🚨🇩🇴 Dominican Republic telecom, government, and education infrastructure allegedly exposed
A forum actor using the handle "TerroahOver" claims to have identified exposed network infrastructure associated with multiple organizations in the Dominican Republic. The post is signed "TerroahGroup."
⠀
The actor lists 3,140 items of allegedly compromised information, without clarifying whether this figure represents systems, services, or individual records.
⠀
Claimed exposures include:
⠀
• Network administration: exposed remote management interfaces for routers and gateways
• Internal information: domain and NTLM-related information disclosure involving Microsoft SQL Server
• Database services: databases allegedly exposed without IP filtering
• Web infrastructure: exposed web servers and control panels
⠀
Organizations named in the post include:
⠀
• Compañía Dominicana de Teléfonos
• Altice Dominicana (Tricom)
• Estrela Telecom
• Instituto Tecnológico de Santo Domingo (INTEC)
• Ministerio de Obras Públicas y Comunicaciones (MOPC)
• Importadora Tropical S.A.
• Alta Gracia Project Holding
⠀
The actor warns that the named organizations could face attacks if the alleged issues remain unresolved. The post includes screenshot attachments, but the material shown does not establish successful intrusion or data theft.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. https://t.co/281Qjc6p2J
⚠️ TARGETED PREVENTIVE ALERT 🇩🇴: ALLEGED MASS EXFILTRATION OF THE DOMINICAN REPUBLIC'S NATIONAL DATABASE (OVER 10 MILLION RECORDS)
[STATUS: UNCONFIRMED; VISIBLE EVIDENCE EXISTS BUT NOT YET VERIFIED / SOURCE: CYBERCRIME FORUMS (DARKFORUMS) / DATE: SEPTEMBER 19, 2026]
Centralized cyber-intelligence monitoring has detected a high-risk post on underground forums (DarkForums) in which the threat actor "rannark" claims to possess and be leaking the Dominican Republic's entire national database.
The attacker asserts that the database covers the entire national territory and includes the civilian population, minors (aged 16 and up), military personnel, active members of the National Police, and foreign residents. It is strictly noted that the magnitude and authenticity of this exfiltration
have not been officially confirmed; while there is visible evidence documented in the file—showing an electronic sales interface, an SQLite database with over 10.2 million records, and ID photos of individuals in military uniforms—the actual intrusion into government systems remains unconfirmed.
Threat Actor: rannark
Victim / Affected Entity: Dominican Republic (Civil Registry and National Data).
Sector: 🏛️ Government / National Security / Civil Data
Country: Dominican Republic 🇩🇴.
Claimed Data Volume: Over 10.2 million records (10.2M+ TOTAL RECORDS).
Data Format: 1 ZIP file (1 ZIP ARCHIVE) containing an SQLite database.
Exposed Data: Official Identity Document (Cédula). Full names and dates of birth. Occupation / Military Rank. Exact physical address. Direct phone and WhatsApp numbers. Official high-quality photographs (Official HQ Photographs).
🛡️ TECHNICAL RECOMMENDATIONS FOR CONTAINMENT AND PREVENTION (SOC / CSIRT / NATIONAL SECURITY)
Immediate Investigation and Data Cross-Referencing: The National Cybersecurity Center (CNCS) of the Dominican Republic and the Central Electoral Board (JCE) must immediately obtain samples of this data to verify its authenticity and cross-reference it with official records, in order to determine the source of the breach (whether the main civil registry or a secondary government database).
Alert to Financial Institutions: Issue an urgent bulletin to all banks and Fintech institutions in the country to raise security awareness and implement Live Biometric Verification (Liveness Detection) requirements for all sensitive transactions and the opening of new accounts.
