← Blog

INOCUIDAD Santa Cruz Breach Claim: 160k Food Handlers

Share on X

Unverified claim — August 17, 2026: Dark Web Informer reports that forum actor konata_izumi_shell published what they describe as databases and photo sets from INOCUIDAD, a Santa Cruz (Bolivia) departmental food-safety / sanitation system, covering more than 160,000 individuals, 150,000+ health-card photographs, and 100,000+ business records. Neither the Gobernación de Santa Cruz nor INOCUIDAD had confirmed the dump at indexing. Canonical row: inocuidad-santa-cruz2026.

Food-handler clearance systems sit in an awkward middle ground of government IT. They are not hospitals, but they store medical screening results that decide whether someone can keep a kitchen job. When those systems leak, the harm is not abstract “PII exposure.” It is hepatitis and tuberculosis results next to a national ID photo, an employer name, and a home address — the kind of package that turns a restaurant worker into a blackmail target overnight.

That is the alleged shape of the August 17 INOCUIDAD Santa Cruz listing. Treat every count below as an actor-attested, unverified claim until Bolivian authorities say otherwise.

What the INOCUIDAD data breach claim says

According to Dark Web Informer’s August 17 write-up, konata_izumi_shell posted a free, direct-download package labeled as coming from INOCUIDAD in Santa Cruz department. The actor framed the material as a JSON database plus a large JPG set. Headline figures circulating with the post include:

  • More than 160,000 individuals
  • More than 150,000 photographs (described as health-card / ID photos)
  • More than 100,000 business records with tax identifiers

Field lists summarized by DWI include national identity numbers, full names, dates of birth, home addresses, phones, emails, employer and job role, health-card photographs, hepatitis / tuberculosis / Chagas / STI screening results, additional clinical findings, fitness-to-work rulings, treatment notes, and business tax identifiers. That combination — identity + employer + infectious-disease screening — is why this claim clears BreachHistory’s bar for a named, high-signal unverified catalog row even without government confirmation.

What INOCUIDAD is (and why food-handler PHI cuts deep)

INOCUIDAD-style systems exist to certify that people who prepare or serve food have passed required health screens. In practice they become long-lived registries: workers renew cards, change employers, retest for the same pathogens, and the platform keeps the history. A dump of that registry is not “just employee data.” It is occupational health surveillance tied to identity documents.

Bolivia’s national ID number is used across banking, SIM registration, and everyday bureaucracy. Pairing it with a face photograph and an STI or tuberculosis result is a privacy failure that cannot be walked back with a password reset. Employers listed in the same rows give attackers a second vector: fake “your carnet sanitario expired — upload again” messages that look like they come from a known kitchen manager.

Timeline of what we know

  • August 17, 2026: Dark Web Informer documents the konata_izumi_shell free-download listing for INOCUIDAD Santa Cruz.
  • At indexing (August 21, 2026): No matching public confirmation from the Gobernación de Santa Cruz, INOCUIDAD operators, or a Bolivian data-protection notice was located in sources reviewed.
  • Related context: The same actor handle has appeared in other Bolivia-linked health dumps indexed by BreachHistory, including an unverified SSSRO rural health intern claim — which does not prove INOCUIDAD is authentic, but does show the handle’s targeting pattern.

Until Santa Cruz authorities confirm or deny, BreachHistory indexes recordsAffected at 160000 as the actor’s individual-count floor and keeps companyConfirmed: false.

What data was allegedly exposed

DWI’s inventory is the best public summary available:

  • Civil identity: national ID numbers, names, birth dates, addresses, phones, emails
  • Employment context: employer names, job roles, fitness-to-work rulings
  • Medical screening: hepatitis, tuberculosis, Chagas, STI results, other clinical findings, treatment notes
  • Biometrics-adjacent media: health-card / ID photographs at scale (150k+ claimed)
  • Business side: tax identifiers and business records (100k+ claimed)

What we do not have is an independent journalist’s dump authentication, a hospital-style OCR filing, or a departmental press release. Column names on a forum screenshot are not a census.

Who is at risk

Food handlers and hospitality workers in Santa Cruz who ever held an INOCUIDAD-style carnet are the primary population — including people who left kitchen work years ago if the registry retains history. Employers and restaurant owners appear in business tables and can be impersonated in worker-facing phishing. Family members sharing a phone or address with a listed worker can receive secondary scam traffic. Even tourists who briefly worked events or catering jobs could appear if their screenings were entered into the same system.

