🇦🇷 Argentina: RENAPER-Based Doxing API Allegedly Offered for Sale
* Threat actor advertises a commercial intelligence API allegedly containing data on Argentine citizens
* Service claims access to RENAPER-related records, family relationships, address history, phone data, and identity information
* Advertised endpoints include DNI lookups, phone-to-identity correlation, address searches, family mapping, and report generation
* Threat actor claims the platform operates independently from government APIs and supports access via web, API, VPNs, proxies, and Tor
* Listing references several Argentine public figures, politicians, and government officials as alleged examples of available records
* The service is marketed as a scalable API product rather than a traditional database dump, indicating potential commercialization of previously collected or compromised data
Analyst Note:
This listing highlights the growing trend of cybercriminals transforming leaked, scraped, and aggregated personal information into subscription-based intelligence services. Rather than selling a one-time database, actors are increasingly offering API-driven access that enables continuous querying and large-scale identity correlation. If the claims are accurate, such services significantly increase privacy, stalking, fraud, and targeted social engineering risks for both public officials and ordinary citizens.
#DDW #Intelligence #DarkWeb #RENAPER
Oh boy…@JasonOnTheDrums@TheBreakdownAB the above post I recognize. We have tried getting this to some vocal folks in #Alberta (& obviously law-enforcement).
@AlbertaNDP verified to have been sent a copy (TLDR: 2 hours of their time and this could have been avoided altogether). Bruhs - I am getting real tired of people’s focus & emphasis on ‘image’ and/or optics. That will not give you a win.
- - -
Me handing this over ( plus lending my expertise to say…@albertaNDP leader @Nenshi or @Alberta_UCP@ABDanielleSmith ) would very likely ‘tip the scales either way’. It’s your call. Ya’ll both can message me here and some of you even have my phone number (and/or txt message). If you have a few hours - I’ll walk this over to you [ Note: The ‘really important parts…I hold the copy rights - so there is that ].
- - -
Link by @wormhole (They the GOAT for encrypted file transfer). 24 hours.
cc: @edmontonjournal@globalnews@cbcfifth@CBCTheNational@CTVCalgary@ctvedmonton@APTNNews@ADanielHill@TodayDarkweb
Images courtesy of: @whiteintel_io@RockHudsonRock & Intelligence X
Data & Evidence available on @virustotal & @LevelBlueCyber OTX 2096
Milei dice que abre sus puertas a los IA-tech en la tierra sin regulación… mientras, un hackeo mas a bases de datos del Estado.
El cibercrimen a pleno…
Other update #2: To be fair I would not have know about this Tenant (or the other two without @userlolxxl to begin with).
cc: @cyb3rops
1) I believe there are more of these Tenants out there - have not gotten to them (I’ve never touched ‘cloud stuff’ before in my life)
2) Even this @virustotal graph - I may have thrown some data (i.e. ‘the kitchen sink’ into VT, but it was - and to be clear, the expertise of @userlolxxl who put in the work to make it look nice & pretty.
2) @Cyb3rops you put out a statement earlier re: ‘Bug Bounty & Responsible Disclosure’. Once is an instance, thrice is a hobby?
-Unclear if that applies here, it just sounds nice
-I tried reporting these, I sounded like a dipstick calling/writing to Microsoft that ‘hey guys…sooo…there is this one tenant thing that isn’t mine but is open with my ID/Creds/etc. No dice.
-@userlolxxl took it to the next level and put the data in an easily readable form & submitted it in to MSRC (it’s been a minute now), a ‘bug bounty report’ for these 3 Tenants). Have not heard back from MSRC about them.
-If not mistaken, I believe @userlolxxl also put in a bug bounty report for the subdomain (takeover/makeover?) for -> myCCID[.]ualberta[.]ca
-The email address that had the BEC/ATO (reported 100x over, fell upon deaf ears). My old email address is also a ‘subdomain’ now - I have no idea how that happens (not the only instance of this) -> I was told by @easyDNS and @CIRA the only way this would have been possible, is if I was a ‘Global admin’ at some point or another ( I provided screenshots of that and both #Evidence & #Data to @userlolxxl ) regarding this showing that I was at one point or another ( Uni told me “No Problems” when providing them a vulnerability report = IRL a significant amount of problems across sectors & countries ).
So to be clear…just wanted to clarify…I might have the #Data and #Evidence, but it is @userlolxxl who found the other 2 ‘Rogue’ Tenants that are under my name (still up and running…). I’ve tried reporting - I sounded like a dipstick.
@userlolxxl put in the ‘hard earned work’ - they have yet to receive any acknowledgement about the 3 malicious ‘Tenants’ nor the Subdomain thing.
It’s only #Canada ‘s 3rd largest University [ #Education, and our Provincial #Healthcare & #Government systems ] no big deal right?
No response from @albertaNDP@NathanIpYEG (who I have reported to directly and provided a ‘live presentation on’ ( wherein during ‘live presentation’ @albertaNDP was found to be ‘bleeding out’ their #Data direct to RU ip address - still active )
cc: @ADanielHill this is the kind of ‘ridiculousness’ I was referring to. I could literally slap a report on ‘whoevers’ desk here, but a lack of understanding (similar to your points on a ‘protocol of silence’ - I liken this much to be similar to a lesser and mas estupido version of that).