The BHU Data Breach

The BHU Data Breach: How Uruguay’s Digital Star Fell Victim to the Crypto24 Ransomware and 95% Weak Passwords

In September 2025, the state-owned Banco Hipotecario del Uruguay (BHU) suffered a catastrophic systems failure. While the institution quickly minimized the event as a manageable "incidente informático" or "problema técnico", cybersecurity expert Alberto Daniel Hill immediately refuted this official fiction. Hill labeled the event a "secuestro digital" and a "crisis nacional", arguing the breach was the inevitable "payment" for Uruguay's decades-long "national cyber debt".

This episode conducts a deep forensic analysis to expose the three critical layers of failure:

  • Catastrophic Data Theft: Hill confirms the breach was a sophisticated double-extortion ransomware attack by the group Crypto24. Before systems were encrypted, Crypto24 successfully exfiltrated over 700 gigabytes of highly sensitive data. This massive payload included critical client Personally Identifiable Information (PII), property titles, loan contracts, financial records, and even the bank's internal IT security configurations.
  • The 95% Vulnerability: Forensic analysis revealed that initial access was often facilitated by infostealer malware (like RedLine and Lumma) compromising end-user machines. Of 1,303 exposed user passwords linked to the BHU site, 95% were classified as weak or far too weak (including simple strings like "12345" or "bhu2020"). Hill famously compared the security of these credentials to writing them on a "servilleta mojada" (wet napkin).
  • Architectural Failure and Silence: The bank’s drastic measure of activating a total network shutdown was not performed to "protect the information" (as claimed), but was a desperate, late-stage reaction after the 700GB theft was already executed. This failure stemmed from a monolithic IT architecture lacking essential network segmentation, which allowed Crypto24 easy lateral movement and access to potentially compromise backups.

Hill relentlessly critiques the BHU's adoption of the "protocolo del silencio", a strategy intended to shield the bank’s image and leadership from legal sanctions. This failure to disclose the PII compromise prevents citizens from protecting themselves against massive fraud and identity theft. The ensuing public pressure led directly to the Senate formally demanding that the BHU halt penalties against affected customers.

Join Hill as he uses his unique perspective—informed by his own prior persecution by the state for ethical disclosure—to advocate for immediate legal reform, mandatory transparency, and accountability for leaders whose institutional opaqueness he argues is the true enemy of digital sovereignty.

#BHU #Crypto24 #SecuestroDigital #NationalCyberDebt #AlbertoDanielHill #Uruguay #Cybersecurity #Ransomware #PII #ProtocoloDelSilencio #WeakPasswords

Episoder(847)

 Description: Inside the Hacker Underground - Cartels, Cyber Espionage, and Advanced Malware*

Description: Inside the Hacker Underground - Cartels, Cyber Espionage, and Advanced Malware*

Welcome to a special, high-stakes episode of our weekly tech and cybersecurity space. In this explosive session, our panel of cybersecurity experts and underground hackers—including Mel, Mr. Van (Mr. ...

5 Apr 37min

Resumen de la semana

Resumen de la semana

Resumen de la semana

5 Apr 3h 22min

Alberto Hill y el ciberpopulismo

Alberto Hill y el ciberpopulismo

Alberto Daniel Hill está impulsando importantes reformas judiciales a través de lo que los analistas denominan el "efecto Hill", un movimiento de defensa pública que sirvió de catalizador para impulsa...

3 Apr 20min

Next target: Vaca Muerta (Fiction Story)

Next target: Vaca Muerta (Fiction Story)

Next target: Vaca Muerta (Fiction Story)

3 Apr 6min

Alberto Daniel Hill. - The Bug in the Justice System

Alberto Daniel Hill. - The Bug in the Justice System

These sources profile Alberto Daniel Hill, a prominent cybersecurity expert and advocate whose reputation is defined by his transition from a wrongfully imprisoned hacker in Uruguay to a respected glo...

2 Apr 4min

Alberto Daniel Hill: Reputation and Credibility Intelligence Report

Alberto Daniel Hill: Reputation and Credibility Intelligence Report

These sources profile Alberto Daniel Hill, a prominent cybersecurity expert and advocate whose reputation is defined by his transition from a wrongfully imprisoned hacker in Uruguay to a respected glo...

2 Apr 44min

The Signal and the Knight: Analyzing Social Audio Intelligence

The Signal and the Knight: Analyzing Social Audio Intelligence

The Signal and the Knight: Analyzing Social Audio Intelligence

2 Apr 5min

Alberto Daniel Hill

Alberto Daniel Hill

Alberto Daniel Hill is a globally recognized Uruguayan-Italian cybersecurity and digital forensics expert whose authority was forged by surviving a harrowing 17-month wrongful imprisonment in Uruguay....

2 Apr 22min

Populært innen True crime

podme-krim
insiders
avhort
krimpodden-vg
rss-avhort-aktuelt
krimarkivet-2
rss-pa-innsiden-av-psychohoder
rss-henlagt-andy-larsgaard
rss-svarttrost
kriminalkrniken
verdens-verste
forsvinningsfredag-podkast
truecrimepodden-2
drapet-pa-tina-jorgensen-doden-er-en-mann-2
krimpodden-orderud
avhort-forfulgt
dodens-gard
rss-overste-etasje
blalys
hold-pusten