Brecha de seguridad del BANCO HIPOTECARIO DEL URUGUAY, datos medicos y la crisis digital.

Brecha de seguridad del BANCO HIPOTECARIO DEL URUGUAY, datos medicos y la crisis digital.

Author: Alberto Daniel Hill September 17, 2026 Duration: 8:26

¿Pueden los jerarcas de un banco estatal decidir mediante un decreto de reserva que tus datos de salud queden bajo su control y en el secreto por 15 años?

En este video podcast de análisis e investigación forense, desglosamos el hallazgo más delicado y crítico tras auditar la filtración masiva de 700 GB del grupo cibercriminal Crypto24 al Banco Hipotecario del Uruguay (BHU): la presencia de fichas médicas, certificados de aptitud física y evaluaciones de salud del Club Banco Hipotecario (CBH) alojados sin cifrado en carpetas compartidas de la red del banco (\\Server\Comun\...).

  • 🧬 El Hallazgo de Datos Médicos: Cómo información de salud e historias clínicas terminaron expuestas en la dark web junto a escrituras, recibos de sueldo y deudas crediticias.
  • ⚖️ El Conflicto de Derechos: El choque entre el decreto de reserva confidencial por 15 años aprobado por el Directorio del BHU y el régimen de protección de datos sensibles (Ley N° 18.331, Art. 9 y 14 / GDPR Art. 9).
  • ⏱️ La Guillotina de 5 Días: Las intimaciones formales de derecho de acceso enviadas al BHU y al Club BHU con plazo legal perentorio.
  • 🚫 El Rebote Técnico (SMTP 550): La insólita respuesta de los servidores de correo de la URCDP (AGESIC) al rebotar la denuncia formal, perfeccionando la denegatoria ficta y la mala fe administrativa.
  • 🏛️ Escalada Transnacional: La denuncia ante la INDDHH en Uruguay y la Segnalazione ex Art. 144 radicada ante el Garante Privacy en Roma, poniendo en riesgo la adecuación de datos de Uruguay ante la Unión Europea.

Can state bank executives enforce a 15-year secrecy decree over your sensitive health records leaked on the dark web?

In this video podcast briefing, we analyze the critical revelation inside the 700 GB Crypto24 ransomware data dump at Banco Hipotecario del Uruguay (BHU): unencrypted health assessments, medical clearance files, and physical fitness certificates from Club Banco Hipotecario (CBH) sitting exposed on open bank network shares (\\Server\Comun\...).

  • 🏋️ Exposed Health Records: How routine sports club medical files were exfiltrated alongside mortgages, property titles, and payrolls.
  • 🛡️ Secrecy Decrees vs. Human Rights: Why state secrecy resolutions cannot override statutory privacy guarantees under Law N° 18.331 and GDPR Article 9.
  • ⏱️ The 5-Day Statutory Clock: Serving formal Article 14 data access demands to BHU and Club BHU.
  • 🚫 Connection Refused (SMTP 550): The official regulatory complaint to URCDP/AGESIC bouncing back, establishing technical obstruction and administrative bad faith (denegatoria ficta).
  • 🇮🇹 Rome & Transnational Escalation: Filing a formal complaint before Italy’s Garante Privacy (Art. 144) and the Italian Embassy, threatening Uruguay's EU Data Adequacy status.
  • 00:00 — Introducción: La brecha de 700 GB y el hallazgo en el Club BHU
  • 02:15 — Datos sensibles de salud expuestos en carpetas compartidas
  • 05:40 — ¿Tienen jerarcas bancarios la potestad de ocultar tu información médica?
  • 09:10 — Intimaciones de 5 días hábiles al BHU y CBH
  • 12:30 — El servidor rebotado: Error SMTP 550 en la URCDP (AGESIC)
  • 15:45 — Escalada a Roma (Garante Privacy) e intervención de la INDDHH
  • Investigación & Conducción: Alberto Daniel Hill
  • PGP Key ID: 0xA1406A6E117EF283
  • Fingerprint: 6B33 A7C8 E94B 8D9C 4E54 03DE A140 6A6E 117E F283

#CasoBHU #Ciberseguridad #DatosSensibles #DerechosDigitales #Uruguay #GDPR #HabeasData #TransparenciaYa

🇪🇸 Descripción en Español (Principal)📌 Puntos clave de este episodio:🇬🇧 English Description (Alternative / Bilingual)📌 Episode Highlights:⏱️ Marcas de Tiempo (Timestamps)🔑 Firma PGP & Registro Público


