SYS::ONLINE
Wasteland.
Briefs1843
Issues23
SinceFeb 2026
LIVE
▣ Breach ARGENTINA-NATIONAL 2026-08-11

RENAPER: GordonFreeman Offers 48 Million Argentine Citizen Records

"An actor using the handle GordonFreeman is advertising what they describe as the complete database of RENAPER, Argentina's Registro Nacional de las Personas, the civil authority that issues the DNI national identity…"

An actor using the handle GordonFreeman is advertising what they describe as the complete database of RENAPER, Argentina's Registro Nacional de las Personas, the civil authority that issues the DNI national identity document. The listing, surfaced by Dark Web Informer on 10 August 2026, claims 48,000,000 records in a single 15.7GB file, with a one-million-record sample released free as proof of possession. Nothing here is confirmed. There is no RENAPER statement, no CERT.ar advisory, and no independent verification of provenance in any of the sourcing available at time of writing, and Dark Web Informer itself labels the claim unverified. What follows treats the listing as an unvalidated claim from a single non-primary source, set against a documented multi-year pattern of Argentine public-sector data exposure that makes the claim plausible enough to warrant defensive action now rather than after confirmation.

What Happened

According to the Dark Web Informer listing, GordonFreeman posted an offer on 10 August 2026 for a database file attributed to RENAPER, structured as sample-free, full-set-on-request. The advertised field schema is granular: DNI identity number, full name, date of birth, municipality, province, province of origin, street address, floor and apartment number, telephone, and internal person identifiers. The last of those is the detail worth pausing on, since internal record IDs are the sort of artefact that tends to survive only in an extract taken from the source system rather than in a set stitched together from scraped or aggregated public data.

The 48 million figure is larger than Argentina's living population, which Dark Web Informer reads as evidence of a registry-wide extract including deceased and historical records rather than a subset of active DNI holders. That interpretation is reasonable but remains the outlet's inference, not a verified finding. The alternative readings that have not been ruled out publicly are equally live: an aggregation of several smaller government and commercial datasets, a stale extract from an earlier incident being recycled, or padding with duplicate records to inflate the headline count. The published sample of one million records is what a buyer or a researcher would need to test provenance, and no such verification appears in the available sourcing.

Timing places this at the end of a heavy run of Argentine claims. In July 2026 alone, a group calling itself Chronus Team advertised roughly one million records attributed to the DNRPA vehicle registry, reported by UNDERCODE NEWS via Dark Web Intelligence on 31 July 2026, and an actor known as PampaLeaks launched a subscription service on the Spear.cx forum, reported by Brinztech on 19 July 2026. Both carry the same unverified status as the RENAPER listing.

What Was Taken

Nothing has been confirmed as taken. What has been claimed, and by whom, breaks down as follows.

For RENAPER specifically, the only figure in circulation is Dark Web Informer's: 48 million records, 15.7GB, one million released as sample. No second source in this set offers a competing count, which is itself a caution rather than a corroboration. Where multiple Argentine datasets are concerned, the figures across sources are separate incidents rather than conflicting counts of the same one: Brinztech reports PampaLeaks claiming over 230 million records spanning Argentina, Uruguay, Peru and Chile in the Samaritan API service; Realpolitik reports roughly 4 million Health Ministry patient records including 14,715 photographs, some of minors, plus 84,000 Argentine Army records covering DNI, mobile numbers, official email, dates of birth, service branch and emergency contacts; ANDigital reports nearly 6 million driving licence records taken from the ANSV digital licence pipeline; UNDERCODE NEWS reports approximately 1 million DNRPA vehicle-registry records. Confidencial's May 2026 survey groups these with incidents at PAMI and the Comisión Nacional de Energía Atómica, and notes explicitly that the episodes differ in both severity and level of official confirmation.

The sensitivity ranking within the RENAPER claim is driven by the address fields. A DNI number paired with full name and date of birth is already a durable identity key, and unlike a card number a DNI cannot be reissued to escape exposure. Adding street address resolved to floor and apartment converts an identity database into a residential directory: any named Argentine becomes physically locatable by anyone holding the file. Dark Web Informer reports that children appear in the sample with the same field completeness as adults, which mirrors the minor-inclusive exposure Realpolitik describes in the Health Ministry set.

Why It Matters

The strategic problem is not any single listing. It is that the sources, read together, describe an ecosystem moving from opportunistic dumps toward persistent, monetised access to national identity data.

Brinztech's reporting on Samaritan API is the clearest signal of that shift. PampaLeaks is described as operating a dedicated portal at samaritan-api[.]top with published documentation, more than 30 endpoints and 130 parameters, and subscription tiers from $10 for a week to $600 for two years. The actor claims the underlying corpus aggregates government databases with data from private telecoms including Claro and Movistar, and has signalled plans to expand coverage across South and Latin America. A structured query interface at $10 entry price removes the technical barrier that used to sit between a raw dump and mass-automated identity fraud. If a RENAPER-scale extract genuinely exists, a service of this shape is the obvious downstream consumer for it.

