- A threat actor claims to have accessed a database from the Office of the Mayor of Santiago de Cali containing over 600,000 records and approximately 60 GB of data spanning two years.
- The listing references public finance and tax management systems, which could expose information useful for targeted fraud, impersonation, and social engineering campaigns.
- The authenticity of the claims remains unverified, and Colombian authorities have not confirmed any breach of the municipal systems of Cali.
A cybercriminal has posted the breach of a database on a dark web forum. The seller claims the data belongs to the Office of the Mayor of Santiago de Cali in Colombia. The listing says it holds more than 600,000 records, and the data spans from 2024 to 2026.
The advertised dataset reportedly relates to public finance and tax management. This includes systems tied to ‘Gestión de Hacienda Pública’ and ‘Gestión Tributaria.’ The seller claims the total data volume reaches approximately 60 GB. The listing provides no public asking price for the information.
What the Alleged Data Contains
The seller claims the database includes municipal tax records and public finance information – these systems handle property taxes, tax returns, and taxpayer data. If authentic, the exposed information could enable targeted fraud and impersonation. Attackers could use taxpayer details for social engineering campaigns against citizens.
The listing references specific tax management systems. These include databases used for public finance administration and tax collection. The seller did not provide detailed samples to verify the claims. Security analysts treat such listings as unverified until technical validation emerges.
The 60 GB volume suggests a substantial dataset. However, the exact contents remain unclear. The seller may have compiled the data from multiple sources. Data aggregation is common in dark web listings. Threat actors often combine information from previous breaches. They also use OSINT and data enrichment services to expand their offerings.
Cali is the third-largest city in Colombia, with a population of over 2.2 million people. The municipality manages tax collection for millions of residents and businesses. A breach of this scale would affect a significant portion of the city’s taxpayers.
Previous Data Incidents in Colombia
Colombia has faced several data security incidents in recent months. In July this year, the Secretaría de Movilidad de Bogotá confirmed a data leak affecting a historical database. The breach originated from an external technology provider. The entity activated its incident response protocols and formed a crisis team.
That incident involved a database managed by a third-party vendor. The Secretaría stated that the affected information was used for internal operational processes. The agency required the provider to strengthen security controls and submit a technical report. The full scope of that breach remains under investigation.
The Valle del Cauca government also addressed claims of a data leak in April, this year. Officials concluded that the reported information had no relation to their domain. They noted that cybercriminals often recycle data from older incidents. This practice misleads people into believing the data is new.
The financial sector of Colombia has also faced cyber threats. Last year, banks revealed the increased number of attempts to compromise accounts of clients – criminals used stolen credentials from past breaches to infiltrate banking institutions. These incidents prove that Colombian businesses are facing exposure to serious risks of cyber-attacks.
Risks for the Residents of Cali
If the Cali database is authentic, the exposed information could fuel various attacks. Tax documents have a lot of information about individuals, from ID numbers to financial data in them. Therefore, criminals can steal their identity and submit them as false tax documents. Also, they can target taxpayers with convincing phishing messages.
Public finance data may reveal information about government spending and contracts. This knowledge could help attackers identify valuable targets. It could also enable corruption-related schemes. The sensitivity of tax records makes this breach more serious than typical citizen data leaks.
Tax data is extremely attractive for criminals. It contains full names, ID numbers, and property information. Criminals can use it for opening false accounts as well as for filing fake tax returns to get refunds. Such damages to victims can last for several months or even years before getting a solution.
Municipal tax systems also hold business registration data. It implies the name, address, and financial records of the business are available. Competitors or other bad actors may access this information and utilize it for getting insider information or launching attacks.
What Citizens Should Do
Residents of Cali should remain alert to potential fraud attempts. They should verify any communication claiming to come from municipal tax offices. Reputable agencies never use unsecured means to request confidential information from their clients. People must inform the local authorities of any suspicious communications.
The UK government has proposed requiring smartphone makers to build digital identity verification into devices. Newly registered phones would have parental controls by default, while users would need age verification for normal web access. Civil liberties groups have criticized the plan as a threat to online anonymity.
Citizens can also be vigilant and take advantage of breach notification services. Changing passwords of government-related accounts is additionally advisable. Also, they should enable multi-factor authentication on financial accounts to create an extra layer of security.
Citizens should monitor their tax records for unauthorized changes. They should also watch for unexpected refund requests or account notifications. Reporting any suspicious activity to tax authorities helps protect others. Keeping personal documents secure prevents additional exposure.
Any organization that uses taxpayer information should increase its security methods. Encryption and limiting access to the information to authorized persons are key parts of this process. Regular audits will help organizations identify problems before hackers exploit them. Fast detection will limit damages that result from hacking incidents.
Share this article
About the Author
Farwa is an experienced InfoSec writer and cybersecurity journalist skilled in writing articles related to cybersecurity, AI, DevOps, Big Data, Cloud security, VPNs, IAM, and Cloud Computing. Also a contributor on Tripwire.com, Infosecurity Magazine, Security Boulevard, DevOps.com, and CPO Magazine.
More from Farwa SajjadRelated Posts
Microsoft Fixes Record 974 Security Flaws as Two Windows Bugs Face Active Attacks
Microsoft fixed 974 security flaws this Patch Tuesday, its biggest release ever. Two Windows bugs ar...
ChatGPT Security Flaw Lets Hidden Prompts Exfiltrate Gmail Data Across Accounts
A single hidden instruction inside a ChatGPT chat could quietly hand a stranger access to a userR...
Australia Moves to Boost Social Media Privacy With Algorithm Opt-Out
Australia’s government may let users turn off personalized recommendation algorithms. People c...
Hackers Abuse Signed Node.js to Hide Malware from Antivirus Tools
Attackers have utilized the signed Node.js binary to launch malicious JavaScript code, enabling payl...
New Security Tool Targets Cyber Threats Hidden Behind VPNs and Proxies
Hackers hide behind VPNs and proxies to look like normal, safe visitors. Most security tools only ch...
EU Puts ChatGPT, Reddit and Roblox Under Toughest Digital Safety Rules
The European Commission named ChatGPT, Reddit and Roblox as very large online services under the Dig...