Colombia's national cyber incident response team is warning that a criminal group calling itself LaPampaLeaks has turned stolen personal data into a product anyone can subscribe to. The service, SAMARITAN API, lets a paying buyer run automated lookups against what the group says are more than 230 million personal records on citizens of Uruguay, Argentina, Peru and Chile. There is no identity check on who buys access.
Not a leak, a lookup service
ColCERT's central point in the alert, published on 4 August and marked TLP:CLEAR, is that this is not a passive dump of files traded once and forgotten. It is a running service, sold by subscription on underground forums and through a Telegram channel. The platform exposes more than 30 endpoints and 130 search parameters, documented so buyers can wire it into Telegram bots, scripts and their own tooling, which makes targeted queries against named individuals cheap and repeatable at scale. ColCERT classifies it as doxing as a service and sets the risk level at HIGH.
It has a lineage, too. ColCERT traces SAMARITAN API back to PampaBot, an earlier Telegram bot the same actor used to dox Uruguayan citizens. Version 1.3 is where that bot became a documented API covering four countries.
Where the data is said to come from
According to the group's own posts, which ColCERT relays as the actor's claim rather than as established fact, the records were assembled by combining leaked government databases (civil registry, electoral, education and traffic records) with data from multinational telecom operators, naming Claro and Movistar. Neither operator has confirmed a breach, and the provenance rests entirely on the seller's word, which is a sales pitch rather than evidence. Sellers routinely inflate both the size and the origin of these collections, and old leaks stitched together can be repackaged as something new: we covered a seller advertising 340 million records who eventually admitted no platform had been breached. The record count here should be read the same way, as an advertised figure.
Why Colombia is warning about other countries' data
Colombia is not among the four countries covered so far, which is precisely why ColCERT frames the impact as preventive. The actor describes the current operation as 'phase 2' of a plan to cover all of South America and Latin America. ColCERT's reasoning is infrastructural: Claro and Movistar run shared architecture across the region, so if the sourcing claim holds, an expansion could pull Colombian records and local operator data in with it.
What it enables
ColCERT lists the abuse this kind of service feeds: SIM swapping, voice phishing, targeted phishing, extortion and identity impersonation, plus reputational and compliance exposure for the organizations whose data ends up in it. The common thread is that every one of those gets easier when an attacker can cheaply confirm a target's identity documents, phone number and address before making contact.
For organizations in the affected countries, the practical takeaway is that knowledge of personal details can no longer serve as proof of identity. That means tightening call center and account recovery flows that still verify callers with an ID number or address, watching for SIM swap indicators on high value accounts, and expecting fraud attempts from people who already have correct answers to the usual security questions.
The full alert, reference AL-20260804-107, is published by ColCERT, Colombia's national cybersecurity incident response group, and is the latest in a run of ColCERT advisories we have covered, after its warning on fake court notices installing a data stealing worm. Country context for the states named is on our Uruguay and Argentina profiles.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.