Unverified claim — August 6, 2026: An actor calling itself LaPampaLeaks says it holds the databases behind Uruguay’s GURI primary-education platform — a 1,144,324-row family application table plus enrolment databases totalling about 3.2 million records for pupils from 2012 to 2025 — and has already plugged them into a paid lookup service. Dark Web Informer covered the listing and marked it unverified. ANEP previously confirmed a cybersecurity incident that took GURI offline; it has not confirmed these volumes.
That combination — children’s national IDs, home addresses and the school and class they attended — is why this claim matters even before a regulator publishes a count.
What is being claimed
According to Dark Web Informer’s August 6 report, LaPampaLeaks markets GURI data as both a bulk sale and a subscription query product. The fields named in the listing include:
- National identity numbers (cédulas)
- Full names and dates of birth
- Home addresses, phone numbers and email addresses
- Family identifiers and parent relationship records
- School name and number, class and year attended
- Department/jurisdiction, gender and socio-cultural classification codes
The actor’s own narrative says CEIP previously treated an intrusion as a limited cybersecurity incident and took the platform offline for about a week without disclosing full scope. That account is the actor’s; treat it as self-serving until ANEP says otherwise.
DWI noted screenshots that appeared to show authenticated queries against live endpoints, which — if authentic — would imply ongoing access rather than a one-time historical dump. BreachHistory is not reproducing endpoints or contact channels.
What Uruguay’s education authorities have confirmed
ANEP and DGEIP did publish a shorter, careful notice of their own: they had detected a cybersecurity incident affecting the GURI platform, GURI would remain out of service while they worked, and families were told updates would follow. A later ANEP update said GURI Familia (app and web) was functioning again while teams continued restoring teacher access.
El País reported the GURI outage in the same news cycle as other Uruguayan public-sector disruptions, including Plan Ceibal platforms and an incident at Banco Hipotecario del Uruguay. Those are separate systems; do not merge them into one breach without official wording that connects them. What they do show is pressure on Uruguay’s education and citizen-facing digital estate.
Critically, the government notices confirm an incident and an outage. They do not, as of indexing, confirm that 1.14 million family rows or 3.2 million enrolment rows left the building, nor that a commercial lookup service is populated with children’s school histories. That gap is why this catalog row and this article stay labelled unverified on the data-sale claim.
What GURI is
GURI is not a marketing CRM. It is the operational system Uruguay uses to manage early childhood and primary education — attendance, school assignment, family contacts and the administrative spine that lets a national system know which child sits in which classroom. When that dataset leaks, the harm is not “another email list.” It is a map of minors: who they are, where they live, and where they spend their days.
Parents use GURI Familia to handle school paperwork. Teachers use related access for classroom administration. That dual audience is why a platform outage becomes national news within hours, and why a claimed database sale becomes a child-protection story rather than a routine breach blurb.
Why children’s education data is different
Adults can freeze credit, change phone numbers and argue with banks. Children cannot rotate a birth date or a cédula. A record that pairs a named child with a home address and a school creates stalking, custody and grooming risks that have nothing to do with credit cards. Family identifiers extend the blast radius to siblings and parents, which is exactly how a “student database” becomes a household dossier.
The lookup-service angle makes it worse. Buying a bulk dump takes effort and money. Searching a name in a subscription panel does not. If the actor’s marketing is accurate, the barrier to abusing school history drops from “download a database” to “type a query.”
None of that proves the listing is genuine. It explains why unverified claims against school platforms still deserve careful public tracking — and why authorities should answer them with facts, not silence.
What we do not know
Several gaps should stay visible:
- Confirmed exfiltration volume. ANEP has not published an attested count of affected children or families.
- Whether the Aug 2026 listing is fresh theft or delayed sale of material from an earlier GURI incident.
- Whether endpoints shown in actor screenshots were still live when DWI observed them.
- Whether Ceibal or BHU incidents share an intrusion set with GURI — currently unproven in public reporting.
Until those answers exist, anyone citing “4.3 million Uruguayan children hacked” as settled fact is overstating the record. The honest sentence is: a named actor claims GURI databases at that scale; Uruguay confirmed a GURI cybersecurity incident and outage; the sale volumes remain unverified.
Who should care
Parents and guardians of children who attended public initial or primary school in Uruguay between 2012 and 2025 are the primary audience for the claim. Even if your child has changed schools, historical enrolment rows are part of what the actor says it holds.
Teachers and school administrators may appear in related tables or be targeted with spear-phishing that references real classroom rosters.
Adults who were pupils in that window should assume their childhood school history could be searchable if the claim holds — useful for identity fraud and doxxing years later.
Other Latin American education ministries should treat this as a warning shot about pupil information systems that were never designed for an extortion-and-query market.
Scams that follow school-data claims
Whether or not LaPampaLeaks is telling the truth, opportunists will fake it.
“Update your child’s GURI profile.” Messages that demand a cédula photo, a payment, or a login to a look-alike domain. Real GURI Familia access should be opened from the official app or a URL you type yourself.
“School transport / canteen debt.” Small payment requests that quote a child’s name and school. Pay only through channels the school already uses.
“Custody or social-services verification.” Cold calls that recite a child’s date of birth and school. Hang up and call the institution on a published number.
Teacher payroll and “re-enrolment” phishing aimed at staff after a public outage, when urgency feels normal.
What you should do
- Use only official GURI / ANEP channels. Do not follow links in SMS, WhatsApp or email about “restoring access.”
- Never send a child’s identity document to anyone who contacted you first.
- Talk to older children about phishing that name-drops their school — they are targets too.
