On September 27, 2022, the Ministry of Foreign Affairs of Costa Rica, known formally as Ministerio de Relaciones Exteriores, appeared on the leak site operated by the onyx ransomware group. The listing states that internal files were exfiltrated during a ransomware attack, although the exact volume and specific categories of data remain undisclosed by the group.
Watch Ministerio de Relaciones Exteriores
Get alerted the next time Ministerio de Relaciones Exteriores files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Ministerio de Relaciones Exteriores’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the Leak-Site Listing
The onyx leak site entry states that the Costa Rican foreign ministry was listed as a victim and that the attackers claim to have stolen internal data. The disclosure does not quantify the number of records affected, name the precise systems compromised, or list the file types exfiltrated. It simply states that data was taken and gives the ministry a deadline to negotiate before further publication. Public copies of the listing, preserved through ransomware.live, show the initial posting occurred on September 27, 2022.
Why This Matters for You and Your Family
When a government ministry that handles passports, visas, consular records, and international communications is breached, the information stolen can easily include details about private citizens. Even if your name is not on a specific leaked document today, diplomatic and administrative databases frequently contain addresses, phone numbers, dates of birth, passport numbers, and family-member relationships. Once such data leaves official control it circulates among criminal networks and can be used for identity theft, targeted phishing, or extortion attempts against you or your relatives. The fact that the ministry has not released a detailed breach notification means you cannot assume your information was untouched.
Doxxing and Identity-Chain Risks
Ransomware operators rarely stop at the first dataset they obtain. A single leaked government email address or internal spreadsheet can link your work identity to personal accounts, social-media handles, and even children’s gaming profiles. These connections form an identity chain that lets attackers impersonate family members, reset passwords across services, or publish personal information to increase pressure on the victim organization. Credential leaks of this nature frequently cascade into account takeovers on platforms that use the same email or password combinations. DoxxScan by GalaxyWarden continuously monitors across 13.1B+ breach records and 100+ platforms with AI-powered identity-chain mapping and hands-on remediation by specialists, including household coverage that extends to children’s gaming accounts.