🚨 VECERT Threat Intelligence: Samaritan API Exposes Data of Millions of Latin Americans
On August 13, 2026, cybersecurity firm VECERT Analyzer (@VECERTRadar) published a threat intelligence report warning about a cybercriminal network linked to the Samaritan API, a Data-as-a-Service infrastructure that turns leaked or compromised databases into accessible endpoints via API keys, web panels, Telegram bots, and external scripts.
According to the analysis, Samaritan is publicly associated with the LaPampaLeaks ecosystem and other collaborators involved in the acquisition, integration, commercialization, and automated distribution of large volumes of information about Latin American citizens.
🔎 What is Samaritan?
Samaritan operates as a Data-as-a-Service (DaaS) infrastructure, meaning it offers data as a product. It converts leaked, compromised, or distributed databases from underground communities into endpoints (access points) that can be queried via API keys, web panels, Telegram bots, scripts, and external tools.
The network has promoted capabilities related to:
- Identity and documents
- Addresses and phone numbers
- Telecommunications
- Vehicles
- Educational records
- Financial information
- Government databases
- Information associated with security officials
🌎 Observed Regional Expansion
Samaritan's operators have announced versions with more than 30 endpoints and 130 parameters, along with new databases, alliances, and continuous expansion to other countries. Affected countries include:
- 🇦🇷 Argentina
- 🇺🇾 Uruguay
- 🇨🇱 Chile
- 🇵🇪 Peru
- 🇨🇷 Costa Rica
- 🇻🇪 Venezuela
🕒 Infrastructure Timeline
| Date | Domain/Event |
|---|---|
| June 30, 2026 | mail.samaritan-api[.]top, www.samaritan-api[.]top, lady.samaritan-api[.]top |
| August 3, 2026 | *.samaritan-api[.]top (wildcard certificate) |
The appearance of the wildcard certificate indicates an evolution of the infrastructure with the capacity to deploy multiple subdomains and services.
⚠️ Cloudflare Does Not Fully Hide the Infrastructure
The public domain samaritan-api[.]top is protected by Cloudflare, but during technical analysis, VECERT identified an exposed and directly accessible backend/origin IP:
🔥 188.93.233[.]175
The host responds directly and exposes content related to Samaritan, including specific resources used by the frontend. Observed ports:
- 22/TCP → OpenSSH 9.6p1 / Ubuntu
- 80/TCP → Caddy HTTP Server
- 443/TCP → HTTPS
- 8080/TCP → HTTP / Samaritan Frontend
Access to 188.93.233[.]175:8080 was observed among other sources, allowing high-confidence technical correlation of the IP with Samaritan's infrastructure, despite the public Cloudflare layer.
🕸️ Cybercriminal Network
The investigation shows that Samaritan does not operate as a standalone site. VECERT observes an ecosystem of actors, providers, collaborators, and related services, where alliances, exchanges, or database incorporations are announced, along with the development of new endpoints and distribution of capabilities across different platforms.
Publicly observed activities include:
- Commercialization of access via subscription/API key
- Promotion and sale on underground forums
- Incorporation of leaked databases into a centralized API
- Automation of citizen queries
- Integration with external bots and scripts
- Collaboration with other data providers
- Distribution via Telegram and Signal
- Systematic expansion to new countries
🔴 Risk Level: CRITICAL
VECERT published the following IOCs (Indicators of Compromise):
- DOMAIN: samaritan-api[.]top
- IP: 188.93.233[.]175
- HOST: www.samaritan-api[.]top
- HOST: mail.samaritan-api[.]top
- HOST: lady.samaritan-api[.]top
- WILDCARD: *.samaritan-api[.]top
- PORTS: 22 / 80 / 443 / 8080
The exposure of personal data of Latin American citizens represents a serious threat to people's privacy and security, potentially being used for fraud, extortion, identity theft, and other crimes. Users are recommended to monitor their accounts and report any suspicious activity.
Source: VECERT Analyzer (@VECERTRadar) on X, August 13, 2026. View original post