The BHU Data Breach  episode artwork

EPISODE · Oct 16, 2025 · 8 MIN

The BHU Data Breach

from Cybermidnight Club– Hackers, Cyber Security and Cyber Crime · host Alberto Daniel Hill

The BHU Data Breach: How Uruguay’s Digital Star Fell Victim to the Crypto24 Ransomware and 95% Weak PasswordsIn September 2025, the state-owned Banco Hipotecario del Uruguay (BHU) suffered a catastrophic systems failure. While the institution quickly minimized the event as a manageable "incidente informático" or "problema técnico", cybersecurity expert Alberto Daniel Hill immediately refuted this official fiction. Hill labeled the event a "secuestro digital" and a "crisis nacional", arguing the breach was the inevitable "payment" for Uruguay's decades-long "national cyber debt".This episode conducts a deep forensic analysis to expose the three critical layers of failure:Catastrophic Data Theft: Hill confirms the breach was a sophisticated double-extortion ransomware attack by the group Crypto24. Before systems were encrypted, Crypto24 successfully exfiltrated over 700 gigabytes of highly sensitive data. This massive payload included critical client Personally Identifiable Information (PII), property titles, loan contracts, financial records, and even the bank's internal IT security configurations.The 95% Vulnerability: Forensic analysis revealed that initial access was often facilitated by infostealer malware (like RedLine and Lumma) compromising end-user machines. Of 1,303 exposed user passwords linked to the BHU site, 95% were classified as weak or far too weak (including simple strings like "12345" or "bhu2020"). Hill famously compared the security of these credentials to writing them on a "servilleta mojada" (wet napkin).Architectural Failure and Silence: The bank’s drastic measure of activating a total network shutdown was not performed to "protect the information" (as claimed), but was a desperate, late-stage reaction after the 700GB theft was already executed. This failure stemmed from a monolithic IT architecture lacking essential network segmentation, which allowed Crypto24 easy lateral movement and access to potentially compromise backups.Hill relentlessly critiques the BHU's adoption of the "protocolo del silencio", a strategy intended to shield the bank’s image and leadership from legal sanctions. This failure to disclose the PII compromise prevents citizens from protecting themselves against massive fraud and identity theft. The ensuing public pressure led directly to the Senate formally demanding that the BHU halt penalties against affected customers.Join Hill as he uses his unique perspective—informed by his own prior persecution by the state for ethical disclosure—to advocate for immediate legal reform, mandatory transparency, and accountability for leaders whose institutional opaqueness he argues is the true enemy of digital sovereignty.#BHU #Crypto24 #SecuestroDigital #NationalCyberDebt #AlbertoDanielHill #Uruguay #Cybersecurity #Ransomware #PII #ProtocoloDelSilencio #WeakPasswords

The BHU Data Breach: How Uruguay’s Digital Star Fell Victim to the Crypto24 Ransomware and 95% Weak PasswordsIn September 2025, the state-owned Banco Hipotecario del Uruguay (BHU) suffered a catastrophic systems failure. While the institution quickly minimized the event as a manageable "incidente informático" or "problema técnico", cybersecurity expert Alberto Daniel Hill immediately refuted this official fiction. Hill labeled the event a "secuestro digital" and a "crisis nacional", arguing the breach was the inevitable "payment" for Uruguay's decades-long "national cyber debt".This episode conducts a deep forensic analysis to expose the three critical layers of failure:Catastrophic Data Theft: Hill confirms the breach was a sophisticated double-extortion ransomware attack by the group Crypto24. Before systems were encrypted, Crypto24 successfully exfiltrated over 700 gigabytes of highly sensitive data. This massive payload included critical client Personally Identifiable Information (PII), property titles, loan contracts, financial records, and even the bank's internal IT security configurations.The 95% Vulnerability: Forensic analysis revealed that initial access was often facilitated by infostealer malware (like RedLine and Lumma) compromising end-user machines. Of 1,303 exposed user passwords linked to the BHU site, 95% were classified as weak or far too weak (including simple strings like "12345" or "bhu2020"). Hill famously compared the security of these credentials to writing them on a "servilleta mojada" (wet napkin).Architectural Failure and Silence: The bank’s drastic measure of activating a total network shutdown was not performed to "protect the information" (as claimed), but was a desperate, late-stage reaction after the 700GB theft was already executed. This failure stemmed from a monolithic IT architecture lacking essential network segmentation, which allowed Crypto24 easy lateral movement and access to potentially compromise backups.Hill relentlessly critiques the BHU's adoption of the "protocolo del silencio", a strategy intended to shield the bank’s image and leadership from legal sanctions. This failure to disclose the PII compromise prevents citizens from protecting themselves against massive fraud and identity theft. The ensuing public pressure led directly to the Senate formally demanding that the BHU halt penalties against affected customers.Join Hill as he uses his unique perspective—informed by his own prior persecution by the state for ethical disclosure—to advocate for immediate legal reform, mandatory transparency, and accountability for leaders whose institutional opaqueness he argues is the true enemy of digital sovereignty.#BHU #Crypto24 #SecuestroDigital #NationalCyberDebt #AlbertoDanielHill #Uruguay #Cybersecurity #Ransomware #PII #ProtocoloDelSilencio #WeakPasswords

NOW PLAYING

The BHU Data Breach

0:00 8:42

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

MG Show MG Show The MG Show, hosted by Jeffrey Pedersen and Shannon Townsend, is a leading alternative media platform dedicated to uncovering the truth behind today’s most pressing political issues. Launched in 2019, the show has grown exponentially, offering unfiltered insights, comprehensive research, and real-time analysis. With a commitment to independent journalism and factual integrity, the MG Show empowers its audience with knowledge and encourages active participation in the political discourse. Breaking News Show | eTurboNews Juergen Thomas Steinmetz News is relevant to the global travel and tourism industry, human rights and global issues.Breaking news when it happens and only from the source. Eat to Live Jenna Fuhrman, Dr. Fuhrman Our health is our most precious gift and smart nutrition can change your life. Each month, join Dr. Fuhrman and his daughter, Jenna Fuhrman as they discuss important topics in the world of nutrition. Eat to Live will change the way you eat and think about food. French Your Way Jessica: Native French teacher founder of French Your Way Boost your French listening skills and test your comprehension with this one of a kind series of podcasts. Get the chance to listen to a real conversation between native speakers talking at normal speed AND customise your learning experience through carefully designed sets of questions (2 levels of difficulty) available for download at www.frenchvoicespodcast.com. All interviews also come with the transcript. French teacher Jessica interviews native speakers of French from around the world who share a bit of their life and passion. Where else would you meet in one same place a French yoga teacher based in Melbourne, a soap manufacturer from Provence, or a couple cycling around the world?

Frequently Asked Questions

How long is this episode of Cybermidnight Club– Hackers, Cyber Security and Cyber Crime?

This episode is 8 minutes long.

When was this Cybermidnight Club– Hackers, Cyber Security and Cyber Crime episode published?

This episode was published on October 16, 2025.

What is this episode about?

The BHU Data Breach: How Uruguay’s Digital Star Fell Victim to the Crypto24 Ransomware and 95% Weak PasswordsIn September 2025, the state-owned Banco Hipotecario del Uruguay (BHU) suffered a catastrophic systems failure. While the institution...

Can I download this Cybermidnight Club– Hackers, Cyber Security and Cyber Crime episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!