-
A threat actor called GordonFreeman claims to have 48 million RENAPER records in a 15.7GB database.
-
The alleged data includes DNI numbers, names, birth dates, phone numbers and detailed home addresses.
-
The claim is not confirmed by RENAPER, and the material could be old data, an aggregation, or a new breach.
Argentina’s national identity registry is at the center of a new alleged data leak. A cybercriminal claims to have obtained 48 million records from the country’s Registro Nacional de las Personas, or RENAPER.
The listing appeared on August 10 and reportedly includes a free sample of one million records. The full database is allegedly 15.7GB in size.
It’s worth noting that these claims remain unverified. No public confirmation from RENAPER as of August 11.
The Alleged Database Contains Detailed Personal Data
The seller, using the name GordonFreeman, claims the database contains records from Argentina’s national identity registry.
The alleged fields are highly sensitive. They reportedly include DNI numbers, full names, dates of birth, phone numbers, municipalities and provinces. The records also reportedly contain street addresses, floor numbers and apartment numbers.
This type of detailed motor registry and identity database exposure is not unique to Argentina, a separate cybercrime forum user recently published an alleged Iranian motorcycle registry database containing over 600,000 records with similar personal and vehicle-specific information.
That level of detail would make the alleged database more than a simple list of names. It could provide a detailed map of where specific people live. The report also says children appear in the sample. However, the sample should not be treated as proof that the entire 48 million-record database is genuine.
The alleged database does not appear to include photographs or biometric records. RENAPER does hold biometric information used for identity checks. Argentina’s official identity system supports facial recognition and fingerprint-based validation.
The 48 Million Figure Raises Questions
The fact that the supposed number of compromised records exceeds Argentina’s population is particularly significant. Argentina’s National Statistics Institute, INDEC, data shows that as of July 1, 2026, the country had approximately 46.47 million people.
But that alone doesn’t make the claim untrue. A national identity registry can contain records for people who have died, changed status or no longer live in the country. It can also contain historical records and entries for foreign residents.
Still, the gap makes it impossible to assume that the alleged file represents 48 million current residents. It also raises another possibility. The material could contain records gathered from several sources rather than being a direct copy of the current RENAPER database. At this stage, there is no public evidence that settles that question.
RENAPER has Suffered Data Incidents Before
The claim is especially serious because RENAPER has faced major data security incidents in the past.
In 2021, Argentina’s government confirmed that someone misused credentials belonging to a public agency to query RENAPER data. The government said the activity involved an authorized connection between RENAPER and the Ministry of Health.
According to RENAPER, the account was used to make individual queries that returned information from identity records. The agency said its investigation found no unauthorized entry into the core system at that time. In addition, it reported a criminal complaint.
The problem arose again in 2024 after over 116,000 images of identity documents were posted on the web.
According to RENAPER, the information belonged to the victims of the 2021 attack, not a result of any new hack. Chequeado reported that the material included DNI information, photographs and fingerprints.
Other reports in 2024 also described a claimed database containing tens of millions of Argentine records. RENAPER again said the material was not evidence of a new hack.
That history makes the latest claim harder to assess. Criminal marketplaces often recycle old data and combine information from several leaks.
A Leaked Address could Create Serious Risks
If the current claim proves accurate, the exposure could be severe.
A DNI number alone is already sensitive. Combine a DNI number with an individual’s name, birthdate, phone number, address, etc and that gives a full profile. This info is valuable to attackers, they could pull off targeted scams, social engineering, or identity fraud with it.
Detailed addresses may also create physical safety concerns. An attacker would not need to search several sources to locate a person if an apartment number is already there.
Children’s records would be particularly concerning because minors may have fewer ways to detect misuse of their information. There is another problem with identity data: you simply cannot change it like a password.
Argentina’s DNI is the country’s official identity document, and people provide it when they need to prove who they are.
Argentina is Also Upgrading Its Identity Documents
The alleged leak comes as Argentina is modernizing its national ID system.
In January, RENAPER approved a new electronic DNI with updated security features. The document uses a polycarbonate card, an embedded chip and other security measures based on international standards.
The government says existing DNI documents remain valid, so citizens don’t have to replace them simply because of the new design. But stronger physical documents cannot solve the problem of exposed personal data.
If the claim turns out to be true, a few questions will require answers. How did the actor obtain the database? How much data does the database hold? And do the attackers still have access to it?
Until we gain clarification regarding these questions, the supposed RENAPER leak remains just that, rumor or unverified claim.