If you live in Costa Rica, some of your personal information may be circulating on the dark web. Authorities have not confirmed how much data is out there or where it came from, but they say part of what has been published is real. That means now is a good time to be extra careful with calls, texts and emails, and to lock down your online accounts.
On Saturday, Sept. 12, the national cybersecurity office at the Ministry of Science, Innovation, Technology and Telecommunications (MICITT) spotted a post on a dark web forum. In it, an anonymous seller claimed to have hacked a credit-reporting agency and obtained a database on people in Costa Rica.
The seller claims to have more than 400 million lines of data. According to the post, that includes salaries, home addresses, phone numbers, email addresses, photos, vehicle records and court records. The seller also claims the files cover the entire population, including foreigners.
None of those claims has been verified. Keep that in mind as you read. Here is what is confirmed. Gezer Molina, MICITT’s director of cybersecurity, said his team is reviewing a sample of about 10,000 lines that the seller released, and that part of that sample contains real information about real people.
What is not confirmed is just as important. MICITT has not said which company or institution the data came from. It has not confirmed that the files come from a single database, that the leak is recent, or that it affects everyone in the country.
Some early reports linked the data to the Central Bank’s registry of company beneficial owners. The Central Bank of Costa Rica said Monday that it found no breach of that registry or any of its other systems, and that its technology infrastructure remains secure.
MICITT is working with the Prosecutor’s Office, the Judicial Investigation Agency (OIJ), the national data protection agency PRODHAB and the Intelligence and Security Directorate. Molina said authorities are also in contact with officials in the Dominican Republic, where the same seller has been linked to another incident.
Why should this worry you if nothing has happened to your bank account? Because criminals rarely use stolen data right away. They use it to make scams more convincing. A scammer who already knows your full name, ID number, address and employer can sound exactly like your bank, your phone company or a government office. Molina warned that the exposed information could be used for fraud, identity theft, extortion and phishing.
Here is what you can do today:
- Distrust unexpected messages. Treat any call, text, WhatsApp or email you did not expect as suspicious, even if the sender knows personal details about you.
- Don’t click unknown links or open unexpected attachments. Go to your bank’s website or app directly instead.
- Never share codes or passwords. Your bank will not ask you for a one-time code, PIN or password by phone or message. If someone does, hang up.
- Turn on two-step verification. Add multifactor authentication to your email, banking, WhatsApp and social media accounts. It stops most account takeovers even when a password is stolen.
- Watch your accounts. Turn on transaction alerts in your banking app and check your statements for charges you don’t recognize.
- Call back on a number you trust. If a caller says they are from your bank or a government office, hang up and call the official number yourself.
If you think you have already been targeted, contact your bank immediately and file a report with the OIJ. MICITT said the case remains under investigation and that it will release more information once the data has been properly verified. Until then, the safest assumption is that basic personal details can be used against you, and that a little extra caution goes a long way.





