Paraguay Unveils New Cybersecurity Initiative After Major Data Breach

by Alicja Pawlowska

Paraguay’s government has rolled out a fresh cybersecurity framework just days after a criminal group made public the personal identification records of its citizens following an unsuccessful ransom negotiation.

The administration of President Santiago Peña confirmed it would not pay the $7.4 million demanded by the hacking collective known as Brigada Cyber PMC, which had gained access to sensitive citizenship data. When the deadline of June 13 was ignored, the group released the stolen documents online.

Local cybersecurity expert Luis Benítez warned that the leaked information could be combined with other records and social media activity to create detailed profiles of individuals, potentially enabling harmful activities.

“The situation leaves us completely exposed,” Benítez said, adding that the data’s reach extends far beyond simple identity theft, allowing for in-depth behavioral and psychological profiling.

The Ministry of Technology and Information has not commented on the breach or the new plan.

In a June 17 address, President Peña announced the national cybersecurity strategy, emphasizing that state institutions must treat digital data with the same care as physical assets. “The state should act as a shield, not a danger,” he stated.

However, Benítez remained skeptical about the government’s ability to address the underlying vulnerabilities. He pointed to a series of recent incidents, including a breach of Peña’s own X account and intrusions into several public agencies in May, such as the health, justice, and labor ministries.

Additionally, a joint investigation by Paraguayan and U.S. authorities in November identified the country as a target of Flax Typhoon, a cyber-espionage group linked to Chinese interests.

“State agencies lack the capacity to manage these threats,” Benítez concluded. “The cybersecurity problem runs deep and is not being tackled effectively.”