- Watch for identity fraud that uses school history as a knowledge-based authentication answer at banks or telcos.
- Teachers: treat unexpected MFA prompts and password-reset calls as hostile until verified out of band.
- Keep screenshots of any official ANEP notices you receive; dated government communication helps if fraud follows.
- If you are outside Uruguay but hold similar pupil platforms: inventory which fields a contractor or API can export in bulk, and whether query logs would detect a scrape.
How this fits the 2026 education threat picture
Schools and ministries remain soft targets because the data is dense, the budgets are thin, and the subjects cannot opt out. Ransomware against US K-12 districts has dominated English-language coverage; Latin American national platforms are the same asset class with fewer public breach letters. A claimed query service built on children’s enrolment history is the logical next product after bulk dumps — higher margins, lower friction, harder to “take down.”
Uruguay’s GURI claim sits next to other 2026 education and youth-data incidents in the BreachHistory catalog, but it is distinctive for the combination of national ID, address and classroom assignment. That is location intelligence about minors, not a newsletter list.
How journalists and parents should read “unverified”
Unverified does not mean “ignore.” It means the sale volumes and the query-service claim are not yet backed by an ANEP attestation or a regulator filing with a sample notice. Dark-web actors inflate numbers, recycle old dumps and screenshot staging environments. They also sometimes tell the truth. The responsible public posture is to warn families about the scam patterns that follow a high-profile education claim, cite the government outage notices accurately, and refuse to launder an actor’s marketing copy into “4.3 million children confirmed breached.”
If ANEP later confirms exfiltration, this article’s label changes. If ANEP says the listing is fabricated, that belongs in the record too. Either outcome is better than a vacuum that leaves parents guessing from Telegram screenshots.
What a serious government response looks like
Countries that have handled pupil-data incidents well tend to do four things quickly. They say whether personal data left the system, not only that a platform was offline. They publish the data categories in plain language parents can use. They give a window for free credit or identity monitoring when national IDs were involved. And they tell schools what to say at the gate so every headteacher is not improvising WhatsApp replies.
Uruguay’s early GURI notices covered availability. The LaPampaLeaks listing raises the privacy question those notices have not yet answered in public. That is the update families are waiting for — not another screenshot from a forum.
Technical notes for education-platform operators
GURI-style systems usually combine a family portal, a staff portal and batch jobs that sync enrolment across schools. The high-risk paths are bulk export APIs, reporting databases refreshed nightly, and contractor access for census or transport planning. If an actor can run authenticated queries that return a child’s address and class, the control failure is as much authorisation and monitoring as perimeter firewalling.
Defenders should ask: which service accounts can SELECT across all schools? Are query logs retained long enough to detect scraping? Can family-app tokens be reused from unusual ASNs? Was any “temporary” replica left exposed after a migration? Those questions are cheaper before a listing appears than during one.
For ministries that share platforms with NGOs or device programmes (Ceibal-style ecosystems), contract language should require breach notice to the education authority on the same clock as the contractor’s own regulators. Parallel outages without shared forensics are how rumour fills the gap.
If you are a parent reading this tonight
You do not need to explain APIs to your child. You need a short household rule: nobody from “the school system” will ask for a cédula photo by chat. You open GURI yourself. You call the school on the number written on last year’s noticeboard. You tell grandparents the same rule, because they are often the ones who answer the afternoon call.
If a message already quoted your child’s school and class correctly, still do not click. Correct personal detail is exactly what a leaked or partially leaked database enables. Report the message to the school and, where Uruguay provides a channel, to the computer-crime or data-protection contacts ANEP publishes for incidents.
Regional pattern: education platforms under extortion pressure
Across 2026, ransomware and data-theft crews have treated universities, career colleges and K-12 vendors as default hunting grounds because downtime creates political pressure and the records include government IDs. National pupil platforms amplify that logic: one intrusion can touch an entire birth cohort. Uruguay is not alone in running a centralised early-education system; it is simply the country with a loud August listing aimed at that system’s family and enrolment tables.
Comparisons to US district ransomware are imperfect but useful. US incidents often produce OCR or state letters with headcounts. Latin American ministry incidents more often produce outage notices first and privacy tallies later — or never. That asymmetry is why independent reporting and careful cataloguing matter. Without them, the only detailed narrative left standing is the actor’s sales page.
Parents should also remember that “unverified” can flip either way. Some education listings collapse when journalists check samples. Others harden into regulator cases months later. The actions in this article — official channels only, no cédula-by-chat, brief the household — are correct in both futures.
One more practical note for diaspora families: if your child attended Uruguayan public primary school while you lived abroad part of the year, you may still be in historical enrolment tables. Do not assume a foreign passport protects you from a GURI-shaped scam. The same rule applies — official app only, no documents by chat.
Schools can help by posting a single paragraph on the door and on the parent WhatsApp: ANEP will not ask for identity documents through messaging apps; ignore payment links; report suspicious contacts to the administration. Clarity beats rumour. A printed notice survives longer than a chat thread that scrolls away by Monday morning. If your school has not posted anything yet, ask for that paragraph — silence is what opportunistic scammers fill with fake payment links.
Canonical record
Uruguay CEIP/GURI 2026 on BreachHistory — unverified LaPampaLeaks sale/query claim (1.14M family-app rows cited); ANEP/DGEIP confirmed a prior GURI cybersecurity incident and outage.
Sources: Dark Web Informer, DGEIP notice, ANEP update, El País.
Published 2026-08-07. Labelled unverified on the data-sale volumes; will update if ANEP or Uruguay’s data-protection authority publishes an attested count or confirms exfiltration. Until then, treat every cold message about GURI as hostile.