The Michoacán State Government CADPE portal in Mexico has allegedly suffered a data breach affecting government suppliers, with threat actors claiming to have published 37,037 identity documents totaling over 58GB. The incident, reported on July 24, 2026, involves two actors operating under the handles “homercracker” and “cenfecracked” who have made the full archive available as a free direct download.
What Types of Documents Were Allegedly Exposed?
The leaked material reportedly consists of scanned source documents rather than extracted database fields, making it particularly concerning for identity fraud. The archive allegedly includes INE voter credentials, CURP population codes, RFC taxpayer identifiers, and official identification documents of business owners and legal representatives. Additional materials claimed in the leak include professional licenses, fiscal domicile certificates, photographs of fiscal addresses, tax situation certificates, and SAT compliance opinions.
Financial records are also allegedly present, including two months of financial statements, payment receipts and proofs, corporate charters, and employee declarations. Email contacts for the affected suppliers round out the exposed information. The folders are reportedly indexed by RFC numbers, making individual records easily searchable without requiring bulk data processing.
How Does This Breach Differ From Typical Data Exposures?
Security analysts note that this incident stands apart from standard database breaches because it involves complete identity packages rather than isolated data points. A photographed INE credential combined with CURP, RFC, professional licenses, and corporate documentation creates a ready-made identity kit that can be submitted directly to institutions accepting document images.
The combination of home and business addresses, photographs of physical premises, and recent financial statements creates what analysts describe as a targeting profile rather than merely a fraud profile. This data reveals not only who business owners are but where they and their operations are located, what their facilities look like, and their recent cash flow.
What Are the Physical Safety Concerns?
Michoacán has documented persistent problems with business extortion, and the nature of this leaked information maps directly to how such targeting operations are conducted. For affected registrants, the exposure carries physical risks alongside financial ones, particularly because none of the compromised information can be remediated by simply changing passwords or credentials. The free distribution without any pricing removes barriers to acquisition by malicious actors.
What Is the Current Verification Status?
The claim remains unverified as of this report. The posting account was created within the last week with minimal history, though the detailed document inventory and RFC-indexed folder structure show more specificity than typical fabricated claims. Neither the document count nor archive contents have been independently corroborated, and the Michoacán State Government has not publicly addressed the alleged breach. Suppliers registered with CADPE are advised to remain vigilant for identity misuse and unsolicited approaches referencing their business or premises.
Source: Dark Web Informer