CSIDB logo
Incident

Mossack Fonseca

Incident posture

Attack window
Jan 2015
Location
Panama
Status
Historical
CIA posture
Available to members
Updated
2026-01-18 02:16

Linked entities

Victim
Mossack Fonseca
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jan 2015
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A significant data breach at Mossack Fonseca resulted from unauthorized access to the firm's email server, leading to the exfiltration of 11.5 million documents totaling 2.6 terabytes of sensitive information. The leaked materials, confirmed as authentic by the company, exposed offshore financial activities of numerous high-profile individuals and entities globally, including over 140 politicians and public officials, 214,000 organizations, and billions in transactions. The Panama-based firm engaged security consultants to investigate the incident and implement preventive measures following the illegal acquisition of data, which was initially provided to a German media outlet before coordinated international release by investigative journalists. The disclosure revealed widespread use of offshore entities for asset concealment, though not all activities were necessarily illicit.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The Mossack Fonseca incident, widely known as the "Panama Papers" leak, originated from a breach of the firm's email server in 2015. Co-founder Ramon Fonseca publicly confirmed the authenticity of the leaked documents, attributing their acquisition to illegal hacking activities. The attackers exfiltrated approximately 11.5 million documents totaling 2.6 terabytes of data, representing the largest document leak in history at that time. German newspaper Sueddeutsche Zeitung initially received the stolen materials in 2015 before collaborating with the International Consortium of Investigative Journalists (ICIJ) to coordinate global publication starting in April 2016. Mossack Fonseca notified clients about the breach investigation while emphasizing efforts to implement preventive measures against future incidents. The company engaged external security consultants to analyze the compromise and strengthen their systems, though technical specifics regarding detection methods or containment timelines weren't disclosed in available reports.

The leaked documents exposed offshore financial activities of 140 politicians and public officials across multiple jurisdictions, including Iceland's Prime Minister David Gunnlaugsson, British PM David Cameron's late father, and associates of Russian President Vladimir Putin. Forensic analysis revealed connections to over 214,000 offshore entities and billions in financial transactions spanning several decades. While the breach highlighted potential tax avoidance and wealth concealment practices, media outlets noted legitimate uses for such offshore structures including estate planning and inheritance management. The ICIJ's investigation suggested international banks frequently initiated creation of these offshore entities, implying possible unawareness among some named individuals regarding operational details. Mossack Fonseca maintained operations throughout the disclosure period while facing intensified regulatory scrutiny and reputational damage across its global franchise network. No technical sector entities featured prominently in initial document releases, potentially due to alternative tax optimization strategies employed by technology firms.

Sources

Sources available to members: 1 source.

CSIDB