SYS::ONLINE
Wasteland.
Briefs2241
Issues25
SinceFeb 2026
LIVE
▣ Breach MAXIA-LATAM-PANAMA 2026-08-25

Maxia Latam: Alleged Supply Chain Data Leak Exposing Panamanian Government Personnel and CSS Credentials

"A threat actor has published a structured database archive allegedly exfiltrated from Maxia Latam (`maxialatam.com`), a Panama City based IT services and software development firm whose client base includes Panama's…"

A threat actor has published a structured database archive allegedly exfiltrated from Maxia Latam (maxialatam.com), a Panama City based IT services and software development firm whose client base includes Panama's Caja de Seguro Social (CSS), the national social security and healthcare administrator. According to Brinztech, which issued a breach alert on 23 August 2026, the leak consists of five CSV files containing personnel records, system role metadata and authentication credentials tied to public sector entities including the CSS. Dark web monitoring aggregators Breach House and Dark Eye both carry an earlier listing for the same target, logged as [Panama] maxialatam.com @shinyc0rpsss.7z and attributed to a leak broker identified as "Database World ROC," with a discovery date of 11 July 2026.

Every source available for this incident is OTHER tier. There is no statement from Maxia Latam, no CSS advisory, no filing with Panama's data protection authority, and no national CERT bulletin in the material reviewed. The breach remains alleged. No source publishes a record count, a dwell time, or an intrusion vector, and readers should treat the scope described below as the threat actor's own claim rather than a verified inventory.

What Happened

Accounts differ on timing more than substance. The aggregator listings on Breach House and Dark Eye place the Maxia Latam archive in circulation from 11 July 2026, catalogued under the "Breaches" type rather than ransomware and sourced to Database World ROC, a reseller or reposter rather than an intrusion crew. Brinztech's alert, dated 23 August 2026, describes a threat actor publishing a structured archive on a public underground forum and claiming direct exfiltration from Maxia Latam's corporate and administrative infrastructure. The most consistent reading is that the data was first listed in July and picked up by wider threat intelligence coverage roughly six weeks later, but no source states this explicitly and the two events could refer to separate postings of the same corpus.

Maxia Latam is a small vendor with outsized public sector reach. Employee profiles reviewed for this brief describe the company as an IT services and IT consulting firm founded in 2012, headquartered in Panama City with a presence in the United States and staff distributed across Panama, Venezuela and Ecuador, at a headcount of roughly 30 to 40 and declining year on year. Its CEO, Pedro "Peter" Díaz, states publicly that Maxia has implemented teleradiology inside the CSS, built digital platforms including Bieni, MiTim and ELEGAD, maintains infrastructure at Panamanian penitentiary facilities, equipped imaging units at Hospital San Miguel Arcángel, deployed AI based COVID-19 monitoring, and developed the RENACER system for SENADIS, claiming impact on more than 2.5 million Panamanians. The firm also maintains a Director of Digital Transformation and Technology role, held since August 2024 by an engineer with a prior four year implementation and support tenure at the same company. That profile matters for one reason: a 30 person vendor holding privileged integration access to a health system serving approximately 84% of Panama's population is a textbook single point of supply chain failure.

Context also matters here. The CSS was itself named as a ransomware victim on 14 April 2026 by the group tracked as "thegentlemen," which claimed 3TB of data including pension, medical and investment records. Both aggregator sources carry that entry. Nothing in the available reporting links the CSS ransomware incident to the Maxia Latam leak, and they should not be assumed to be the same campaign, but defenders assessing Panamanian public sector exposure should treat them as adjacent pressure on the same institution.

What Was Taken

Only Brinztech characterises the dataset in detail, so the following is single source and attributed accordingly. Brinztech reports the archive comprises five distinct CSV files holding tabular personal data, internal contact metrics and professional system metadata. The exposed personal identifiers are said to include full legal names, active telephone numbers, both corporate and personal email addresses, and dates of birth, spanning administrative, technical and medical personnel.

The credential material is the more damaging half. Brinztech describes weakly protected or clear text authentication parameters, specifically naming default administrative tokens and department codes, appearing alongside professional email records. It assesses that this combination points to compromise of a corporate database repository or an unsegmented backup server rather than a targeted application breach.

No source in this set publishes a record count. That absence is notable and worth stating plainly: brokers usually lead with volume, and its omission here means the size of the exposure is genuinely unknown. Anyone citing a figure for this incident is citing something not present in the public record as of publication. For contrast on how volume is normally advertised, the same publisher's alert on the Polish diagnostics firm ALAB Laboratoria, issued the same day, leads with a specific claim of more than 110,000 patient records including PESEL national identifiers. That is a separate and unrelated incident in a different jurisdiction, referenced here only to illustrate the reporting convention Maxia Latam's listing does not follow.