Alberto Daniel Hill hosts Cybermidnight Club-Hackers, Cyber Security and Cyber Crime, a podcast that exists at the raw intersection of digital crime and personal consequence. His authority comes from a unique and grim distinction: as an expert in cybersecurity, he also became the first person in Uruguay to serve a prison sentence for a computer-related crime-one he maintains he did not commit, an offense that may be entirely fictional. This lived experience, shadowed by ambiguity and the weight of the state, fuels every conversation. The series moves beyond theoretical discussions to explore the real human stories and systemic flaws within the shadowy realms of hacking, security failures, and cyber crime. Listeners are taken into operations on the dark web, not through sensationalism, but through the lens of someone who has navigated its myths and realities from both sides of the law. The podcast naturally unfolds with interviews, analysis, and Hill’s own reflections, offering a grounded perspective that challenges easy narratives about guilt, technology, and power. It’s a detailed audit of the digital underworld, conducted by a guide who understands the cost of a single line of code or a misplaced accusation. You’ll hear about vulnerabilities, both in systems and in justice, making this a essential series for anyone intrigued by the true crime of the modern age, where the evidence is often ephemeral and the stakes are profoundly human.
Author: Language: English Episodes: 50

Cybermidnight Club– Hackers, Cyber Security and Cyber Crime
Podcast Episodes
La venganza criptográfica de Alberto Daniel Hill [not-audio_url] [/not-audio_url]

Duration: 1:04:12
La venganza criptográfica de Alberto Daniel Hill,**Operativos / caso** `#CiberseguridadUY` `#AGESIC` `#CERTuy` `#TransparenciaRadical` `#OpSecFails` `#MGAP` `#SNIG` `#DFIR` `#GnuPG` `#Transparencia` `#SeguridadDigital` `…
The Cryptographic Siege of Alberto Daniel Hill [not-audio_url] [/not-audio_url]

Duration: 31:50
The_Cryptographic_Siege_of_Alberto_Hil**Operativos / caso** `#CiberseguridadUY` `#AGESIC` `#CERTuy` `#TransparenciaRadical` `#OpSecFails` `#MGAP` `#SNIG` `#DFIR` `#GnuPG` `#Transparencia` `#SeguridadDigital` `#Cibersegur…
La ecuación que desenmascaró al Estado uruguayo [not-audio_url] [/not-audio_url]

Duration: 31:50
La ecuación que desenmascaró al Estado uruguayo**Operativos / caso** `#CiberseguridadUY` `#AGESIC` `#CERTuy` `#TransparenciaRadical` `#OpSecFails` `#MGAP` `#SNIG` `#DFIR` `#GnuPG` `#Transparencia` `#SeguridadDigital` `#C…
Forensic Audit and Integrity Report of CERT.uy Email Correspondence [not-audio_url] [/not-audio_url]

Duration: 7:31
Forensic Audit and Integrity Report of CERT.uy Email Correspondence**Operativos / caso** `#CiberseguridadUY` `#AGESIC` `#CERTuy` `#TransparenciaRadical` `#OpSecFails` `#MGAP` `#SNIG` `#DFIR` `#GnuPG` `#Transparencia` `#S…
Jaque mate criptográfico al Estado uruguayo [not-audio_url] [/not-audio_url]

Duration: 22:29
Jaque mate criptográfico al Estado uruguayo**Operativos / caso** `#CiberseguridadUY` `#AGESIC` `#CERTuy` `#TransparenciaRadical` `#OpSecFails` `#MGAP` `#SNIG` `#DFIR` `#GnuPG` `#Transparencia` `#SeguridadDigital` `#Ciber…
Jaque mate criptográfico al Estado uruguayo [not-audio_url] [/not-audio_url]

Duration: 12:04
Jaque mate criptográfico al Estado uruguayo**Operativos / caso** `#CiberseguridadUY` `#AGESIC` `#CERTuy` `#TransparenciaRadical` `#OpSecFails` `#MGAP` `#SNIG` `#DFIR` `#GnuPG` `#Transparencia` `#SeguridadDigital` `#Ciber…
Ciberdelincuencia de Estado y fraude forense [not-audio_url] [/not-audio_url]

Duration: 30:15
Ciberdelincuencia de Estado y fraude forense**Operativos / caso** `#CiberseguridadUY` `#AGESIC` `#CERTuy` `#TransparenciaRadical` `#OpSecFails` `#MGAP` `#SNIG` `#DFIR` `#GnuPG` `#Transparencia` `#SeguridadDigital` `#Cibe…
How Alberto Hill Cornered Uruguay [not-audio_url] [/not-audio_url]

Duration: 43:44
How Alberto Hill Cornered Uruguay**Operativos / caso** `#CiberseguridadUY` `#AGESIC` `#CERTuy` `#TransparenciaRadical` `#OpSecFails` `#MGAP` `#SNIG` `#DFIR` `#GnuPG` `#Transparencia` `#SeguridadDigital` `#Ciberseguridad`…