CSIDB logo
Threat actor

AnibalLeaks

Attribution profile

Type
Undetermined
Location
-
Known incidents
0 incidents
First seen
-
Last seen
-
Updated
2026-08-29 03:20
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

AnibalLeaks is the alias used by a hacker who gained unauthorized access to Argentina’s national identification system, RENAPER, the agency responsible for issuing national ID cards and storing citizen data within the Interior Ministry. The actor’s known activity focuses on governmental targets in Argentina, specifically the centralized identity database that holds personal information for the country’s entire population. Public statements from the hacker indicate a financial motive, as they offered to sell the stolen data and advertised a lookup service for any Argentinian user’s details. The intrusion was carried out by exploiting a virtual private network account that had been assigned to the Ministry of Health, which provided the initial vector into RENAPER’s internal network. No malware families or custom tooling are described in the reporting, with the emphasis placed on credential misuse rather than malicious software deployment.

The most significant operation attributed to AnibalLeaks occurred in October 2023, when the actor released photographs of ID cards and personal data for 44 high‑profile Argentinians, including Lionel Messi and Sergio Agüero, on a Twitter account under the same alias. Following this disclosure, the hacker posted an advertisement offering to retrieve personal details for any individual in the national ID database, later providing a sample containing Trámite numbers and identification codes to validate the claim of full database access. Argentine officials initially denied a breach but later confirmed a security incident, asserting that the VPN credential misuse did not result in a leak despite the hacker’s assertions and the evidence shared with journalists. The actor claimed possession of the complete RENAPER database and expressed intent to either sell or leak the material, underscoring a profit‑driven objective. This incident is noted as part of a pattern, with references to earlier compromises in 2017 and 2019 that point to persistent weaknesses in Argentina’s digital government infrastructure. No public attribution to a state sponsor, criminal consortium, or other affiliation has been made available in the sources.

Incidents

Attributed incidents are available to members.

0 incidents
CSIDB