Search a title or topic

Over 20 million podcasts, powered by 

Player FM logo
Artwork

Content provided by Alberto Daniel Hill. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Alberto Daniel Hill or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.
Player FM - Podcast App
Go offline with the Player FM app!

Uruguay Data Hack Compromised Three Million Records

12:49
 
Share
 

Manage episode 522629630 series 2535026
Content provided by Alberto Daniel Hill. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Alberto Daniel Hill or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.

The combined sources present a critical analysis of the October 2025 cybersecurity incident impacting Uruguay’s Plataforma GURI, the education system's central data repository for millions of citizens, including minors. Security analysts confirm this incident is part of a systemic cyber campaign targeting the Uruguayan public sector, concurrent with breaches against the state bank (BHU) and the Ceibal education program. The central governance failure identified is the official refusal by ANEP to confirm or deny claims by groups like Tacuara, who alleged the theft of nearly 3 million sensitive PII records, thereby eroding public trust and exposing families to identity fraud risks. Legally, critics argue that the confirmed security failure violates the essential Principle of Security mandated under Uruguayan law, thereby undermining ANEP’s legal justification for processing sensitive data, particularly as it pertains to the integration of student academic and Ministry of Public Health records. The GURI platform’s failure also highlighted systemic weaknesses, including a lack of Multi-Factor Authentication and poor network segmentation, which allowed threat actors to achieve unauthorized access. The sources unanimously recommend immediate mandatory disclosure and the enforcement of foundational security controls to address these deep-seated vulnerabilities.

  continue reading

770 episodes

Artwork
iconShare
 
Manage episode 522629630 series 2535026
Content provided by Alberto Daniel Hill. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Alberto Daniel Hill or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.

The combined sources present a critical analysis of the October 2025 cybersecurity incident impacting Uruguay’s Plataforma GURI, the education system's central data repository for millions of citizens, including minors. Security analysts confirm this incident is part of a systemic cyber campaign targeting the Uruguayan public sector, concurrent with breaches against the state bank (BHU) and the Ceibal education program. The central governance failure identified is the official refusal by ANEP to confirm or deny claims by groups like Tacuara, who alleged the theft of nearly 3 million sensitive PII records, thereby eroding public trust and exposing families to identity fraud risks. Legally, critics argue that the confirmed security failure violates the essential Principle of Security mandated under Uruguayan law, thereby undermining ANEP’s legal justification for processing sensitive data, particularly as it pertains to the integration of student academic and Ministry of Public Health records. The GURI platform’s failure also highlighted systemic weaknesses, including a lack of Multi-Factor Authentication and poor network segmentation, which allowed threat actors to achieve unauthorized access. The sources unanimously recommend immediate mandatory disclosure and the enforcement of foundational security controls to address these deep-seated vulnerabilities.

  continue reading

770 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Copyright 2025 | Privacy Policy | Terms of Service | | Copyright
Listen to this show while you explore
Play