Blog · IT scandals · Personal data

Using another ministry's credentials, they pulled data from Renaper and asked $17,000 for a database they claimed held 45 million records

In October 2021, the national ID photos of 44 public figures were posted online, followed by a file with data on 60,000 people, and the attacker asked for about $17,000 for the full database. Renaper, Argentina's national registry of persons, attributed the access to credentials assigned to the Ministry of Health, which made between 600,000 and 800,000 queries a day, and denied a mass download. According to experts quoted in the press, there was no query limit in place to stop anyone.

Argentina's 2020 national ID card design (sample specimen)
Argentina's 2020 national ID card design (sample specimen). Cropped to 16:9. Photo: Gobierno de la República Argentina · CC BY 4.0 · Wikimedia Commons

What happened

On October 9, the ID photos of 44 public figures, including the president, appeared on Twitter. The next day, on a cybercrime forum, the same user posted a JSON file with about 60,000 entries as proof. The user claimed to have 45,387,114 records and asked for 0.29 bitcoin for the full database, close to $17,000 at the exchange rate at the time, according to the Argentine newspaper Clarín.

The government explained that the access was made with a username and password over an authorized VPN connection between Renaper and the Ministry of Health, used by the SISA health system to load COVID-19 and vaccination data. Renaper's security team found that 19 of the 44 photos had been queried at the same moment they were being posted on Twitter. It blocked the Health Ministry's access and denied a mass download: its theory was a piecemeal theft made up of many small queries.

Why did no one stop it?

A programmer interviewed by Infobae argued that the system should raise an alert when faced with an excessive number of accesses, and that it had no control limiting requests per minute, hour, or day. Another expert pointed out that the ID numbers in the sample were consecutive, which suggests a sequential download rather than a piecemeal theft.

The underlying problem is common: a system-to-system credential with a huge legitimate volume hides misuse well. If a client system makes 700,000 queries a day, a few thousand more don't stand out unless someone looks at the pattern. After the incident, Renaper announced it would cut queries with those credentials to a minimum, review unusual usage, and limit the information shared to what is strictly necessary.

Sources

  1. Infobae, 10/31/2021
  2. Clarín

Consulting: AWS architecture review →

← Back to the blog