[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1gwcw66ut0hc6":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":9,"sourceUrls":15,"pwnCount":16,"affectedCount":16,"affectedCountStatus":17,"affectedCountLowerBound":18,"affectedCountUnit":19,"hasEnglishDescription":4,"severity":20,"dataClasses":21,"description":29,"seoTitle":9,"seoTitleEn":30,"seoDescription":9,"seoDescriptionEn":31,"logoUrl":32,"isVerified":4,"isSensitive":4,"isSpamList":33,"isMalware":33,"company":34},"68e3266eda11adda4882536b","salvadoran-citizens","Salvadoran Citizens Data Breach","","2024-04-02T00:00:00.000Z","2024-04-10T22:25:03.000Z","2024-04-10T22:26:30.000Z","2026-07-18T23:57:49.938Z","Third party breach",[],946989,"known",null,"unknown","High",[22,23,24,25,26,27,28],"Dates of birth","Email addresses","Government issued IDs","Names","Phone numbers","Physical addresses","Profile photos","\u003Cp>The Salvadoran Citizens data breach is a security incident recorded in April 2024 that affected millions of citizen records and accounts associated with approximately 947 thousand unique email addresses. In the incident linked to the publication of records belonging to citizens of El Salvador, official identification fields, profile photos, and contact information were included. This record addresses the number of affected accounts, the scope of the incident, which data fields were listed, and which steps users should prioritize in a clear manner.\u003C\u002Fp>\u003Cp>The nature of citizen data distinguishes this record from an ordinary membership data event; the combination of official ID, date of birth, address, and photo creates a high level of privacy and identity risk. Only data types that can be verified have been used in the description; additional claims that cannot be verified or could be confused with the same name have not been shown as a data field. In this way, the user can clearly see both the seriousness of the event and the applicable security measures for their personal account.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>The types of data listed in this incident are as follows: birth dates, email addresses, official identification information, names, phone numbers, physical addresses, and profile photos. When evaluated together, these fields create a very strong data profile in terms of identity fraud, targeted scams, forged document production, and personal security risk. The presence of these fields together can pose a higher risk than an email leak alone; because attackers can combine communication, identity, location, shopping, or account access signals belonging to the same person to prepare more convincing phishing attempts.\u003C\u002Fp>\u003Cp>In this record, the password field is not listed; however, since permanent data such as official ID, address, date of birth, and profile photo cannot be changed, the risk period is much longer. Users should especially pay attention to fraud attempts that match passwords, phone numbers, and address information they use on different services with the same email address. Even if there is no password in the leak, fields such as email, phone, full name, or physical address are valuable in terms of targeted advertising, social engineering, fake notifications, and account recovery abuse.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The record is associated with El Salvador citizen data; while the number of affected unique emails is listed as approximately 947,000, the total volume of records and photos is broader. Therefore, we keep the record limited to the available data fields without expanding it as if it were an official company statement. The incident is classified as a verified record. The scope limitation is important: unnecessary alarm is not given to the user for unlisted data types, but the combined impact of the listed fields should not be underestimated.\u003C\u002Fp>\u003Cp>This record has been kept in the context of citizen data instead of a specific commercial website; therefore, the domain name has been left blank and the sector has been corrected as government records. In points where there may be duplicate or incorrect attribution, the title, domain name, country, and sector information have been checked separately. Different platforms with similar names or different services operating in the same sector have not been merged under this record as if they were a single incident.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>Citizens of El Salvador, individuals who carry out transactions with the relevant official identification number, and users who use the same contact information in bank, public, or telecom accounts are at risk. The most important risk for individuals in this group is that the leaked data can be linked to daily account security. If a user uses the same email address in different shopping, gaming, community, dating, work, or financial services, attackers can use this information to create messages that appear to come from the real service.\u003C\u002Fp>\u003Cp>The combination of official ID and profile picture is not just about an online account; it also poses risks in terms of fake applications, convincing fraud, and attempts to act on behalf of the person. Email addresses with a corporate domain can also become targets for business account attacks. For individual users, fields such as phone number, address, date of birth, profile picture, purchase information, or device information can lead to consequences such as account takeover, phishing, harassment, unauthorized tracking, and reputation risk.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Affected users should monitor unusual application or verification attempts on bank, telecom, and public accounts; they should perform stricter verification against messages requesting official identity information. For accounts with passwords or password-like fields, users should change the password on all accounts where they have used the same or similar password, use strong and unique passwords, and enable multi-factor authentication wherever possible. For accounts without listed passwords, unexpected verification codes, links, and attachments received via email and phone should be evaluated more carefully.\u003C\u002Fp>\u003Cp>In records containing address, date of birth, official identification, profile photo, or location information, users should update identity verification questions, review account recovery options, and monitor for fake profiles representing themselves. Corporate users should share with the security team whether these fields are being used for employee targeting.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Since citizen data consists of fields that cannot be changed or are difficult to change, long-term monitoring, identity protection, suspicious application tracking, and institutional notifications are more important. In the long term, a unique password for each account, a password manager, multi-factor authentication, regular session checks, and the closure of old accounts form the basic security baseline. The fact that an email address has appeared in different incidents before signifies a risk accumulation that is not limited to a single record.\u003C\u002Fp>\u003Cp>After such incidents, it may not be sufficient for users to only change the password on the relevant platform. If the same phone number, the same delivery address, the same username, or the same recovery email is used on other services as well, attackers can try different accounts based on these common points. Therefore, making an inventory of accounts and cleaning up old memberships provides a permanent defense.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>If the user sees an email match, they should check not only the email account but also the phone line, bank account, official transaction history, and authentication settings. This record has been prepared to show the user directly which areas are at risk. If a match is seen, the first step is not to panic; it is to separate passwords, log out of sessions, review security notifications, and check for suspicious logins.\u003C\u002Fp>\u003Cp>Final assessment: This record is a high-impact citizen data incident involving official identification and non-biometric photo data; sensitive classification is therefore necessary. The user should compare the list of fields on this page with their account history and should immediately take action, especially on services where the same email-password pair is reused. Suspicious messages, unexpected calls, or account recovery notifications should be handled with higher priority after the incident.\u003C\u002Fp>","Salvadoran Citizens Data Breach (947 Thousand Reported Records)","Salvadoran Citizens Data Breach. 947 Thousand reported records were reported. Reported data: Dates of birth, Email addresses, Government issued IDs. Review…","\u002Fuploads\u002Flogo\u002Fsalvadoran_citizens.webp",false,{"name":35,"sector":36,"country":37,"website":9,"websiteArchiveUrl":9,"websiteStatus":9,"websiteCheckedAt":18},"Salvadoran Citizens","National Citizen Data \u002F Government Records","El Salvador"]