Cybermidnight Club– Hackers, Cyber Security and Cyber Crime podcast

Uruguay BHU Data Breach: Opacity and Digital Crisis

0:00
5:29
15 Sekunden vorwärts
15 Sekunden vorwärts

Can state bank executives enforce a 15-year secrecy decree over your unencrypted health records leaked on the dark web?

In this video podcast forensic briefing, independent cybersecurity researcher Alberto Daniel Hill breaks down the most critical and alarming revelation inside the 700 GB Crypto24 ransomware data dump at Banco Hipotecario del Uruguay (BHU): the exfiltration of sensitive medical files, physical fitness clearance certificates, and health assessments belonging to members of Club Banco Hipotecario (CBH)—stored completely unencrypted across open bank network shares (\\Server\Comun\...).

We examine the fundamental collision between institutional opacity, state secrecy decrees, and fundamental human rights to personal data protection under Uruguay’s Law N° 18.331 and EU GDPR Article 9.

  • 00:00 — The 700 GB Ransomware Dump: How Crypto24 breached BHU and exposed sensitive citizen data.
  • 02:15 — The Exfiltrated Medical Records: Discovering unencrypted Club BHU fitness and health files inside public network shares.
  • 05:40 — Secrecy Decrees vs. Citizen Rights: Can state officials use a 15-year confidentiality resolution to hide data breaches affecting personal health information?
  • 09:10 — The 5-Day Statutory Clock: Serving formal Article 14 data access demands on BHU and Club BHU.
  • 12:30 — Connection Refused (SMTP 550): How the regulatory complaint sent to the Data Protection Authority (URCDP/AGESIC) bounced back, legally establishing administrative obstruction (denegatoria ficta).
  • 15:45 — Transnational Escalation: Filing a constitutional complaint before the INDDHH and a Segnalazione ex Art. 144 before the Garante Privacy in Rome, threatening Uruguay's EU Data Adequacy status.
  • Data Breach Severity: Plaintext passwords, unsegmented file shares, and massive exfiltration of mortgage, salary, and medical records.
  • Constitutional Rights: Self-determination of information (Habeas Data) vs. board-level administrative secrecy.
  • International Impact: Challenging Uruguay's EU Data Adequacy status under EU Decision 2012/484/EU due to structural regulatory dependency between AGESIC and URCDP.
  • Host & Lead Analyst: Alberto Daniel Hill
  • PGP Key ID: 0xA1406A6E117EF283
  • Fingerprint: 6B33 A7C8 E94B 8D9C 4E54 03DE A140 6A6E 117E F283
  • Public Record: All legal filings and forensic proofs are PGP-signed and cryptographically verified on public archives.

#DataBreach #CyberSecurity #BHU #Privacy #HumanRights #GDPR #HabeasData #RadicalTransparency #Uruguay #Whistleblower

📌 Key Highlights & Timestamps🛡️ Legal & Regulatory Breakdown🔑 Cryptographic Verification & PGP Records

Weitere Episoden von „Cybermidnight Club– Hackers, Cyber Security and Cyber Crime“