Trending

ee-track">
HomeBlog
Old Records with NIDs Resurface – 42 Million Mexico Residents Hit

Old Records with NIDs Resurface – 42 Million Mexico Residents Hit

The wave of data breaches is on the rise as hackers are highly motivated to steal sensitive data for financial gains. This is compounded by the fact that personal information is a highly valued data. 

Recently, the Research Team at Cyble found a post on one of the cybercrime forums in which the threat actor claimed to be in possession of 42 million records of residents of Mexico along with their National Identification Numbers (NIDs). 

Below is an image of the post from the forum. The threat actor has also shared a sample to display the authenticity of the data. 

image 30

The dataset is about 6.14GB in size, containing 128 .mdb files in total.  The files are dated between 2009 to 2011, as shown in the screenshot below. 

image 28
image 27

Below is a screenshot of extracts from one of the files. It contains NIDs, identified as CURP in Mexico. CURP is a Unique Population Registry Code for citizens and residents of Mexico, and each CURP is a unique alphanumeric 18-character string. 

image 31

Cyble researchers also found a blog on another forum with the same database for sale. We suspect that threat actors acquire such data from multiple sources and share it on cybercrime forums to build a reputation for their profiles. 

report-ad-banner
Text

Description automatically generated

Cyble has been reporting these types of breaches to spread awareness of the risks associated with using online services. Recently, during our routine Dark web monitoring, we came across a post in the cybercrime market in which a threat actor claimed to be in possession of more than 220k+ unique records of Jammu and Kashmir residents. The rising number of such data leaks not only reaffirms the need for updated cybersecurity measures but also underlines the importance of handling sensitive consumer data responsibly. 

Data leaks such as these can foster criminal activities and play a pivotal role in various malpractices such as phishing attacks, credential stuffing, financial fraud, and social engineering campaigns. 

We recommend people to: 

  • Never share personal information, including financial information over the phone, email, or SMSes.  
  • Use strong passwords and enforce multi-factor authentication wherever possible.  
  • Regularly monitor your financial transactions, and if you notice any suspicious activity, contact your bank immediately.  
  • Turn on the automatic software update feature on your computer, mobile, and other connected devices wherever possible and pragmatic.  
  • Use a reputed anti-virus and Internet security software package on your connected devices, including PC, laptop, and mobile.  
  • People who are concerned about their exposure in the Darkweb can register at AmiBreached.com to ascertain their exposure.  
  • Refrain from opening untrusted links and email attachments without verifying their authenticity.   

About Cyble 

Cyble is a global threat intelligence SaaS provider that helps enterprises protect themselves from cybercrimes and exposure in the darkweb. Cyble’s prime focus is to provide organizations with real-time visibility into their digital risk footprint. Backed by Y Combinator as part of the 2021 winter cohort, Cyble has also been recognized by Forbes as one of the top 20 Best Cybersecurity Startups To Watch In 2020. Headquartered in Alpharetta, Georgia, and with offices in Australia, Singapore, and India, Cyble has a global presence. To learn more about Cyble, visit www.cyble.com

Disclaimer: This blog is based on our research and the information available at the time of writing. It is for informational purposes only and does not constitute legal, financial, or professional advice. While we strive for accuracy, we do not guarantee the completeness or reliability of the content. If any sensitive information has been inadvertently included, please contact us for correction. Cyble is not responsible for any errors, omissions, or decisions made based on this content. Readers should verify findings and seek expert advice where necessary. All trademarks, logos, and third-party content belong to their respective owners and do not imply endorsement or affiliation. All content is presented “as is” without any guarantee that it is free of confidential, proprietary, or otherwise sensitive information. If you believe any portion of this content contains inadvertently shared or sensitive data, please contact us immediately so that we may address and rectify the issue. No Liability for Errors or Omissions Due to the dynamic nature of cyber threat activity, this [blog/report/article] may include partial, outdated, or otherwise incorrect information due to unverified sources, evolving security threats, or human error. We expressly disclaim any liability for errors or omissions or any potential consequences arising from the use, misuse, or reliance on this information.

Get Threat Assessment Report

Identify External Threats Targeting Your Business​
Free
CISO's Guide to Threat Intelligence 2024

CISO’s Guide to Threat Intelligence 2024: Best Practices

Stay Ahead of Cyber Threats with Expert Insights and Strategies. Download Free E-Book Now

Stay informed

Subscribe to Cyble

Get the latest threat intelligence, research, and security updates straight to your inbox.

Cyble protects your personal data to manage your account and deliver requested content. Submit your details to receive updates. Withdraw consent anytime. See our privacy policy for details.

Share the Post:
Scroll to Top

Book your session

Request a Personalized Demo

See how Cyble's threat intelligence protects your organization. A specialist will reach out within one business day.

Select one or more options

Cyble protects your personal data to manage your account and deliver requested content. Submit your details to receive updates. Withdraw consent anytime. See our privacy policy for details.

Your information is encrypted and never shared.
SOC 2 Type II GDPR compliant Trusted by 1,000+ teams

Download the brochure

Get the Cyble Vision Brochure

Explore how Cyble Vision delivers AI-powered threat intelligence across your attack surface. Fill in your details to access the brochure.

Select one or more options

Cyble protects your personal data to manage your account and deliver requested content. Submit your details to receive updates. Withdraw consent anytime. See our privacy policy for details.

Your information is encrypted and never shared.
SOC 2 Type II GDPR compliant Trusted by 1,000+ teams