Costa Rica's Ministry of Science, Innovation, Technology and Telecommunications (MICITT) and its National Cybersecurity Directorate have opened a formal investigation into a dark web listing in which a threat actor claims to hold hundreds of millions of records on Costa Rican citizens, including identity photographs, judicial files, salary histories, vehicle registrations and marriage records. The directorate detected the posting on Saturday 12 September 2026. By Monday 14 September, Cybersecurity Director Gezer Molina Colomer told Teletica that analysts had examined a released sample of roughly 10,000 lines and confirmed that part of it corresponds to real information, while stressing that this does not establish the authenticity of the full database. The actor reportedly used data attributed to President Laura Fernández as proof-of-access bait. Separately, the Banco Central de Costa Rica publicly ruled out any compromise of its own systems. One caveat on sourcing: all eight available reports are regional press or aggregator write-ups rather than first-party filings, though several carry direct quotes from MICITT officials.
What Happened
Per Delfino.cr, a user identified as "jarol1488" posted the advertisement on the DarkForums criminal marketplace on 13 September at 3:54 a.m., writing that they had "hacked a credit reporting agency and managed to obtain all this data, affecting the entire population of Costa Rica." The same listing claims the archive also contains records on foreign nationals resident in the country. None of those assertions has been confirmed by officials or independently verified.
MICITT's account, relayed through Teletica and Centroamerica360, is narrower and more cautious. Molina said the detection triggered standard analysis and investigation processes aimed at verifying authenticity, determining origin, scope and level of impact, and establishing whether any national institution's systems or information have been compromised. In his words: "We have confirmed that part of the information included in this sample is real, however this does not demonstrate the authenticity of the complete database. At this moment we are validating the origin and the true scope of this breach."
The Tico Times reports MICITT was emphatic that it cannot currently confirm a recent breach occurred, nor that the published data is genuine, and that it will release verified details only when doing so does not compromise the investigation. MICITT is coordinating with the Ministerio Público, the Organismo de Investigación Judicial (OIJ), the data protection agency Prodhab, and the Directorate of Intelligence and Security.
Independent cybersecurity specialist Esteban Jiménez, who first raised public alarm on the listing, is analysing the released files in JSON format to reverse-engineer the database structure and identify its origin. Jiménez told Teletica his working hypothesis is that the affected system belongs to a credit bureau, and that he has shared additional material with Costa Rican authorities and with Prodhab. Teletica's 13 September report notes investigators were weighing two possible source organisations; neither has been named publicly.
Accounts differ on how confident anyone should be about the credit bureau attribution. It originates with the threat actor's own marketing copy, is treated as a hypothesis by Jiménez, and has not been endorsed by MICITT. UNDERCODE NEWS separately reports that the Dark Web Intelligence account flagged "a Costa Rican credit reporting agency" on 12 September, but that post contained no detailed description of stolen data, no attacker identity, no ransom demand and no evidence that unauthorised access actually occurred.
What Was Taken
Nothing is confirmed stolen. What exists is a claimed inventory, reproduced consistently across The Tico Times, Teletica, Centroamerica360 and UNDERCODE NEWS, and a partially validated 10,000-line sample.
The listing attributed to the actor advertises:
- 374.6 million salary records
- 21.8 million address records
- 18.74 million detailed judicial or legal records
- 13.45 million telephone records
- 9.95 million citizen records
- 8.1 million additional judicial records
- 3.95 million email addresses
- 3.52 million vehicle records
- 3.39 million beneficial ownership records
- 3.31 million photographs
- 2 million marriage records
Figures for the total vary by framing rather than by contradiction. Molina characterised the actor's claim as "more than 400 million records"; the itemised counts above sum to roughly 463 million; UNDERCODE NEWS describes it only as "hundreds of millions"; and The Tico Times headline framing refers to "tens of millions of personal records belonging to people in this country." Readers should treat the itemised list as the actor's claim and the 400 million-plus figure as MICITT's characterisation of that claim, not as an official count.
Several categories exceed Costa Rica's entire population. The Tico Times puts the national population at roughly five million; UNDERCODE cites an official 2026 projection of approximately 5.22 million. Both outlets reach the same analytic conclusion, and it is the correct one: these counts almost certainly describe database rows, not distinct individuals, and would include historical entries, duplicates, transactions and multiple records tied to the same person. A 374.6 million salary-record figure is entirely plausible as a payroll ledger spanning years; it is not plausible as 374.6 million Costa Ricans.
The identity-grade content is what matters more than the row counts. Photographs tied to identity cards, judicial case files, home addresses, vehicle registrations and beneficial-ownership links are the ingredients for high-quality impersonation, not just spam.
