSec #Unverified 🇬🇹🛡️⚠️🚨🎓