Blog · IT scandals · Security
700 GB of Argentine Federal Police data went public, including profiles of undercover officers. The case was closed with no one held responsible
On August 12, 2019, 700 GB of files from Argentina's Federal Police were published: raid reports, wiretaps, and profiles of undercover officers. In November 2021 the case was closed and all 15 suspects were cleared, among them a developer known for pointing out security flaws in government systems. The perpetrator was never identified.

What was published
The leak, called LaGorraLeaks 2.0 (“la gorra” is Argentine slang for the police), spread through GitHub, Telegram, Twitter, and the Deep Web. According to the Argentine news site Infobae, it included about 200 wiretap recordings, cell site data used to locate suspects, documents from the Drug Division, and profiles of 70 police officers with their phone numbers, home addresses, and names of family members.
The Federal Police said in a statement that its database had not been compromised and that the files were in the cloud, uploaded by outlying units.
How they got in and how the case ended
According to official documents from February 2020 cited by the Argentine outlet El Resaltador, access was gained through the email server of the Federal Police's Welfare Superintendency, which was running PHP 5.6.3, a version from November 2014.
The investigation charged 15 people, including that developer. A prosecutor questioned the grounds used to charge him, calling them assessments without scientific rigor. The authorities seized 23 devices that were never forensically examined. On November 17, 2021, the prosecutor asked for all 15 to be cleared, the judge approved the request on the 24th, and the decision became final on the 30th. Who was behind the leak was never established.
What's the general lesson?
Two things. First, the core system can be well protected and the leak can still come from an outdated secondary server, or from files that other units uploaded to the cloud. Second, looking for a culprit among people who publicly criticize security is no substitute for a technical analysis of the incident.