Why It Matters
The presidential angle is the intelligence signal here, not the headline. According to Jiménez, the actor specifically surfaced personal data on President Laura Fernández, including references to residence and properties, and used it as the sample to prove the dataset's value. "What stands out is the focus on the president," Jiménez told Teletica. Choosing a head of state as the demo record is a pressure tactic: it maximises media coverage, forces a government response on the actor's timetable, and functions as free advertising to buyers. Defenders should read it as a marketing decision, and should not let it distort the assessment of what is actually in the archive.
The second signal is aggregation risk. As Centroamerica360 quoted the assessment, if authentic this would be an unusually broad national-scale exposure because the alleged datasets can potentially be correlated across identity, employment, financial and legal records. A credit bureau is precisely the kind of intermediary that has already done that correlation work on behalf of an attacker. One compromise at a data broker yields a pre-joined national identity graph that no single government ministry holds in one place. UNDERCODE makes the same point about why credit reporting organisations are disproportionately attractive targets: their systems assemble the complete financial identity.
Third, this lands in a country with institutional memory of national-scale cyber crisis. The response pattern visible here, rapid detection, cross-agency coordination with prosecutors and the data protection authority, and public refusal to confirm unverified claims, is a more mature posture than many governments manage. MICITT declining to validate the actor's numbers while simultaneously admitting the sample contains real data is honest crisis communication, and it is worth copying.
The Attack Technique
There is no confirmed intrusion vector. The only claim of method comes from the actor's own post: that they compromised a credit reporting agency and extracted its holdings wholesale. No initial access technique, vulnerability, credential compromise, insider route or timeline has been disclosed by anyone, and no ransom demand has been reported.
What the forensics show so far is structural, not intrusive. Jiménez is examining JSON-formatted files to map the schema, on the theory that the field structure will fingerprint the originating system. That is the standard approach when attribution of source matters more than attribution of actor, and it is the right one here: the practical question for Costa Rican institutions is which system leaked, not who took it.
The Banco Central de Costa Rica issued a specific denial on 14 September, reported by La Nación and echoed by Teletica. Because part of the leaked material referenced beneficial owners, speculation pointed at the BCCR's Registro de Transparencia y Beneficiarios Finales (RTBF). The central bank stated it had identified no compromise of the RTBF or any other institutional system, that its technology infrastructure remains stable and operating normally, and that the information available to date provides no technical basis to claim the published data came from the RTBF. That is one candidate source eliminated, at least by the custodian's own assessment.
A realistic alternative hypothesis, unconfirmed but consistent with the record mix, is that the archive is an aggregation assembled from multiple sources over time rather than a single clean exfiltration. Datasets that combine court records, payroll, vehicle registrations and marriage certificates rarely live inside one organisation, unless that organisation is a bureau whose business model is precisely to assemble them.
What Organizations Should Do
- Data brokers and bureaus: audit the blast radius of a single compromise. If one credential or one exposed API can enumerate your entire correlated dataset, you have built the exact asset described in this listing. Enforce per-query rate limits, volumetric anomaly alerting on bulk reads, and row-level access scoping so that no single account can pull a national dataset.
- Verify before you attribute, and say so publicly. MICITT's split message, sample partially real, database unverified, is the correct template. Organisations named in dark web listings should follow BCCR's example: investigate first, then state plainly what was and was not found, with the technical basis for the conclusion.
- Assume identity-proofing that relies on static personal data is degraded. Addresses, ID photographs, vehicle records and family status are the standard inputs to knowledge-based authentication and to manual KYC review. In the Costa Rican market, treat those attributes as potentially attacker-known and shift to possession or biometric factors for high-value transactions.
- Instrument for schema-level detection, not just perimeter alerts. The lead here came from structural analysis of leaked JSON. Maintain documented schemas and canary records in bulk datasets so that when a sample surfaces publicly, you can confirm or rule out your own systems in hours rather than weeks.
- Pre-wire the cross-agency path. MICITT's coordination with the Ministerio Público, OIJ, Prodhab and national intelligence happened fast because those channels existed. Private organisations should have equivalent pre-agreed escalation to regulators, law enforcement and their data protection authority before an incident, not during one.
- Prepare for the fraud wave regardless of verification outcome. Even a partially genuine archive is enough to fuel targeted phishing, SIM swap attempts and loan fraud against Costa Rican residents. Banks, telecoms and government services should raise verification friction on account recovery and port-out requests now, rather than waiting for MICITT to finish validating the full dataset.
Sources: Costa Rica Data Leak Probed by MICITT After Dark Web Post | "Parte de la información es real", dice Micitt tras filtración masi... | Micitt investiga presunta filtración masiva de datos de costarricen... | Experto alerta por presunta filtración masiva de datos en Costa Ric... | Costa Rica Faces a Troubling Dark Web Data Breach Claim Involving M... | Costa Rica y la filtración de datos recientes | Costa Rica Credit Reporting Agency Appears in Dark Web Intelligence... | Banco Central descarta ataque a sus sistemas tras alerta por supues...