OSINT — How a Telegram Bot Is Indexing Data on Millions of Citizens in Latin America
In recent months, a platform has emerged on Telegram, linked to a threat actor who has developed a bot capable of automating the search for…
OSINT — How a Telegram Bot Is Indexing Data on Millions of Citizens in Latin America
In recent months, a platform has emerged on Telegram, linked to a threat actor who has developed a bot capable of automating the search for personal information on citizens across several Latin American countries. Operating under the guise of an OSINT tool, the service allows users to query sensitive data derived from leaked databases, compromised government records, and other security breaches — all accessible via commands issued directly to the bot.
The system functions as a personal data search engine, where users pay for tokens or subscriptions to conduct queries regarding individuals, vehicles, or leaked records. This model transforms large-scale data leaks into an automated, commercial service, significantly lowering the technical barrier to accessing sensitive data.
CopilotLeaks’ infrastructure includes a dedicated Telegram bot, leak distribution channels, and a network of administrators and resellers who handle payments via cryptocurrency and bank transfers. Furthermore, the group has published and distributed multiple databases containing citizen data from various countries, integrating them into its query system.

Analyzer PRO: “CopilotLeaks” is composed of Spanish-speaking members — hackers currently active and recognized for attacks against countries such as Bolivia, Mexico, and Peru — including prominent defacers from each of these nations.
The actors have successfully compiled a database of leaked records — a collection in which they themselves appear as targets — and have integrated this data into their platform. Through a bot, users can visualize facial recognition data and vehicle records; this bot likely communicates via an API or a CDN that serves the corresponding images.
The response from the “CopilotLeaks” bot via Telegram reveals a vast amount of information; unlike other bots that merely provide PII, this one also includes images of faces and vehicle details.
An illegal bot — developed by an attacker likely operating from “Bolivia” and known as “ExploitBolivia” — has carried out these reconnaissance, attack, and intrusion operations.
Analyzer PRO: List of leaks associated with a username.
Analyzer PRO: “admin copilotleaks”
The perpetrator has also migrated to other usernames, such as “vulnerandolo” — an actor actively involved in attacks targeting Mexico, as well as data leaks concerning Peru and Bolivia.
This report analyzes the actor’s structure, business model, infrastructure, Indicators of Compromise (IoCs), and modus operandi regarding CopilotLeaks, demonstrating how such services are transforming data leaks into automated platforms for the exploitation of personal information.
Affected countries:
Latin America
🇧🇴 Bolivia
One of the bot’s primary targets.
The group claims to possess “the most comprehensive database in Bolivia.”
🇻🇪 Venezuela
Included in the bot’s query commands.
🇪🇨 Ecuador
Mentioned in the system documentation and commands.
🇨🇴 Colombia
Subsequently added to the bot’s database.
🇵🇦 Panama
Included in the database expansions.
🇲🇽 Mexico
Leaks related to TELCEL, Citibanamex, and identification databases have been distributed.
🇩🇴 Dominican Republic
6.1 million SQL records of citizens
50,000 Dominican national ID cards published
Up to 4.4 million national ID cards in image format available privately
A database containing millions of citizen records was published.
Subsequently, potential Indicators of Compromise (IoCs) were detected involving a domain with a .xyz extension — commonly used illicitly for forums or criminal promotional activities — which first appeared in 2025.
AnalyzerPRO : fingerprint
TTPs:
Táctica Técnica MITRE ID
Initial Access Exploit Public-Facing Application T1190
Credential Access Credentials from Password Stores T1555
Collection Data from Information Repositories T1213
Exfiltration Exfiltration Over Web Services T1567
Command & Control Application Layer Protocol T1071
Operation CopilotLeaks Timeline:
January 2026 — Database Expansion
The group announces a significant update to its database, indicating that the system now includes records from multiple countries.
Countries added to the system:
Colombia
United States
Panama
This announcement confirms that the bot was already operating as an aggregator of leaked databases on an international level, extending its reach beyond Bolivia.
February 2026 — Distribution of Massive Databases
February 2, 2026
CopilotLeaks publishes a database of citizens from the Dominican Republic.
The dataset includes:
6.1 million citizen records
4.4 million Dominican national ID numbers
This dataset is distributed partially as a sample to attract users.
February 6, 2026
The group announces an update to the query system for the `/breach` command, improving the processing of leaked databases.