🖥️ CENTRALIZED THREAT MONITORING SYSTEM
Intelligence System: https://t.co/wk9bZJ2Nli
Monitoring Console: https://t.co/5LuqwzYuS6
#Cybersecurity #ThreatIntel #DataLeak #DominicanRepublic #rannark #DataBreach #NationalDatabase #InfoSec #CyberAlert #VECERT #SOC #CSIRT #Unconfirmed #AllegedIncident #VisibleEvidence #SecurityAlert
⚠️ TARGETED PREVENTIVE ALERT 🇩🇴: ALLEGED CRITICAL DATA EXFILTRATION FROM THE DOMINICAN REPUBLIC NATIONAL POLICE COMPLAINT MANAGEMENT SYSTEM (SPGD)
[STATUS: UNCONFIRMED; EVIDENCE VISIBLE BUT NOT VERIFIED / SOURCE: CYBERCRIME CHANNELS / DATE: SEPTEMBER 17, 2026]
Centralized cyber-intelligence monitoring has detected the posting of a download link on underground channels that allegedly contains records from the Dominican Republic National Police's Complaint Management System (SPGD). The post offers a direct download of a file containing 10,000 lines of data via the temporary hosting platform Gofile.
It is strictly noted that this has not been officially confirmed; while there is visible evidence (such as the posted link and the official image attached by the threat actor), the authenticity of the records, their currency, and the extent of the compromise of police servers remain unverified.
🛡️ PREVENTIVE TECHNICAL CONTAINMENT RECOMMENDATIONS (SOC / CSIRT)
Urgent Access Audit (SPGD): The Dominican National Police technology department must immediately audit the SPGD audit logs to identify which user or IP address recently performed mass queries or exported 10,000 records.
🖥️ CENTRALIZED THREAT MONITORING SYSTEM
Intelligence System: https://t.co/wk9bZJ2Nli
Monitoring Console: https://t.co/5LuqwzYuS6
#Cybersecurity #ThreatIntel #DataLeak #DataBreach #DominicanRepublic #NationalPolice #SPGD #PublicSecurity #Extortion #InfoSec #CyberAlert #VECERT #SOC #CSIRT #Unconfirmed #AllegedIncident #VisibleEvidence #SecurityAlert
🚨🇩🇴 Claro Dominican Republic dataset containing 2.8M+ customer records allegedly leaked
⠀
Claro is a major telecommunications provider in the Dominican Republic, offering mobile, internet, television, and other communications services to consumers and businesses.
⠀
A forum actor using the handle jarol1488 claims to have breached Claro’s systems in the Dominican Republic and obtained a dataset containing information tied to 2,889,256 customers.
⠀
Claimed exposed data includes:
⠀
• Customer identification numbers
• Mobile phone numbers
• Subscription records
• SIM / ICCID identifiers
• Service and account status
• Plan categories and descriptions
• Activation dates
• Billing cycle information
• Release dates
• Mobile validation status
• Internal subscription and plan identifiers
⠀
The actor published sample records showing customer identifiers alongside multiple mobile subscriptions, phone numbers, SIM-related data, account status, and prepaid plan information.
⠀
The breach claim, record count, authenticity of the dataset, and full scope of the exposed customer information have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. https://t.co/281Qjc6p2J
💬 Signal: la mensajería que realmente protege tus conversaciones
Sí, sé que vas a comentar: "Pero hay una aplicación mejor..."
Ya sabes que Signal tiene buena privacidad, pero además tiene:
· Más usuarios
· Más recorrido
· Más soporte
· Más revisiones
· Más facilidad de uso
que otras aplicaciones de mensajería con una fama de un par de días...
Lo único que exige es un número de teléfono, que no tiene ni por qué identificarte, lo que facilita el uso entre usuarios avanzados y más novatos.
Podría ser mejor pero es una puerta de entrada enorme a protegerse de forma sencilla y que cualquier persona puede asumir.
Cifrado robusto, solamente recopilan tu teléfono y hora de conexión.
¿Quieres mejorarlo aún más? Utiliza "Molly". Una bifurcación que reduce la dependencia de grandes tecnológicas en ciertos procesos y utiliza sistema de notificaciones alternativos como UnifiedPush.
La aplicación de mensajería que recomiendo por excelencia, pero no la única, hablaremos de otras.
Aplicación del día 1