Costa Rica’s Agency for the Protection of Inhabitants’ Data (Prodhab) has opened its own investigation into an alleged mass leak of personal data on people in Costa Rica. It is the third public body to formally examine the case, which came to light a week ago. Prodhab opened case file No. 425-09-2026 on its own initiative and formally requested information to clarify what happened. The agency will examine whether there were failures in how personal information was handled.
Its inquiry runs alongside those already under way at the Ministry of Science, Innovation, Technology and Telecommunications (Micitt) and the Public Prosecutor’s Office. The case began on Saturday, Sept. 12, when Micitt’s National Cybersecurity Directorate detected a dark web post from a threat actor claiming to have breached a credit reporting agency. The actor claims to hold more than 400 million lines of data on people in Costa Rica.
According to the actor’s claims, the records include information on the beneficial owners of companies, salaries, home addresses, phone numbers, email addresses, photographs, vehicles, and judicial and marriage records. The actor also claimed to have information on President Laura Fernández.
Micitt has confirmed that a sample of about 10,000 lines released by the actor contains real data. Gezer Molina, the national director of cybersecurity, said the investigation seeks to determine whether a breach actually occurred, when it happened and which system was affected.
Investigators are also trying to establish whether the information comes from a single source or is a compilation of databases obtained earlier. Authorities have not publicly identified the entity the files may have come from. Officials have stressed that the appearance of a database on the dark web does not by itself prove the information is authentic, recent or the product of a single breach.
Micitt said it is coordinating with the Public Prosecutor’s Office, the Judicial Investigation Agency (OIJ), Prodhab and the Directorate of Intelligence and Security (DIS). Molina said authorities are also in contact with counterparts in the Dominican Republic, where the actor has been linked to another incident.
A few days ago, the Public Prosecutor’s Office said its Cybercrime Prosecutor’s Unit had opened an investigation on its own initiative. The investigation will determine whether the crime of violation of personal data was committed. No suspects have been publicly identified. The Central Bank of Costa Rica (BCCR) has denied that data in its systems was affected.
The bank issued the statement after reports suggested the leaked information could have come from the Registry of Transparency and Beneficial Owners (RTBF), which the BCCR administers. The RTBF holds ownership information on corporations and other legal entities registered in Costa Rica, including the individuals who ultimately control them.
Micitt has warned that the exposed information could be used for fraud, identity theft, extortion or phishing attacks. The ministry recommends that people distrust unexpected messages, avoid opening suspicious links or attachments, refuse to share personal information and turn on multifactor authentication for their online accounts.
Cybersecurity expert Esteban Jiménez has warned that the leak could lead to a rise in fraud in the coming months. Real details such as names, addresses and phone numbers can make fraudulent calls and messages far more convincing. The case is the latest in a series of cyber incidents in Costa Rica. In 2022, a ransomware attack on the Finance Ministry and other public institutions paralyzed key digital services, including tax and customs systems.
In March of this year, the Costa Rican Electricity Institute (ICE) reported that part of its systems had been breached and 9 GB of emails taken. Investigators have not said how many people may be affected or when they expect to release their findings.