The consequences are not theoretical. Confirmado reported on 29 July 2026 that a family in Salta discovered a DNI had already been issued for their nine-year-old daughter hours before their own scheduled appointment, with Registro Civil records and appointment imagery showing a different minor presenting the original birth certificate alongside unknown adults. Investigators are examining whether an organised network is involved. That case predates the GordonFreeman listing and no source connects the two, but it demonstrates the end state that a complete civil registry extract would industrialise: identity assumption against real people, including children, at the point where the state itself issues the credential.

For defenders outside Argentina, the read-across is that any organisation performing knowledge-based verification against Argentine identity attributes should now assume those attributes are compromised, whether or not this particular listing is authentic. DNI plus name plus date of birth plus registered address is precisely the tuple that call-centre and onboarding verification scripts rely on.

The Attack Technique

No initial access vector has been disclosed for the RENAPER claim. The listing describes possession of data, not a method, and no source in this set attributes an intrusion technique.

The best-documented Argentine access chain in the available sourcing comes from The Register's 13 July 2026 report on the Argentine Football Association compromise, which is a separate incident but instructive on tradecraft. Hudson Rock told The Register it traced the AFA compromise to an infostealer infection dated 8 September 2025 on the machine of an AFA software developer of nearly a decade's tenure, with the device entering Hudson Rock's victim database the following day. The credentials sat unused for roughly ten months before the attack, claimed by "All Egyptian Cyber Warriors" following Egypt's World Cup elimination, produced mass emails from legitimate AFA domains. Hudson Rock assessed the intruders likely held profound administrative control, including phpMyAdmin panels, root access to certain databases, the training HQ management portal, the media portal and the competition management system, and found weak, easily guessable passwords reused across multiple internal systems. Data advertisements on cybercrime forums followed.

That pattern of stolen credential, long dwell, administrative database access, then forum listing is the most common route to the kind of bulk extract GordonFreeman claims, and it is worth treating as the working hypothesis absent better information. Two other data points shape the picture. ANDigital reported that the ANSV licence data was accessed not from the core registry but from the narrower slice shared with a handful of partner agencies to assemble digital licences, with the government stating that neither the databases nor sensitive citizen information were compromised even as nearly 6 million records proved to be involved and the attackers demanded $3,000 for return. UNDERCODE NEWS makes the corresponding point on the DNRPA claim: a sample and an advertisement prove someone holds data, not where the data came from. Third-party integration surfaces, not the crown-jewel database itself, are a recurring weak point in these cases.

Confidencial notes the state has been building structure in response, including the Plan Federal de Prevención de Ciberdelitos y Gestión Estratégica de la Ciberseguridad 2025-2027 approved by the Ministry of Security in January 2025, the subsequent creation of the Centro Nacional de Ciberseguridad, and Disposición 1/2026 published in May 2026 requiring national public sector bodies to produce contingency policies, recovery plans and processing centres. The outlet's framing is that digital infrastructure has outgrown the state's capacity to defend it.

What Organizations Should Do

  1. Retire static Argentine identity attributes as authentication factors. Treat DNI number, full name, date of birth and registered address as public for verification purposes. Any onboarding, password reset, or call-centre flow that authenticates on those fields alone needs replacing with document liveness checks, out-of-band confirmation, or bank-grade verification, and this should proceed regardless of whether the RENAPER listing is ever confirmed.
  2. Audit third-party data sharing before auditing the core registry. The ANSV case shows the loss occurring in the slice of data shared with partner agencies rather than the primary database. Inventory every downstream consumer of citizen data, scope each to the minimum fields required, log every bulk read, and set volumetric alerting on export paths.
  3. Hunt for infostealer exposure against your own workforce. The AFA chain began with a single developer's infected device and a ten-month gap before exploitation. Query commercial stealer-log datasets for corporate domains, force credential rotation on every match, and assume any credential appearing in a log is compromised even if the infection is old and remediated.
  4. Kill password reuse on administrative interfaces. Hudson Rock found weak, reused passwords across AFA internal systems, and direct phpMyAdmin exposure. Enforce phishing-resistant MFA on every database management panel, remove such panels from internet-facing paths, and separate administrative credentials per system.
  5. Monitor the commercial access layer, not just the dumps. Samaritan API represents subscription-based querying of aggregated citizen data. Fraud and threat intelligence teams should track these services directly, since the presence of your customers' attributes in a queryable API changes the attack economics far more than a static dump ever did.
  6. Prepare the notification and verification position now. If the RENAPER claim is confirmed, remediation for citizens is limited because a DNI cannot be reissued to escape exposure. Organisations serving Argentine customers should pre-plan step-up verification, enhanced monitoring for account takeover and SIM swap, and clear guidance for individuals who cannot change the identifier that has been exposed.

Sources: Argentina's National Identity Registry Allegedly Leaked, 48 Million... | World Cup grudge attackers may have scored Argentine FA access via... | Launch of 'Samaritan API' Offering Unauthorized Access to LATAM Cit... | Ciberseguridad estatal en alerta: la fragilidad digital argentina q... | Ola de hackeos en el gobierno de Javier Milei comprometen bases de... | Hackearon casi 6 millones de licencias de conducir y pidieron USD 3... | Grave denuncia en Salta: usaron la identidad de una niña para emiti... | Argentina’s Vehicle Registry Data Is Allegedly Leaked as Dark Web G...