Dominican Republic Vaccinations Data Breach
Dominican Republic National Vaccination Records Breach (2024): 819K Citizen Records Including Government ID Exposed
Government-managed dataset of national vaccination and citizen health records.
Risk Interpretation
High sensitivity. Exposure can enable identity theft, medical privacy harm, profiling based on health status, and government-themed phishing or fraud.
Impact & Downstream Threats
The institutional impact on the Dominican Ministry of Public Health was meaningful but bounded by limited domestic regulatory enforcement infrastructure. There is no public record of substantial penalties against SESPAS or its IT contractors specifically tied to the breach. The reputational impact was concentrated within the Dominican public-health and digital-identity policy debate, with researchers and journalists pointing to the incident as evidence of weak data governance around health progr
- Identity theft and synthetic identity construction using government-issued IDs
Threat Vectors
Breach Intelligence
Executive Summary
The Dominican Republic's Ministry of Public Health and Social Assistance suffered a cyberattack in April 2024 that compromised more than 8,000 files containing COVID-19 vaccination records. The threat actor, using the alias CiberInteligenciaSV, posted the stolen dataset on Breach Forums, a hacking forum known for hosting Latin American breach data. Dominican news outlet DominicanToday and security researchers at Resecurity confirmed and analysed the leak.\n\nThe published dataset covered approximately 820,000 individuals. Compromised fields included the citizen's full name and Dominican national identification number (cédula), along with vaccination-specific data including total doses received, the clinic where doses were administered, dates of vaccination, and the type of vaccine used. The dataset reportedly included records linked to vaccines from Pfizer and SINOVAC, the two principal vaccines used in the Dominican vaccination campaign. Researchers noted possible overlaps with a separate breach of Dominican tourism company Caribe Tours from 2022, although the precise origin of the SESPAS file was not definitively traced.\n\nFor affected individuals, the practical risk is concentrated in identity-fraud scenarios using the cédula as a stable government identifier. The combination of full name and cédula supports identity-verification bypass at Dominican banks, government services, and other regulated institutions. Vaccination records themselves carry less direct fraud value but contribute to medical-privacy harm and could support discrimination or targeted social engineering. Individuals whose data may have been included should remain alert to unsolicited contact referencing public-health or government services, monitor accounts at Dominican financial institutions, and request fraud alerts where available.
About Dominican Republic Vaccinations
The Ministry of Public Health and Social Assistance of the Dominican Republic, known by its Spanish acronym SESPAS or MSP, is the Dominican government agency responsible for national public health policy, programs, and registry management. As part of its COVID-19 response, the Ministry maintained a national vaccination registry that recorded each citizen's vaccination status, doses received, dates, vaccine type, and the clinic where each dose was administered. The dataset combined immunisation records with each individual's national identification number (cédula), tying vaccination status to a stable government identifier used widely for identity verification, banking, employment, and access to government services across the Dominican Republic.
Why They Hold Your Data
Vaccination-record datasets collect highly sensitive citizen identity, public-health records, vaccination status, dates, and healthcare-linked information across immunization programs.
Recent Developments
SESPAS confirmed the cyberattack publicly in mid-April 2024 and engaged technical specialists to investigate. Dominican authorities acknowledged additional cyberattacks against government systems through 2024 and 2025, including an October 2024 breach of the country's migration system that was later linked in international reporting to a Spanish hacking operation called 'Udyat.' The Dominican Republic's data-protection framework continues to operate under Ley 172-13 of 2013, with broader legislative discussion about modernisation continuing through 2025. The COVID-19 vaccination dataset has continued to circulate on Breach Forums and other dark-web aggregators in the years since the original publication.
Data Points Exposed
Exposure Categories
Canonical Fields
full_name, government_id
Dark Web Verification
- Dataset containing ~819K records identified in breach intelligence sources
- Data indexed and searchable across breach notification platforms
- Source: dominican-republic-vaccinations-2024
Recommended Actions
⚠️ Do not assume this is low sensitivity.
Protect Yourself
Check If You’re Affected
Enter your email to check if your data appears in this breach.
Get Free Breach Alerts
Be the first to know when new breaches are disclosed.
High-Risk? Get an Exposure Audit
Full-spectrum exposure audits for executives and public figures.
ObscureIQ Advisory
We combine proprietary dark web access with commercial and restricted breach intelligence to verify exposure and assess real-world risk.
- A public-facing individual
- A high-profile executive
- A customer of Dominican Republic Vaccinations
- Or concerned about credential reuse
Powered by the ObscureIQ Breach Intelligence Database
© 2026 ObscureIQ · All Rights Reserved · Data Licensing
Latest from ObscureIQ
What Is Credit Monitoring? And Do I Want It? (Answer: Not Really)
Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars.
Sextortion Spam
