The Ministerio de Ciencia, Innovación, Tecnología y Telecomunicaciones (Micitt)—Ministry of Science, Innovation, Technology, and Telecommunications—has launched an investigation into an alleged massive data leak of a Costa Rican credit reporting agency.
The discovery involves Costa Rican citizens and follows a dark web post in which a threat actor claims to have obtained an extensive database containing personal, financial, employment, and other types of information.
According to Gezer Molina Colomer, the director of the Dirección Nacional de Ciberseguridad (DNC)—National Cybersecurity Directorate—the issue was identified over the weekend.
Based on claims made by threat actor “jarol1488” in DarkForums, the alleged database reportedly contains over 400 million records—including salaries, addresses, phone numbers, email addresses, photographs, and other personal data.

However, authorities emphasized that it is not yet possible to confirm the authenticity or the full scope of the leaked information.
Threat actor has confirmed that data leak originates from a vulnerable database belonging to credit protection company “Cero Riesgo” through its official Telegram channel. In potentially the most serious data leak targeting civilian PII in the history of Costa Rica.
Specialists from the DNC are currently analyzing a sample of approximately 10,000 data entries released by the threat actor. Preliminary analysis has confirmed that some of the included data is indeed genuine, although the results do not allow for the conclusion that the entire advertised file is legitimate.
What is the dark web?
The dark web is a part of the internet that is not indexed by traditional search engines like Google and requires specific tools or networks to access. These systems are designed to provide a higher level of anonymity for both site administrators and visitors.

The use of the dark web is not necessarily illegal; it can also serve to protect communications, preserve the anonymity of journalistic sources, or enable access to information in contexts of censorship. However, that same level of anonymity has facilitated the creation of forums and marketplaces used to offer stolen databases, access credentials, personal information, cybercrime tools, and other illicit content.
In this instance, the post investigated by Micitt appeared in one of those spaces and was attributed to a user claiming to possess information on individuals in Costa Rica.
Authorities emphasize that the mere fact that a database is advertised on the dark web does not prove that the information is authentic, recent, or the result of a single breach. Precisely for this reason, the technical analysis aims to determine the origin of the files and how much of the advertised material can be verified.
Central Bank denies a breach
The emergence of the alleged database also sparked speculation linking some of the information to the Registro de Transparencia y Beneficiarios Finales (RTBF)—Transparency and Ultimate Beneficial Owners Registry, managed by the Banco Central de Costa Rica (BCCR)—Central Bank.
The institution denied the existence of any evidence of a breach.
The Central Bank stated that it has not identified any security incidents or unauthorized access regarding the RTBF or any of its other computer systems.

