Uruguay
Government / Primary Education
Sold as a Service
Uruguay's Primary Education Databases Allegedly Breached, 1M+ Children's Records Offered for Sale and Query
An actor posting as LaPampaLeaks claims to hold the databases behind GURI, the student management platform operated by Uruguay's CEIP primary education council, covering pupils enrolled between 2012 and 2025. The listing describes a family application database of 1,144,324 records alongside enrolment databases totalling 3.2 million. Fields named include national identity numbers, full names, dates of birth, home addresses, phone numbers, email addresses, family identifiers, and the specific school and class each child attended. Beyond the sale, the actor states the data is already loaded into a subscription service allowing clients to look up any Uruguayan citizen's school history. The claim is unverified.
▣Post details
Uruguay!Allegedly included
- National ID numbers
- Full names
- Dates of birth
- Home addresses
- Phone numbers
- Email addresses
- Family ID numbers
- Parent relationship records
- School name & number
- Class and year attended
- Department & jurisdiction
- Gender
- Socio-cultural classification
- Registration dates
◱Screenshots
⚠Potential impact
The subjects here are children, and the field combination is the concern rather than the volume. A record pairing a named child's date of birth and home address with the specific school and class they attend is a location dataset, not a marketing one, and no remediation exists for it: a child cannot change their identity number, their address, or where they went to school. The family identifiers extend the exposure to parents and siblings. What distinguishes this listing is that the data is described as already queryable through a paid service, which lowers the barrier from acquiring a database to simply searching a name, and the actor markets that capability for confirming a person's identity and reconstructing who they knew.
iStatus
UnverifiedThe post includes record samples and screenshots of what appear to be authenticated queries against live endpoints, suggesting access may be ongoing rather than historical. Dark Web Informer is not reproducing the endpoints, parameters, or contact channels. The actor alleges CEIP previously characterised this as a limited cybersecurity incident and took its platform offline for a week without disclosing the scope; that account is the actor's own and is uncorroborated. The claim is unverified and CEIP has not addressed this listing.
DARK WEB INFORMER - THREAT INTELLIGENCE