Costa Rica Probes Alleged 400 Million Record Leak From Credit Agency Cero Riesgo on Dark Web

Costa Rica's government has launched an investigation into one of the most serious alleged data leaks in the country's history, after a threat actor claimed on a dark web forum to possess a database of more than 400 million records tied to Costa Rican citizens, drawn from a credit protection company whose business is selling exactly that kind of information.
The Ministry of Science, Innovation, Technology and Telecommunications, known as Micitt, opened the probe after a user identified as jarol1488 posted the offering on DarkForums, claiming the file contains personal, financial, employment and other data. According to Gezer Molina Colomer, director of the National Cybersecurity Directorate, the issue was identified over the weekend.
## What The Leak Is Claimed To Contain
Based on the threat actor's claims, the alleged database includes more than 400 million records covering salaries, addresses, phone numbers, email addresses, photographs and other personal data. The company at the center of the claim is Cero Riesgo, which sells financial institutions and businesses the personal information of people across Costa Rica, including salaries, emails, addresses, phone numbers and marital status.
The threat actor has since confirmed through an official Telegram channel that the data originates from a vulnerable database belonging to Cero Riesgo, describing it as potentially the most serious leak targeting civilian personal information in Costa Rica's history.
Authorities have been careful about what they will confirm. Specialists from the cybersecurity directorate are analyzing a sample of approximately 10,000 entries released by the actor, and preliminary analysis has confirmed that some of the included data is genuine, though the results do not allow the conclusion that the entire advertised file is legitimate.
## The Central Bank Pushes Back
The leak's emergence also drew speculation that some of the information might be connected to the Transparency and Ultimate Beneficial Owners Registry, managed by the Central Bank of Costa Rica. The institution denied any compromise.
The Central Bank stated it has not identified any security incidents or unauthorized access involving the registry or any of its other computer systems, effectively ruling out its systems as the source.
## A Country Tested Before, A Question Of Scale
Costa Rica knows the cost of cyberattacks against state institutions, having weathered ransomware campaigns that disrupted government operations in recent years. But this alleged leak targets something different: the private personal data of ordinary citizens held by a commercial broker, and at a claimed scale of 400 million records in a country of roughly five million people, the numbers imply heavy duplication, historical data, or records covering foreign individuals as well.
That gap between claim and verifiable reality is now the government's central task. Advertising a database on the dark web proves nothing about its authenticity, recency or provenance, which is precisely why the technical analysis is focused on establishing how much of the advertised material is real and where it came from.
For Costa Ricans, the practical advice is unchanged in principle but urgent in tone: assume personal data is exposed, treat unexpected calls, emails and messages referencing personal details as potential scams, and monitor financial accounts closely. For the country's regulators, the episode raises the question of what obligations a company that monetizes the personal information of an entire nation owes to the people inside its files, and what a 400 million record headline will mean if even a fraction of it proves real.
## What We Know Versus What Is Claimed
The distinction between claim and evidence is the story's spine. The threat actor's advertisement is a marketing pitch aimed at buyers of stolen data, and such listings routinely inflate scale and mix multiple sources to raise perceived value. What the government has independently established is narrower but significant: a sample of about 10,000 entries has been examined, and within that sample some records are confirmed genuine. That is enough to treat the leak as a real incident rather than a hoax, but not enough to state that 400 million authentic records are in circulation.
The company's silence compounds the uncertainty. Cero Riesgo's entire commercial value rests on being a trusted steward of personal data, and a confirmed breach of its systems would damage not just its own business but the financial institutions that rely on its files for credit decisions. Whether it has verified the exposure internally, and what it has told regulators, are the disclosures to watch next.
## The Wider Stakes
The incident also arrives as Costa Rica positions itself as a regional technology hub, with government digital services expanding and international tech investment growing. A leak of this scale, if confirmed, would sharpen debates over data protection legislation and the powers of the cybersecurity directorate that Molina Colomer leads.
For now, the government's message balances urgency with caution: the investigation is open, some of the data is real, the full scope is unknown, and citizens should protect themselves on the assumption that at least some of their information is among the records for sale.
Discussion
Recommended for you
More technology
Cybersecurity
Hackers Impersonate Italian Law Enforcement to Extort Revolut Over 680 Customers
9/17/2026
Cybersecurity
CenterPoint Energy Confirms Customer Data Stolen as Hacker Claims 7.49 Million Records in Utility Breach
9/17/2026
Cybersecurity
Hackers Exploit VPN Flaw to Breach Japan's Digital Agency and Access 240,000 People's Data
9/16/2026
Cybersecurity