-
Someone on a cybercrime forum claims to hold 305,852 tuberculosis records from Mexico’s national disease tracking system, and is selling everything for 12,500 pesos.
-
A 4,000-record sample shows names, ID numbers, addresses and HIV status, including for babies, prisoners and migrants.
-
The hacker allegedly obtained the data in September 2025, months after a similar leak. No public response from the Health Secretariat has surfaced.
A hacker using the handle “Eternal” is selling what he says is Mexico’s national tuberculosis database containing 305,852 records.
The data allegedly comes from the country’s disease tracking system, known as SINAVE, which the Health Secretariat oversees. The asking price is 12,500 pesos, about four centavos per patient.
What the Sample Shows
A review of a 4,000-record sample found 193 data fields per person. They include name, home address, phone number, and CURP, Mexico’s national ID number. Every CURP checked out as valid.
The files go well beyond contact details. They list HIV diagnoses, drug use, alcoholism, pregnancy, and lab results. Medical notes also name family members and contacts. Those people were never patients.
The seller says the data covers all 32 states. It spans IMSS, IMSS-Wellbeing, the Health Secretariat, ISSSTE, the defense and navy secretariats, and Pemex.
The sample alone holds 409 inmates from prisons in Baja California, Chihuahua, and Coahuila. It lists 249 minors, 15 of them babies. It also includes 270 speakers of indigenous languages and 13 migrants, with their travel routes.
Fifty doctors and nurses appear too. The full database also reportedly exposes 805 user accounts and more than 2,000 names of health workers who entered the data.
Only one in five records in the sample is a confirmed tuberculosis case. The rest are suspected cases or people still under study. All stayed on file. Many people named may never have had the disease.
A Similar Incident has been Reported Before
The seller says the data was extracted in September 2025. That would mean it has been out of control for a year. No public statement from the Health Secretariat turned up in searches for this story.
This is not the first warning. In March 2025, Publimetro México reported that a hacktivist group called Ciberguerrilla Nahual had breached SINAVE and leaked patient records.
The outlet reviewed more than 1,300 records dating from 2018 to 2025. They held names, CURPs, diagnoses, treatments and the doctors involved. Publimetro said it was unclear whether the attack used a website flaw or an insider leak. The group said it acted to pressure the Oaxaca government, and it apologized for hitting a health system.
The reporter who covered that leak says doctors who entered SINAVE data confirmed that the records were accurate. If the seller’s date is right, that means the flaw remained open for about six months after that report.
Who is Eternal?
Eternal also goes by Holistic-K1ller and V1ralGod, and he has spent at least five years leaking and selling Mexican databases. His claimed targets include 10 million Telcel users, 1.7 million vehicles in the REPUVE registry, and the Registro Civil, according to Milenio reports.
Eternal is not the only threat actor claiming access to large Mexican datasets. Another hacker recently claimed root access to fuel retailer Mega Gasolineras and offered 1.9TB of data for $450.
Another report also ties him to the April 2025 leak of President Claudia Sheinbaum’s marriage certificate, and to a 2022 leak of more than 10 million Banorte customers.
Some of his offers have held up. Milenio notes that at least one recent offer was confirmed by the affected company. This month, the Anticorruption Secretariat issued two alerts in five days tied to his activity. It took over data leak cases after Mexico’s privacy agency, INAI, was dissolved.
Another Health System in Question
In June 2026, cybersecurity specialists reported that a group had taken about 1.7 million clinical records from the federal health system, including CURPs, tax IDs, emails and birth dates. The platform was named AAMATES, which stores electronic medical records. The specialists said such leaks can lead to identity theft and tailored fraud.
Why this Data is Dangerous
A tuberculosis label still carries stigma. Publimetro warned in 2025 of discrimination and extortion risks for patients. Add HIV status or drug use, and the risk grows. Addresses and family names give scammers plenty to work with.
Fraud and extortion were Mexico’s most common crimes in the 2026 national victimization survey, Milenio notes. Cheap databases like this feed those phone scams. Health workers face risks too. Their names could invite threats or impersonation.
Some Key Details Still Unconfirmed
In this situation, everything hinges on what the seller says and on a sample. There hasn’t been any public verification of the full database yet. Leaked files can sometimes come from either an old database or data scraping from public sources, so each leak needs checking.
The valid CURP numbers and unique information indicate real patients. Official confirmation will clarify the situation. But currently, there is no way for patients to find out if their data is part of the database.
If someone receives a phone call from a stranger knowing their diagnosis, he should immediately hang up and contact relevant agencies. Reporting such a leak falls within the competence of the Anticorruption Secretariat.