
← Cybermidnight Club– Hackers, Cyber Security and Cyber Crimeeergisteren · 12 min
Uruguay BHU Data Breach: Opacity and Digital CrisisUruguay BHU Data Breach: Opacity and Digital Crisis
<p></p><p><strong>Can state bank executives enforce a 15-year secrecy decree over your sensitive health records leaked on the dark web?</strong></p><p>In this video podcast briefing, we analyze the critical revelation inside the <strong>700 GB Crypto24 ransomware data dump at Banco Hipotecario del Uruguay (BHU)</strong>: unencrypted health assessments, medical clearance files, and physical fitness certificates from <strong>Club Banco Hipotecario (CBH)</strong> sitting exposed on open bank network shares (\\Server\Comun\...).</p><ul><li>🏋️ <strong>Exposed Health Records:</strong> How routine sports club medical files were exfiltrated alongside mortgages, property titles, and payrolls.</li><li>🛡️ <strong>Secrecy Decrees vs. Human Rights:</strong> Why state secrecy resolutions cannot override statutory privacy guarantees under Law N° 18.331 and GDPR Article 9.</li><li>⏱️ <strong>The 5-Day Statutory Clock:</strong> Serving formal Article 14 data access demands to BHU and Club BHU.</li><li>🚫 <strong>Connection Refused (SMTP 550):</strong> The official regulatory complaint to URCDP/AGESIC bouncing back, establishing technical obstruction and administrative bad faith (<em>denegatoria ficta</em>).</li><li>🇮🇹 <strong>Rome & Transnational Escalation:</strong> Filing a formal complaint before Italy’s <em>Garante Privacy</em> (Art. 144) and the Italian Embassy, threatening Uruguay's EU Data Adequacy status.</li></ul><ul><li>00:00 — Introducción: La brecha de 700 GB y el hallazgo en el Club BHU</li><li>02:15 — Datos sensibles de salud expuestos en carpetas compartidas</li><li>05:40 — ¿Tienen jerarcas bancarios la potestad de ocultar tu información médica?</li><li>09:10 — Intimaciones de 5 días hábiles al BHU y CBH</li><li>12:30 — El servidor rebotado: Error SMTP 550 en la URCDP (AGESIC)</li><li>15:45 — Escalada a Roma (Garante Privacy) e intervención de la INDDHH</li></ul><ul><li><strong>Investigación & Conducción:</strong> Alberto Daniel Hill</li><li><strong>PGP Key ID:</strong> 0xA1406A6E117EF283</li><li><strong>Fingerprint:</strong> 6B33 A7C8 E94B 8D9C 4E54 03DE A140 6A6E 117E F283</li></ul><p>#CasoBHU #Ciberseguridad #DatosSensibles #DerechosDigitales #Uruguay #GDPR #HabeasData #TransparenciaYa</p><p>📌 <strong>Episode Highlights:</strong>⏱️ <strong>Marcas de Tiempo (Timestamps)</strong>🔑 <strong>Firma PGP & Registro Público</strong></p>