Why It Matters

The value of this leak to an attacker is not the personal data. It is the access path.

Credentials belonging to a systems integrator are functionally credentials to that integrator's clients. If default administrative tokens and department codes were exported in clear text alongside a staff email roster, an attacker holds both halves of an authentication attempt against any CSS facing system Maxia provisioned or supports. Brinztech's own analysis flags credential stuffing and account takeover as the leading downstream risk, noting that leaked vendor credentials frequently follow predictable corporate naming conventions or default initialisation strings, which makes them cheap to spray at scale.

The personnel angle compounds it. A roster that identifies administrative, technical and medical staff by name, role, phone number and date of birth is a targeting package for voice phishing and helpdesk social engineering against a national health system. Attackers calling a CSS service desk with a real Maxia engineer's name, real department code and a plausible ticket pretext are difficult to screen out with generic awareness training.

Finally, the sector context. Panama has absorbed repeated pressure across 2026 per the aggregator timelines, including ransomware postings against Bladex in April, the CSS in April, a Panamanian telecom distributor in July, and a Panama registered bank in August. A vendor breach landing in the middle of that sequence is not an isolated event but part of a sustained regional targeting pattern in which small suppliers are the softest reachable surface.

The Attack Technique

The initial access vector is not established by any source. No source names an exploited CVE, a phishing campaign, an exposed remote access service or a compromised credential as the entry point, and no forensic timeline exists in the public record.

What can be said is inferential and belongs to Brinztech, which reads the structure of the dump as the signature of the compromise. Five flat CSV exports containing mixed personnel data, contact metrics and system metadata, with clear text authentication parameters sitting in the same corpus, is not the output of a targeted application level breach. It is the output of bulk access to an aggregated store, which Brinztech attributes to either a corporate database repository or an unsegmented backup server. That assessment is consistent with the archive format observed by the aggregators, a single compressed .7z container listed as a breach rather than an extortion post.

Distribution follows the now standard broker model. The archive surfaced as a forum posting rather than a leak site countdown, and the aggregator listings credit Database World ROC as the source, indicating the data reached wider circulation through a reposter. There is no ransom demand, no extortion timer and no named ransomware brand attached to the Maxia Latam entry in any source reviewed, which distinguishes it from the CSS ransomware post four months earlier.

What Organizations Should Do

  1. Rotate every credential Maxia Latam holds or issued. Any Panamanian public sector body with a Maxia integration, most urgently CSS facilities running teleradiology, imaging or the Bieni, MiTim, ELEGAD and RENACER platforms, should treat all vendor issued and vendor held credentials as burned. Prioritise default administrative tokens and any shared service accounts, since those are the specific artefacts Brinztech reports in the dump.
  2. Hunt retroactively, not just forward. With a July listing date and August publicity, any successful use of these credentials likely predates the alert. Review authentication logs on vendor facing systems back to at least June 2026 for logins from unfamiliar ASNs, out of hours access on integrator accounts, and successful authentications against accounts that had been dormant.
  3. Kill standing vendor access. Replace persistent integrator accounts with just in time, time boxed, MFA enforced access requiring per session approval. Where an integrator needs database level reach, scope it to named tables and log every query. A 30 person vendor should not hold continuous privileged access to a system serving 84% of a country's population.
  4. Audit backups and repositories for credential material in clear text. The suspected source here is an unsegmented backup or database store. Scan your own backup estate and internal repositories for plaintext tokens, department codes and hardcoded secrets, and segment backup infrastructure away from general corporate network reachability.
  5. Brief service desks and named personnel. Staff appearing in the dump face targeted vishing and phishing using accurate internal detail. Issue an explicit warning naming the incident, and require out of band callback verification for any password reset or access request referencing Maxia, its projects, or its staff.
  6. Run the regulatory clock now. Panama's Law No. 81 of 26 March 2019, implemented by Executive Decree No. 285 of 28 May 2021, is a comprehensive data protection statute supervised by ANTAI through its Dirección de Protección de Datos Personales, and the decree adds operational detail on breach procedures and sanction criteria. Practitioner guidance for the region frames the first 72 hours as decisive: contain and isolate in the first 12 hours without destroying volatile evidence, complete forensic triage and legal assessment by hour 36, then determine and execute notification obligations by hour 72. Affected entities should be establishing their notification position against Law 81 and Decree 285 rather than waiting for the vendor to characterise the incident.

Sources: Panamanian Technology Service Provider Maxia Latam Suffers Alleged... | Panama Ransomware & Cyber Attacks Breach House | Panama Ransomware & Cyber Attacks Dark Eye | Dark Web Leak Exposes Over 110000 Patient Records ... | Juan Cedeño | Peter Diaz | Panama Data Protection & Privacy Regulation Monitor GDPRI | Data Breach Response: What Latin American Startups Do First