🚨 CYBER INTELLIGENCE ALERT / EXFILTRATION OF SENSITIVE DATA: HEALTH SECTOR — GUATEMALA 🇬🇹
[STATUS: ACTIVE THREAT / UNCONFIRMED / HEALTH SECTOR / SOURCE: UNDERGROUND FORUM]
THEME ACTOR "M✘T3Я." IS SELLING ALLEGED DATABASE OF THE MINISTRY OF PUBLIC HEALTH
The threat actor identified by the alias M✘T3Я. has announced in underground communities the exfiltration and sale of the central databases of the Ministry of Public Health and Social Assistance (MSPAS) of Guatemala. The attacker claims to have compromised the perimeter infrastructure of the health servers due to the lack of controls and logical security practices, managing to extract structured records ranging from epidemic control to medical records of patients with chronic conditions and vital civil records.
🏢 Allegedly Affected Entity: Ministry of Public Health and Social Assistance of Guatemala (https://t.co/zfXJTFMCsk).
👤 Threat Actor: M✘T3Я.
🔍 Verification Status: UNCONFIRMED. As of June 24, 2026, the Guatemalan Ministry of Health authorities have not issued official statements confirming a large-scale intrusion or loss of integrity of their databases. This is unconfirmed because no evidence was found.
🗂️ FORENSIC ANALYSIS AND TAXONOMY OF THE EXPOSED DATASET
The publication explicitly details the assumption that the stolen data compromises the population's health data lifecycle, structured in four main relational modules:
📋 1. Epidiary (Epidemiological Surveillance and Outbreaks)
Content: Dates of institutional reports, hierarchical mapping by area, district, and health service, diagnosis of epidemiological events, location (community/municipality), demographic breakdown (sex and age), pregnancy status, current patient condition, and active outbreak alerts.
🔑 2. HIV List / ICD-10 Code B24.X (~12,647 records)
Content: Patient's full name in plain text, sex, date of birth, assigned unique patient code, clinical care timestamps, psychological counseling records, history of tests administered with their respective results, exact date of HIV diagnosis, and the location of the healthcare center or hospital unit responsible for treatment.
🪦 3. Deaths (FRegister)
Content: Identities of deceased persons, sex, age, exact date and time of death, residential address, clinical diagnosis with the direct cause of death, coordinates of the location of the death, type of medical care received prior to death, and the identification data of the physician who certified the death certificate.
👶 4. Births (Registration)
Content: Newborn's identity, sex, date of birth, weight, type of delivery, full names, ages and addresses of the parents and legal guardians, history of living or deceased children in the family unit, and the identity of the healthcare personnel who attended the birth.
🛡️ TECHNICAL RECOMMENDATIONS AND EMERGENCY RESPONSE (SOC)
🛑 Isolation of Reporting and Auditing Endpoints (SOC Guatemala): The MSPAS security teams are urged to immediately audit all external connections to the databases of the epidemiological surveillance systems and vital records, isolating unusual requests aimed at extracting bulk queries (Bulk Downloads).
🔑 Revocation of District and Health Center Credentials: Immediately invalidate active session tokens for administrative accounts distributed across healthcare centers nationwide. Implement the mandatory policy for changing complex passwords associated with systems that require Multi-Factor Authentication (MFA/2FA).
📊 MONITORING AND EVALUATION
Intelligence System: https://t.co/wk9bZJ2Nli
Quickly assess your website's security with: https://t.co/QZhWp0kFrO
#CyberSecurity #Guatemala #MSPAS #DataLeak #HIHList #Epidiario #DeathRegistry #Births #PIIExposure #MedicalRecords #ThreatIntelligence #CyberAlert #VECERT #Infosec #UnverifiedBreach
1/2‼️🇬🇹 Guatemalan Ministry of Finance allegedly breached: 130,000 RGAE registrations and 235,000 sensitive PDFs (324.5GB) exposed via IDOR and unauthenticated APIs
A threat actor claims to have compromised the Registro General de Adquisiciones del Estado (RGAE) system operated by the Guatemalan Ministry of Finance (Ministerio de Finanzas Públicas), the official state procurement registry.