How this fits Bolivia’s 2026 health-data claims

Put INOCUIDAD next to the unverified Bolivia MoH SSSRO forum claim and the pattern is familiar: actors prefer government health-adjacent platforms that must stay online for compliance workflows and that accumulate years of identity plus clinical fields. These are not ransomware leak-site spectacles with countdown timers. They are free dumps that still destroy privacy for workers who never chose a SaaS vendor — they only needed a permit to keep a job.

International readers tracking U.S. health vendor breaches like CareCloud (~3.76M HHS OCR) or One Medical Seniors (~153k) will recognize the same lesson in a different institutional shape: the system that sits between a person and a paycheck is often the one holding the most sensitive combination of fields.

What authorities and INOCUIDAD have said

As of BreachHistory indexing on August 21, 2026, no public Santa Cruz departmental confirmation matching this specific konata_izumi_shell listing was located. Dark Web Informer documents the claim and field inventory. Watch for a Gobernación notice, a formal police cyber unit statement, or worker union letters — any of those would move the catalog row from unverified toward confirmed and may revise the count.

Action items if you hold (or held) an INOCUIDAD carnet

  1. Assume phishing will cite a real employer name and “carnet sanitario” renewal. Do not click WhatsApp or SMS upload links — open the official departmental site from a bookmark or go in person.
  2. If you reuse a password on any government health portal or email that received INOCUIDAD notices, change it and enable MFA on the mailbox.
  3. Treat unexpected calls about hepatitis / TB / STI “re-testing after the hack” as social engineering until verified through the published departmental phone number.
  4. Monitor bank and mobile-money accounts if your national ID and phone were stored together; identity-fraud risk is higher than password-reset risk here.
  5. Employers: warn staff in writing that INOCUIDAD will not ask for passwords or card photos over WhatsApp; document that warning.
  6. If you receive a letter or PDF claiming to be from INOCUIDAD, verify the domain and call the published office number before enrolling in any paid “monitoring” offer.
  7. Do not download alleged dump archives “to check if you’re in them.” That spreads secondary malware and further doxxing.
  8. Keep the Dark Web Informer URL as the public chronology; ignore aggregators that strip the unverified label.

Phishing patterns to expect after a Santa Cruz food-handler headline

Local breach news cycles in hospitality are predictable. Within days of a forum dump claim, kitchen managers see messages that look like they come from INOCUIDAD or from a municipal inspector: “your carnet was cancelled after the cyberataque — upload a new photo and ID by tonight or you cannot work.” Attackers do not need the dump to be real for that playbook to work. They only need workers to fear losing a shift.

Concrete defenses beat generic vigilance. Save the real departmental phone number in contacts. When a message cites an expired card, call that saved number. Never send a full national ID photo to an inbound WhatsApp account. If a page asks for a bank deposit “to reissue the carnet after the leak,” close the tab.

For restaurant owners and municipal IT

If your business uses INOCUIDAD for food-handler compliance, treat August 17 as an incident-response drill even without confirmation. Inventory which staff emails receive renewal notices. Tell workers which domains and phone numbers are legitimate. Ask the departmental operator — in writing — whether your workers appear in any forensic scope and whether photo archives were among systems reviewed. Document the answers.

Also review what you store locally. Many kitchens keep photocopies of carnets in binders or shared Drive folders. A cloud dump is bad; a photocopier drawer next to it is worse. Minimize copies. Lock paper archives. Stop emailing ID photos between shift leads.

How BreachHistory will update this story

We will revise inocuidad-santa-cruz2026 if Santa Cruz authorities confirm, deny, or publish a smaller attested census; if a Bolivian privacy authority posts a formal notice; or if reputable trade press authenticates samples against production records. Until then, search results for “INOCUIDAD data breach” or “Santa Cruz food handler leak” should keep the unverified label in the first screen — which is why this blog leads with it.

Readers comparing this claim to verified health incidents should remember the evidentiary bar: HHS OCR and company letters change a row; forum screenshots do not. The difference matters for workers deciding whether to freeze credit, file police reports, or simply harden against carnet phishing.

