Skip to content

JCE Records on 7.1 Million Dominicans Advertised With 5.76 Million ID Photographs

Breach Report Dominican Republic Government No Price Stated

JCE Records on 7.1 Million Dominicans Advertised With 5.76 Million ID Photographs

A forum user posting as GordonFreeman claims to have breached the Junta Central Electoral, the Dominican Republic's central electoral board, and is publishing what they describe as 7,141,313 citizen records alongside 5,758,124 identity card photographs keyed to the cédula number of each person. The stated fields include cédula, given names and surnames, civil status, date of birth, sex, place of birth, blood type and occupation. The citizen data is given as 573 MB in .DB format and the images as 19.4 GB of JPEGs, with a 500,000 record sample published openly. No price is stated, only a messenger contact. The claim is unverified.

Citizens7,141,313
ID photographs5,758,124
Image data19.4 GB
ActorGordonFreeman

Post details

TargetJunta Central Electoral
CountryDominican Republic
SectorElectoral authority
ListingNo price stated
Volume7,141,313 records
Formats.DB and JPEG
Observed
ActorGordonFreeman

!What the post claims

  • 7,141,313 citizen records
  • 5,758,124 ID photographs
  • 573 MB database file
  • 19.4 GB of images
  • Cédula numbers
  • Record validity flag
  • Given names and surnames
  • Civil status
  • Dates of birth
  • Sex
  • Place of birth
  • Blood type
  • Occupation
  • Photos keyed to cédula
  • 500,000 record sample
  • Direct breach of JCE claimed
  • No mechanism described

Screenshots

Forum post publishing data attributed to the Junta Central Electoral, observed 24 August 2026.

Mapped techniques

The actor asserts a direct breach but describes no method. Entries below are inferred from the artefacts unless marked otherwise.

  • Collection T1213 Data from information repositories Stated The actor describes extracting citizen records directly from the electoral board's system.
  • Collection T1530 Data from cloud storage Inferred Nearly six million JPEGs named by cédula indicate a separate image store was reached alongside the database.
  • Exfiltration T1567 Exfiltration over web service Inferred The sample is distributed through a public file host. The route out of the environment is not described.

Potential impact

The photographs are what separate this from a normal registry leak. A cédula number with a full name and date of birth is an identity record; the same thing with the holder's official identity card portrait attached to it is a working identity kit, and it arrives at a scale covering most of the adult population. Remote onboarding at banks, telecoms and wallet providers frequently rests on a photograph of an identity document plus a selfie, and a genuine portrait tied to a genuine number weakens the weaker end of that market considerably. None of it can be reissued: a face cannot be rotated and a cédula rarely changes. The record fields add their own problems. Blood type is health data, place of birth and civil status feed the security questions that call centres still use, and occupation allows a set this size to be sorted into targets worth pursuing. The near complete coverage also means the useful question is not who is exposed but which institutions still treat cédula and name as proof of identity, because for those, this set is the end of that assumption.

iStatus Unverified

Unlike the same actor's Chilean listing published a day earlier, this data has no plausible public source. Electoral rolls are often published in some form; official identity card portraits held against cédula numbers are not, so if the images are genuine they came from somewhere they should not have. That makes the sample a far stronger test here, and anyone who can match a handful of images to the right people has effectively confirmed the set. What remains entirely unsupported is the breach claim itself, since no method, date or access route is given, and registry data from the region has circulated before, so overlap with older sets should be ruled out before this is treated as new. The account is established, with a substantial history and a paid rank, and this is its second national registry claim in as many days, which is either a run of genuine access or a pattern worth being sceptical of. Dark Web Informer has not retrieved the data and is not linking it, nor the contact address. The JCE has not publicly addressed the claim.

Dark Web Informer // Threat Intelligence

Latest