La Pampa Leaks is a suspected Latin American cybercriminal actor associated with claimed compromises of Uruguayan public-sector and citizen-data systems. The actor has been observed publicly alleging theft of large government-linked datasets and monetizing the purported data through sale offers and lookup-style access services, indicating an extortion- and data-theft-oriented operating model rather than confirmed ransomware encryption activity. Reported claims tied to the actor include alleged access to Uruguay's CEIP GURI student management platform and a government-sponsored identity service managed by Antel, with both incidents centered on sensitive citizen information. The actor's apparent targeting emphasizes government and public administration systems, especially repositories containing identity, education, and other citizen records. In the reported Uruguay cases, the actor claimed possession of large databases relating to school enrollment histories and identity-service data, and advertised paid access to query that information. This behavior is consistent with exfiltration-led monetization and data-theft extortion patterns in which the value of the intrusion derives from the sensitivity and scale of stolen records. High-confidence attribution beyond the actor name is currently not available. The reported breach claims associated with La Pampa Leaks were described as unverified, and at least one affected organization publicly downplayed the impact. As a result, operational details should be treated cautiously. Based on the available facts, the strongest supported assessment is that La Pampa Leaks is a threat actor name used in connection with alleged compromises of Uruguayan government-linked data systems and attempted monetization of purportedly stolen citizen data.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed breach actor allegedly offering Uruguay primary education databases for sale and via a subscription query service, exposing sensitive student and family records.
Latin American cybercriminal group claiming compromise of Uruguay's government-sponsored identity service and monetizing stolen citizen data; discussed as part of a regional trend of extortion and data-exfiltration-focused attacks against government entities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.