A limit of 700 records per query has also been established, signaling an optimization of the search engine.
February 7, 2026
CopilotLeaks announces that it will release new databases related to Mexico, including telecommunications information and financial records.
The group also warns against vendors reselling previously released leaks.
February 15, 2026
The group shares evidence of a defacement on a Bolivian government system, along with the database obtained from the compromised system.
The objective appears to be to demonstrate the group's capability to obtain data directly from vulnerable systems.
February 16, 2026
CopilotLeaks introduces new features within the bot, including the command:
/anhb
This command allows you to query vehicle records, including:
vehicle information
photographs
official records
March 2026 — Bot Commercialization and Growth
March 1, 2026
The group announces new commercial terms for access to the CopilotInfoBot, including:
an initial access license
a quarterly maintenance fee
measures against scraping and the resale of access
This confirms that the bot operates as a commercial, subscription-based service.
March 3, 2026
CopilotLeaks reports that its infrastructure experienced an incident with its VPS provider, forcing the group to migrate its server to a new infrastructure.
The group also announces the implementation of daily backups to prevent data loss.
The analysis of CopilotLeaks demonstrates how the cybercrime ecosystem continues to evolve toward automated models of data exploitation. What previously required access to clandestine forums, advanced technical expertise, or vast volumes of leaked databases can now be accomplished through a simple interaction with a Telegram bot.
The infrastructure developed by this actor transforms massive leaks of personal information into an accessible, on-demand service, enabling any user to conduct queries regarding citizens of various countries through a system of tokens and subscriptions. This model transforms stolen data into a recurring commercial product, wherein every leak is integrated into a centralized search engine.
Furthermore, the presence of administrators, resellers, and cryptocurrency-based payment systems suggests the existence of an organized structure geared toward the continuous monetization of compromised information. The distribution of citizen databases, vehicle records, and other sensitive data highlights a significant risk to the privacy and security of millions of people across Latin America.
CopilotLeaks serves as a clear example of the transition toward “Data Exploitation as a Service” platforms, where the exploitation of data leaks ceases to be an isolated event and instead becomes a permanent infrastructure for accessing personal data.
LEGAL & ETHICAL DISCLAIMER
This report is based exclusively on publicly available information obtained through Open-Source Intelligence (OSINT). No intrusion, hacking, unauthorized system access, interception, credential harvesting, exploitation, or acquisition of private or confidential data has been performed.
All observations, indicators, infrastructure references, metadata, signals, or correlations presented in this report are derived from publicly accessible sources and must be treated as technical intelligence, not as definitive or judicial attribution.
The presence of domains, IP addresses, log patterns, underground references, or leaked information does not constitute a formal accusation or legal determination of responsibility. Attribution, motivation, and actor identity may require additional validation by competent authorities, legal entities, or digital forensics.
The content contained in this report may include potential false positives, infrastructure that later changes ownership, expired datasets, or previously exposed material. Intelligence derived from OSINT should always be corroborated and verified before any operational, legal, investigative, financial, or organizational action is taken.
The analysis provided here is strictly for educational, academic, security research, cyber risk evaluation, and threat-intelligence purposes. It must not be used for harassment, personal retaliation, unauthorized surveillance, doxing, stalking, profiling of individuals, or any unethical or illegal activity.
Vecert does not store, distribute, commercialize, or trade stolen, private, or illicit data. All data indexed, referenced, or analyzed is already publicly available at the time of research.
Any interpretation, operational decision, investigative direction, mitigation action, or use of the intelligence included in this report is performed entirely at the reader’s own responsibility. This publication does not replace formal legal advice, law-enforcement investigation, digital forensics, or compliance assessments. 메타데이터
- post_id
- c5a3670aadbb
- slug
- osint-how-a-telegram-bot-is-indexing-data-on-millions-of-citizens-in-latin-america-c5a3670aadbb
- url
- https://medium.com/@vecert/osint-how-a-telegram-bot-is-indexing-data-on-millions-of-citizens-in-latin-america-c5a3670aadbb
- canonical_url
- https://medium.com/@vecert/osint-how-a-telegram-bot-is-indexing-data-on-millions-of-citizens-in-latin-america-c5a3670aadbb
- author_url
- https://medium.com/@vecert
- status
- ok
- fetched_at
- 2026-06-12 07:40:50