⚠️ PREVENTIVE ALERT 🇨🇱 🏛️: ALLEGED EXFILTRATION FROM THE PEÑALOLÉN MUNICIPALITY DATABASE, CHILE (ACTOR: TUIYIN)
[STATUS: ALLEGED / UNCONFIRMED / THREAT ACTOR: TUIYIN / DATE: OCTOBER 7, 2026]
The centralized cyber-intelligence system has detected a post on underground Chinese-language channels. The report details the alleged exfiltration of the user database belonging to the Municipality of Peñalolén (Peñalolén, Chile).
It is strictly noted that the veracity of this compromise and the authenticity of the records have not been officially confirmed by Chilean municipal authorities. The definitive status of the infrastructure remains unconfirmed.
Threat Actor / Source: tuiyin.
Victim / Affected Entity: Municipality of Peñalolén (Citizen user portal).
Sector: 🏛️ Local Government, Municipal Administration, and Public Services in Chile 🇨🇱.
Reported Data Volume: A total of 394,486 records, including:
349,750 unique RUTs (358,713 valid lines).
257,124 unique email addresses (349,643 lines).
258,935 unique mobile phone numbers (309,522 valid lines).
🔍 TECHNICAL BREAKDOWN OF THE EXPOSED DATA STRUCTURE
User identifiers: ID, customer number, username, and document type.
Identity and personal details: Chilean RUT, first names, paternal surname, maternal surname, nationality, date of birth, and gender. Contact information and credentials: Email address, email status, phone numbers, hashed passwords, permissions, activation status, registration and update dates, and session/API metadata.
🛡️ TECHNICAL PREVENTIVE CONTAINMENT RECOMMENDATIONS (SOC / CSIRT / MUNICIPALITY)
Municipal Portal Audit and Forensic Analysis: The municipality's technical teams must immediately review access logs and citizen portal databases to determine the source of the data extraction.
🖥️ CENTRALIZED THREAT MONITORING SYSTEM
Intelligence System:
analyzer.vecert.io
Quickly check your security at:
monitor.vecert.io
Quotes and services:
vecert.io/contact
#Cybersecurity #ThreatIntel #Penalolen #Chile #Municipality #DataLeak #PII #InfoSec #CyberAlert #VECERT #SOC #CSIRT #Unconfirmed #SecurityAlert