Fortalezco la seguridad de tu sitio WordPress ๐ Doy respuesta a incidentes de seguridad y malware ๐๐ค๐ง๐๐ฅ๐ง๐๐จ๐จ ๐๐๐๐ช๐ง๐๐ฉ๐ฎ ๐๐ฃ๐ฉ๐๐ช๐จ๐๐๐จ๐ฉ ๐จ
๐๐น๐ฒ๐ฟ๐๐ฎ ๐จ | Campaรฑa de #Phishing para @BancoEstado ๐จ๐ฑ, solicitando credenciales, coordenadas, datos de tarjeta y clave de cajero ๐คฏ. Llamativo lo "๐ฝ๐ฒ๐ฟ๐๐ผ๐ป๐ฎ๐น๐ถ๐๐ฎ๐ฑ๐ผ" al usar nombre del usuario asociado al RUT y lo interactiva de la interfaz. #PhishingChile
๐จ STRATEGIC CYBER INTELLIGENCE ALERT: POSSIBLE PERMISSIVE INTRUSION INTO PUBLIC HEALTH SYSTEM โ MINSAL CHILE ๐จ๐ฑ
โ ๏ธ POSSIBLE HEALTH PLATFORM WITH POTENTIAL EXPOSURE OF NATIONAL HEALTH RECORDS
[STATUS: UNVERIFIED / UNDER INVESTIGATION / ATTRIBUTED TO THREAT ACTOR / CRITICAL RISK OF EXFILTRATION AND UNAUTHORIZED PRIVILEGED ACCESS]
Through proactive monitoring of cyber threat distribution channels and hacktivist activities, the publication of a manifesto by the RSA CRACKERS group was detected on May 28, 2026.
The threat actor claims to have exploited vulnerabilities and credential flaws in the systems of the Chilean Ministry of Health.
The group alleges that the breach potentially exposed more than 36 million health records of Chilean citizens. Under a "good faith" narrative, the attacker maintains that they did not exfiltrate the database or infect the service. However, the collected graphical evidence suggests that the actor maintained operational access to an active government platform.
๐ฏ Affected Entity: Chilean Ministry of Health
๐ค Threat Actor: RSA CRACKERS
๐ Potential Volume and Impact: Theoretical exposure of up to 36 million patient records, medical histories, and national epidemiological information.
๐ Technical Breakdown and Visual Evidence Analysis
Through detailed analysis of the file, the following logical and operational compromise vectors can be deduced:
1. Credential Abuse Compromising Roles and Privileges
Generalized Access: The visual evidence in the sample image indicates that the attacker accessed the system using a legitimate but compromised corporate credential. This access likely granted them privileges to perform general queries on citizens, patients, and medical records.
Role and Institution Flexibility: The exposed web system has upper management modules that explicitly allow "Change institution" and "Select role." This means that the attacker had the operational capabilities to switch between different healthcare entities and modify their internal permissions as needed during the session.
2. Exposed Clinical and Demographic Data (PII and PHI)
The forms displayed in Screenshot_113.png reveal direct access to critical epidemiological control interfaces and patient data:
General and Epidemiological Background: Display of case notification forms, epidemiological weeks, final patient status classification (e.g., "Confirmed"), case number, corresponding SEREMI (e.g., SEREMI of Atacama), and contact information for healthcare professionals.
Patient Identification Form: Fields displaying the RUN (National Unique Identification Number), full names, surnames, sex, date of birth, patient status ("Alive" or "Deceased"), nationality, health insurance provider (e.g., FONASA), exact residential address (street, municipality, region of residence), and emergency cell phone numbers.
Geographic Segmentation: Full nationwide filtering capacity, encompassing drop-down menus for the Santiago Metropolitan Region (municipalities such as Alhuรฉ, Buin, Calera de Tango, Cerrillos, Cerro Navia, and Colina) and northern regions such as Tarapacรก, Antofagasta, Atacama, Coquimbo, and Valparaรญso.
๐ก๏ธ Emergency Mitigation and Recommendations
๐ Revocation and Cross-Cutting Audit of Identities (Critical Priority): The Ministry of Health (MINSAL) is urged to immediately invalidate all active sessions on the epidemiological and patient registration portals. It is mandatory to identify the specific account used to capture the screenshots by cross-referencing access logs with the selected options (such as the Atacama Regional Health Authority (SEREMI) or the regional consultations of May 28).
๐ Implementation of Geographic and Network Restrictions: Strengthen web application firewall (WAF) policies and restrict access to administration and role change modules exclusively through corporate VPN connections authenticated with two-factor authentication (MFA) based on hardware tokens.
โก Monitoring and Evaluation
๐ Intelligence System: https://t.co/wk9bZJ3laQ
๐ก๏ธ Quickly assess your website's security with: https://t.co/YnDw1QkkYK
#CyberSecurity #DataLeak #Chile #Minsal #RSACrackers #Anci #Hacktivism #ThreatIntelligence #CiberAlert #VECERT #DataBreach #UnderInvestigation #PublicHealth
"Hackearon" un sitio que yo cree, pero que no quisieron el servicio de mantenimiento. Y ahora me amenazan con demandar ๐, en una revisiรณn rรกpida tiene plugins "premium" que yo no instale en la creaciรณn. Apostarรญa que estรกn descargados de algรบn sitio de plugins piratas ๐
"Hackearon" un sitio que yo cree, pero que no quisieron el servicio de mantenimiento. Y ahora me amenazan con demandar ๐, en una revisiรณn rรกpida tiene plugins "premium" que yo no instale en la creaciรณn. Apostarรญa que estรกn descargados de algรบn sitio de plugins piratas ๐
Si, porque el formato de entrega de informaciรณn es similar a sistema de instituciรณn de salud al consultar por previsiรณn o datos de paciente, tipo sistema informรกtico interno.
๐จ BREAKING: Instructure, the company behind Canvas - the LMS tool used by almost every university in the United States, has been breached by popular threat actor ShinyHunters.
List of breached schools:
http://91.215.85.103/pay_or_leak/instructure_affected_schools_list.txt