Dominican Republic Vaccinations 2024 Data Breach

Dominican Republic National Vaccination Records Breach (2024): 819K Citizen Records Including Government ID Exposed

Government Health Data Exposure · Public health vaccination records and citizen identity data · National vaccination records dataset · Dominican Republic

Dominican Republic National Vaccination Records Breach (2024): 819K Citizen Records Including Government ID Exposed

Government-managed dataset of national vaccination and citizen health records.

Confirmed · ObscureIQ Intelligence
Breach Risk Index i
54/100
Lower riskHigher risk
Moderate: notable exposure with meaningful misuse potential.
Data Sensitivity i
Elevated
Exposed data raises the risk of fraud, targeting, and impersonation. Proactive steps are warranted.
819KRecords
2024Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
Gov IDGovernment ID
Classification Tags
CiberInteligenciaSVCloud MisconfigurationHealthcareMedicalCitizen2024

Breach Summary

The Dominican Republic's Ministry of Public Health and Social Assistance suffered a cyberattack in April 2024 that compromised more than 8,000 files containing COVID-19 vaccination records. The threat actor, using the alias CiberInteligenciaSV, posted the stolen dataset on Breach Forums, a hacking forum known for hosting Latin American breach data. Dominican news outlet DominicanToday and security researchers at Resecurity confirmed and analysed the leak.\n\nThe published dataset covered approximately 820,000 individuals. Compromised fields included the citizen's full name and Dominican national identification number (cédula), along with vaccination-specific data including total doses received, the clinic where doses were administered, dates of vaccination, and the type of vaccine used. The dataset reportedly included records linked to vaccines from Pfizer and SINOVAC, the two principal vaccines used in the Dominican vaccination campaign. Researchers noted possible overlaps with a separate breach of Dominican tourism company Caribe Tours from 2022, although the precise origin of the SESPAS file was not definitively traced.\n\nFor affected individuals, the practical risk is concentrated in identity-fraud scenarios using the cédula as a stable government identifier. The combination of full name and cédula supports identity-verification bypass at Dominican banks, government services, and other regulated institutions. Vaccination records themselves carry less direct fraud value but contribute to medical-privacy harm and could support discrimination or targeted social engineering. Individuals whose data may have been included should remain alert to unsolicited contact referencing public-health or government services, monitor accounts at Dominican financial institutions, and request fraud alerts where available.

Full threat analysis, exploitation vectors, and principal guidance below.

11 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

819K records analyzed

About Dominican Republic Vaccinations

The Ministry of Public Health and Social Assistance of the Dominican Republic, known by its Spanish acronym SESPAS or MSP, is the Dominican government agency responsible for national public health policy, programs, and registry management. As part of its COVID-19 response, the Ministry maintained a national vaccination registry that recorded each citizen's vaccination status, doses received, dates, vaccine type, and the clinic where each dose was administered. The dataset combined immunisation records with each individual's national identification number (cédula), tying vaccination status to a stable government identifier used widely for identity verification, banking, employment, and access to government services across the Dominican Republic.

Why They Hold Your Data

Vaccination-record datasets collect highly sensitive citizen identity, public-health records, vaccination status, dates, and healthcare-linked information across immunization programs.

Recent Developments

SESPAS confirmed the cyberattack publicly in mid-April 2024 and engaged technical specialists to investigate. Dominican authorities acknowledged additional cyberattacks against government systems through 2024 and 2025, including an October 2024 breach of the country's migration system that was later linked in international reporting to a Spanish hacking operation called 'Udyat.' The Dominican Republic's data-protection framework continues to operate under Ley 172-13 of 2013, with broader legislative discussion about modernisation continuing through 2025. The COVID-19 vaccination dataset has continued to circulate on Breach Forums and other dark-web aggregators in the years since the original publication.

Data Points Exposed

2 verified field types
Full Name
Government ID Critical

Breach Impact

The institutional impact on the Dominican Ministry of Public Health was meaningful but bounded by limited domestic regulatory enforcement infrastructure. There is no public record of substantial penalties against SESPAS or its IT contractors specifically tied to the breach. The reputational impact was concentrated within the Dominican public-health and digital-identity policy debate, with researchers and journalists pointing to the incident as evidence of weak data governance around health programs. Cross-border concern has been voiced because the dataset includes records on tourists who received vaccinations during stays in the country, alongside records on Dominican nationals.

Exploitation & Downstream Threats

• Identity theft and synthetic identity construction using government-issued IDs

Principal Risk Advisory

What this means for a principal

A healthcare-linked breach: exposure ties a named individual to a provider relationship and, where clinical or insurance data is present, to conditions and treatment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.

What You Should Do

  1. Freeze credit at all three bureaus and monitor for new-account and tax-refund fraud.
  2. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping: cross-reference the exposed identifiers against broker-available data to size and prioritize the principal's wider footprint.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).
C
Threat Actor: CiberInteligenciaSVConfidence: High
Data leak / hacktivist-style actor

Motivation: Political, anti-government, exposure-driven
A data leak actor associated with large-scale Salvadoran citizen data exposure, including PII and biometric material. Reporting also links the actor to compromise claims involving El Salvador's Chivo state Bitcoin wallet, source code, and VPN credentials.

Read the full threat-actor profile →

Protect Yourself

Check If You're Affected

Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation