Costa Rica’s National Cybersecurity Directorate is investigating a dark web post claiming to offer tens of millions of records tied to people in Costa Rica, including identity card photos, court files, vehicle registrations, salary histories, marriage records, addresses, emails, phone numbers, and beneficial ownership data. MICITT said it detected the publication and opened a technical analysis to determine whether the material is authentic, where it came from, how large it is, and whether any national institution was compromised. Officials emphasized that they cannot yet confirm a recent breach or validate the published data, and several claimed counts appear to represent database rows rather than unique individuals.
The potential sensitivity is enormous because the alleged dataset spans personal identity, legal, financial, employment, property, vehicle, and corporate ownership information. Researchers are considering whether the material may have come from a credit reporting agency or from structures resembling Costa Rica’s Transparency and Beneficial Ownership Registry, which collects information on the real individuals who own or control corporations and private trusts. If authentic, this would not be a simple contact-data leak — it could combine identity documents, property records, salary data, court history, ownership structures, and relationship records into a powerful toolkit for fraud, extortion, impersonation, property scams, and targeted social engineering.
Incidents like this show why governments need more than perimeter defenses; they need a national-scale security data foundation in a lake like NIKSUN that can trace data lineage across agencies, registries, cloud systems, databases, identity platforms, and network traffic. When a threat actor claims to hold hundreds of millions of records, investigators should be able to rapidly compare samples against known schemas, identify which system generated the fields, map access history, detect abnormal queries, and determine whether data was exported, scraped, or recycled from older breaches. A unified platform, such as NIKSUN, combining SIEM, NDR, EDR, XDR, threat intelligence, database activity monitoring, packet capture, NetFlow/IPFIX, DNS, forensic retention, and compliance reporting gives cyber authorities one evidence layer to validate or disprove the claim. That is the difference between reacting to a dark web listing with uncertainty and quickly proving the origin, scope, affected institutions, and containment path.
Read more about this story on our LinkedIn page