One more practical note for migrant and temporary kitchen workers: if you tested in Santa Cruz and later moved to another department or country, you may still be in the registry. Watch the phone number and email you used for the original carnet. Language barriers make fake “inspector” messages easier — an urgent Spanish-language PDF can look official to someone who never saw the real portal UI carefully.

Parents and partners of food handlers should remember that STI and infectious-disease fields are among the most sensitive strings a compliance system can hold. If a school, landlord, or employer later cites “a government health leak” while asking for medical paperwork, verify the request through a known channel, not through a link in an unexpected SMS.

Journalists and researchers reading alleged INOCUIDAD samples should avoid republishing rows that contain real names and disease results. Amplifying identifiable clinical samples helps the actor’s narrative more than it helps the public. The right model is to describe field categories and scale while refusing to mirror the dump.

If you are a Santa Cruz hospitality association and you already received a private departmental note that has not been posted publicly, consider whether local worker notice is required even before a national press release. Local letters beat silence when carnet phishing is already circulating in WhatsApp kitchen groups.

Bottom line for searchers landing on this page from “INOCUIDAD Santa Cruz data breach 2026” or “fuga carnet sanitario Santa Cruz”: the claim is large, clinically sensitive, and still unverified; the phishing risk is real either way; and the canonical BreachHistory record will track confirmation if and when it arrives.

For workers who never heard the acronym INOCUIDAD until a cousin forwarded a Telegram post: ask your employer which office issued your food-handler card and whether they have guidance after August 17. Document the answer. If a convincing message arrives tomorrow citing your kitchen by name, you will already know which phone number is legitimate and which domain to type by hand.

Security teams at departmental governments should treat the listing as a tabletop exercise regardless of confirmation: map which compliance databases hold photos and lab results, who has admin, whether backups sit on internet-reachable shares, and how you would notify 160,000 people if the claim proves real. Those questions remain useful even if this specific dump collapses under scrutiny.

Finally, do not let the “unverified” label become an excuse for complacency. Forum actors lie about counts and sometimes invent victims. They also sometimes publish real government health data. The responsible public posture is the one this page takes: name the claim, label it clearly, give workers concrete actions, and update the chronology when Santa Cruz speaks.

Why infectious-disease fields change the stakes

A leak of names and phones is bad. A leak of hepatitis or tuberculosis screening results next to a face photograph is a different category of harm. In small kitchen communities, rumor travels faster than any official FAQ. Workers can lose shifts over stigma even when a result is old, incomplete, or wrongly attributed. That is why this INOCUIDAD Santa Cruz data breach claim deserves careful public wording: scale matters, but so does the clinical sensitivity of the alleged columns.

Chagas screening and STI results add another layer. Those fields are not “HR metadata.” They are health information that, if authentic, belongs in a regulated clinical context — not in a free forum archive. Employers who learn of a dump should resist the urge to demand workers re-upload lab PDFs over chat. That impulse creates a second collection of sensitive files outside the original system.

What “fitness to work” rulings enable for scammers

Fitness-to-work fields are operational gold for social engineers. They tell an attacker whether a person was cleared, deferred, or restricted — and often when. A message that says “your aptitude expired on [date] after the cyberataque” can be customized with just enough truth to feel bureaucratic. Combine that with an employer name from the same row and the scam becomes a workplace problem, not just an inbox problem.

Workers should treat any inbound request to “revalidate aptitude” the same way they treat a bank freeze call: hang up, use a known number, and ask the office what channels they actually use. Managers should post a one-page notice in Spanish (and other languages used on the line) listing the only legitimate URLs and phones.

Business tax identifiers and restaurant fraud

The alleged 100,000+ business records matter beyond worker privacy. Tax identifiers and business contact fields support invoice fraud, fake supplier onboarding, and impersonation of municipal inspectors asking for “updated sanitation fees.” Restaurant owners who never heard of INOCUIDAD as a brand still need a verification habit: no wire transfers or card photos based on WhatsApp urgency alone.

If your accounting team receives a PDF that references the August 2026 dump and asks for immediate payment to “restore your commercial registry,” treat it as fraud until the Gobernación confirms a real process. Real governments rarely collect remediation fees through chat apps.

Cross-check BreachHistory’s related entries on Bolivia MoH SSSRO and large verified health vendor incidents only for context — not as proof that INOCUIDAD’s files are authentic. Similarity of actor handles or sector targeting is a research clue, not corroboration.