Cybermidnight Club– Hackers, Cyber Security and Cyber Crime

← Cybermidnight Club– Hackers, Cyber Security and Cyber Crimeeergisteren · 5 min

Uruguay BHU Data Breach: Opacity and Digital Crisis

Uruguay BHU Data Breach: Opacity and Digital Crisiseergisteren5 min

<p></p><p><strong>Can state bank executives enforce a 15-year secrecy decree over your unencrypted health records leaked on the dark web?</strong></p><p>In this video podcast forensic briefing, independent cybersecurity researcher <strong>Alberto Daniel Hill</strong> breaks down the most critical and alarming revelation inside the <strong>700 GB Crypto24 ransomware data dump</strong> at <strong>Banco Hipotecario del Uruguay (BHU)</strong>: the exfiltration of sensitive medical files, physical fitness clearance certificates, and health assessments belonging to members of <strong>Club Banco Hipotecario (CBH)</strong>—stored completely unencrypted across open bank network shares (\\Server\Comun\...).</p><p>We examine the fundamental collision between institutional opacity, state secrecy decrees, and fundamental human rights to personal data protection under <strong>Uruguay’s Law N° 18.331</strong> and <strong>EU GDPR Article 9</strong>.</p><ul><li><strong>00:00</strong> <strong>— The 700 GB Ransomware Dump:</strong> How Crypto24 breached BHU and exposed sensitive citizen data.</li><li><strong>02:15</strong> <strong>— The Exfiltrated Medical Records:</strong> Discovering unencrypted Club BHU fitness and health files inside public network shares.</li><li><strong>05:40</strong> <strong>— Secrecy Decrees vs. Citizen Rights:</strong> Can state officials use a 15-year confidentiality resolution to hide data breaches affecting personal health information?</li><li><strong>09:10</strong> <strong>— The 5-Day Statutory Clock:</strong> Serving formal Article 14 data access demands on BHU and Club BHU.</li><li><strong>12:30</strong> <strong>— Connection Refused (SMTP 550):</strong> How the regulatory complaint sent to the Data Protection Authority (URCDP/AGESIC) bounced back, legally establishing administrative obstruction (<em>denegatoria ficta</em>).</li><li><strong>15:45</strong> <strong>— Transnational Escalation:</strong> Filing a constitutional complaint before the <strong>INDDHH</strong> and a <em>Segnalazione ex Art. 144</em> before the <strong>Garante Privacy in Rome</strong>, threatening Uruguay&#39;s EU Data Adequacy status.</li></ul><ul><li><strong>Data Breach Severity:</strong> Plaintext passwords, unsegmented file shares, and massive exfiltration of mortgage, salary, and medical records.</li><li><strong>Constitutional Rights:</strong> Self-determination of information (<em>Habeas Data</em>) vs. board-level administrative secrecy.</li><li><strong>Internationa