
Weaponizing Gym Records Against State Secrets (The BHU Cyber Crisis) Banco Hipotecario del Uruguay data breach by Crypto24
Episode Summary: When state bank executives classified all technical details of a catastrophic 700 GB ransomware breach under a 15-year confidentiality decree, they assumed the narrative was sealed until 2041. They didn't count on the exfiltrated files containing something they couldn't legally classify: sensitive health and medical records from the bank's sports club, Club BHU.
This episode traces the exact mechanics of a legal and forensic pincer strategy—turning unencrypted sports club fitness files into a high-leverage tool to dismantle institutional opacity across Montevideo, Rome, and Brussels.
Key Timestamps / Topics Covered:
- 00:00 — Introduction: The Anatomy of a 700 GB State Bank Leak
- 03:15 — The Discovery: Medical & Fitness Files inside \\Server\Comun\...
- 08:30 — Legal Analysis: Law 18.331, GDPR Art. 9, and the 15-Year Secrecy Decree
- 14:20 — Serving the 5-Day Statutory Clock on BHU & Club BHU
- 19:45 — The SMTP 550 Bounce: When the Data Protection Authority Shuts its Doors
- 25:10 — The Rome Pincer: Filing Segnalazione ex Art. 144 with the Italian Garante
- 31:00 — Why Uruguay's $2.2B Tech Export Industry is Now on the Line
- 36:30 — Conclusion & What Happens When the 5-Day Deadline Hits Zero
Documentation & Public Records:
- PGP Key ID: 0xA1406A6E117EF283
- Fingerprint: 6B33 A7C8 E94B 8D9C 4E54 03DE A140 6A6E 117E F283
- Hashes & Archives: All filings PGP-signed and verified on the public record.
D'autres épisodes de "Cybermidnight Club– Hackers, Cyber Security and Cyber Crime"



Ne ratez aucun épisode de “Cybermidnight Club– Hackers, Cyber Security and Cyber Crime” et abonnez-vous gratuitement à ce podcast dans l'application GetPodcast.








