Hacktivist group

LaPampaLeaks

LaPampaLeaks is the principal public-facing identity of a PampaLeaks-branded Latin American cybercrime operation focused on personal-data acquisition, aggregation, doxing and commercial identity intelligence. The actor’s most mature observable product is Samaritan API, a subscription Data-as-a-Service platform advertised as consolidating government and private-sector records from multiple Latin American countries into searchable endpoints usable by direct customers, Telegram bot developers and other service providers.

The strongest independently confirmed incident connected to the actor’s public narrative is the 2026 unauthorized access to Antel’s TuID digital-identity platform in Uruguay. Antel confirmed the access and bounded the confirmed exposure: no passwords, signing PINs, private keys or credentials were compromised, while historical fingerprint minutiae from a maximum of 163 early-enrollment users may have been exposed. LaPampaLeaks contemporaneously claimed responsibility, but Antel’s public statement does not identify the actor. This distinction is important: the incident itself is confirmed; actor attribution remains based on self-attribution and supporting public reporting rather than victim-side naming.

From April through August 2026, LaPampaLeaks used underground-marketplace posts to advertise or distribute material linked to Ceibal, DNIC, MEC/Butiá, Argentine identity datasets and GURI/CEIP, while progressively converting those datasets into reusable lookup services. The June 2026 launch of Samaritan marks a material operational transition from individual dataset sales and chat-based doxing toward an API-centric model that commoditizes identity enrichment. Actor-controlled reporting describes more than 30 endpoints, over 130 parameters, subscription access and downstream integration by third-party bot developers.

The actor’s value proposition is not merely possession of leaked records. It is the ability to correlate identity numbers, addresses, telephone data, family relationships, educational history, telecommunications information and other attributes across multiple repositories. The August 2026 GURI/CEIP sales post explicitly describes using historical school/class information to identify possible acquaintances and validate a person before querying deeper citizen-data endpoints.

INFERENCE (confidence: high): LaPampaLeaks has evolved from a leak/doxing identity into a data-enablement actor whose principal strategic value lies in reducing the time, cost and technical skill required for downstream users to resolve and enrich Latin American identities. This makes the actor relevant not only as a direct data-theft threat but as a capability supplier for fraud, social engineering, account-recovery abuse, executive targeting and other identity-driven operations.

Created by iQBlack CTI Team
Contributors 1
Last updated 2026-08-18