Skip to content

Michoacán State Government CADPE Portal Allegedly Breached, 37,000 Supplier Identity Documents Published

Breach Report Mexico flagMexico Government / Procurement Free Download

Michoacán State Government CADPE Portal Allegedly Breached, 37,000 Supplier Identity Documents Published

Threat actors posting as homercracker and cenfecracked claim to have extracted the full contents of CADPE, the executive procurement and administrative platform of the Michoacán State Government in Mexico, which handles public tenders and supplier registration. The post describes 58GB and 37,037 documents organised into folders named by each registrant's RFC taxpayer identifier. The material is said to consist largely of scanned identity and compliance documents rather than database rows, including INE voter credentials, CURP and RFC records, professional licences, tax compliance certificates, corporate charters, recent financial statements, and photographs of registrants' fiscal addresses. The data is offered as a free direct download. The claim is unverified.

Size58GB+
Documents37,037
CountryMexico flagMexico
Actorhomercracker

Post details

TargetCADPE, Michoacán State Government
CountryMexico flagMexico
SectorGovernment / Public procurement
ListingFree direct download
Volume58GB / 37,037 documents
StructureFolders indexed by RFC
Observed
Actorshomercracker x cenfecracked

!Allegedly included

  • INE voter credentials
  • Full names
  • CURP population codes
  • RFC taxpayer identifiers
  • Official ID of owners
  • Legal representative ID
  • Professional licences
  • Fiscal domicile certificates
  • Photographs of fiscal addresses
  • Tax situation certificates
  • SAT compliance opinions
  • Financial statements (2 months)
  • Payment receipts & proofs
  • Corporate charters
  • Employee declarations
  • Email contacts

Screenshots

Potential impact

What distinguishes this claim is that the material is described as scanned source documents rather than extracted database fields. An identity number in a table supports fraud; a photographed INE credential alongside CURP, RFC, a professional licence, and a corporate charter is a ready-made identity package that can be submitted directly to institutions that accept document images. Because folders are said to be indexed by RFC, the set is also trivially searchable for any specific individual or company rather than requiring bulk processing. The more serious concern is the combination of home and business address data, photographs of those premises, and two months of financial statements, held for people who are on record as suppliers to a state government. That is not a fraud profile so much as a targeting profile: it identifies who a business owner is, where they and their premises are, what they look like, and how much money moved through the business recently. Michoacán has a well-documented and persistent problem with extortion of businesses, and material of this shape maps directly onto how such targeting is carried out. For affected registrants the exposure is physical as much as financial, and none of it can be undone by changing a credential. The free, unpriced distribution removes any barrier to who obtains it. The claim is unverified.

iStatus

Unverified

The post is a leak rather than a sale, with the archive hosted on a public file service and no price attached. Dark Web Informer is not reproducing the download location. The listing is credited to two handles operating jointly, and the posting account was created within the last week with almost no history, though the specificity of the document inventory and the RFC-indexed folder structure is more detailed than fabricated listings typically manage. Neither the document count nor the archive contents have been independently corroborated. The claim is unverified and the Michoacán State Government has not publicly addressed it. Suppliers registered with CADPE may wish to be alert to identity misuse and to unsolicited approaches referencing their business or premises.

Want everything on this breach? Paid subscribers get the full claim details and more. Check out the threat feed, then after subscribing, search there for this alert. View pricing →

DARK WEB INFORMER - THREAT INTELLIGENCE

Latest