CiberinteligenciaSV is the alias used by a threat actor associated with the public release of a massive dataset containing personally identifiable information and biometric data of more than five million people in El Salvador. The actor advertised and distributed the stolen data on a cybercrime forum, exposing identity records and facial images at national scale. This activity is notable for the breadth of the compromise, affecting a substantial majority of the country’s population and creating significant downstream risk of identity theft, fraud, impersonation, and abuse of biometric data, including potential deepfake-enabled social engineering. The actor’s observed behavior is consistent with data theft and public dissemination of stolen information for criminal purposes. High-confidence reporting supports exfiltration of sensitive personal and biometric records and subsequent posting of the dataset to a breach marketplace forum. Publicly available information does not establish a confirmed nation-state affiliation, organizational structure, or broader campaign history beyond this leak. Attribution beyond the alias remains unconfirmed, and there is no high-confidence evidence in the available facts to support linkage to another named intrusion set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.