The actor describes the breach as part of an ongoing "digital siege" against Guatemala, citing critical IDOR/BOLA vulnerabilities at /api/Solicitud/ObtenerSecciones and two open APIs without any security, including one connected to the Superintendencia de Administración Tributaria (SAT) at /api/sat/email.
The actor states that despite Cloudflare and a WAF being in place, the extraction was performed by simulating real traffic from ordinary web users to avoid alerting the system, allowing 130,000 registration records from 2020 to 2026 to be extracted, alongside 235,000 sensitive PDF documents totalling 324.5 GB.
A proof-of-concept 5,000-row CSV sample and a 200-PDF preview have been published.
▸ Actor: GordonFreeman (VIP), branded "LAT4MFUCK3RS"
▸ Sector: Government / Public Procurement / Finance
▸ Type: Data Breach (IDOR/BOLA, unauthenticated APIs)
▸ Records: 130,000 registrations + 235,000 PDFs (324.5 GB)
▸ Country: Guatemala
▸ Date: 14/05/2026
Compromised data:
Registration records (130,000 rows, 2020-2026):
▪ ID
▪ NIT (Guatemalan tax identification number)
▪ CUI (Código Único de Identificación)
▪ Nombre (full name)
▪ Direccion (address)
▪ Telefono (phone number)
▪ Correo (email address)
▪ Tipo_Org (organization type, Individual or Juridica)
PDF documents (235,000 files, 324.5 GB):
▪ University degrees and diplomas
▪ Ministry of Education teaching titles
▪ SAT invoices (Facturas)
▪ Negotiation minutes and articles of incorporation
▪ Sports minutes (actas)
▪ Simple agreements
▪ Notarial acts (Protocolos with Diez Quetzales registry stamps)
▪ Balance sheets
▪ Bank certifications
▪ Administrative contracts
▪ Signed affidavits
▪ Tax solvency certificates
▪ Commercial patents
▪ Scanned DPIs
▪ Constitution of Sociedad Anónima documents
Vulnerability details:
▪ IDOR/BOLA
▪ Unauthenticated SAT API
▪ Second unauthenticated API hosting all persons registered in RGAE
▪ Cloudflare and WAF in place but bypassed via traffic simulation
Stop guessing what's redacted. Subscribers see everything → https://t.co/281Qjc6p2J
I lost my job yesterday.
Rent was due.
No backup plan.
Then I remembered I still had Claude.
Asked it:
“Analyze every top Polymarket wallet from the last 90 days and build me something”
$25 → $4,237 in one night.
It scanned 10,000 wallets.
Cross-referenced win rates, sizing, timing.
Found 7 traders whose edge wasn’t luck.
Then built an autonomous agent.
Not a script.
Not an if-then bot.
An agent that reads live news,
maps it to markets,
detects mispricing,
and exploits arbitrage across outcomes.
Sizes every position using Kelly.
I deployed it at 11:47PM.
Closed the laptop.
Woke up to:
$25 → $4,237
94 trades while I slept.
No input.
No hesitation.
No second-guessing.
That’s the game.
Information asymmetry at machine speed.
Wall Street pays millions for this.
I pay $20/month.
You only need Claude + laptop + 1 hour/day.
Giving This Free for 24 hours. To get it:
1. Comment the word 'AutoPilot'
2. Like and Retweet this post
3. Follow me @marryevan999
#SelecciónMayor ¡Nos vemos en Argentina! 🇦🇷
La Albiceleste jugará un partido amistoso el martes 31 de marzo ante #Guatemala 🇬🇹
📝 https://t.co/NB3d3Q2QVy
Cloud computing doesn’t have to feel overwhelming.
The White Book of Cloud Computing cuts through the noise and presents cloud concepts in a clear, structured, real-world way so you understand how the cloud actually works not just the buzzwords.
💌Comment PDF for Full Guide
📘 CompTIA Security+ (SY0-701) Study Notes | Clear & Exam-Focused
These SY0-701 notes help you revise key topics quickly without wading through dense documentation.
💌Comment PDF for full Guide