On March 20, 2025, the ransomware group Hunters listed Megacentro on its leak site and stated that internal files had been exfiltrated. The company, which appears to operate in Latin America, has not publicly disclosed the number of people whose records were taken, leaving customers, employees, and their families uncertain about what personal information may now be in attackers’ hands.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Megacentro
Get alerted the next time Megacentro files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Megacentro’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that Hunters posted proof of the breach on its dark-web leak portal, showing samples of stolen internal documents. The data was allegedly exfiltrated but not encrypted on the victim’s systems, a common ransomware tactic that allows the group to threaten both operational disruption and public exposure. No exact victim count or detailed list of exposed data types has been released by Megacentro or independent analysts. Available reporting describes the incident as a standard ransomware double-extortion case in which the attackers first demand payment to restore systems and then threaten to publish the stolen files if the ransom is not paid.
Why This Matters for You and Your Family
When a company that holds customer records, employee payroll data, or vendor contracts suffers a breach, the information often includes names, addresses, national identification numbers, contact details, and sometimes financial records. If your data was among the files taken, it can be sold or traded on underground forums within days. For ordinary families this means higher risk of identity theft, loan fraud in your name, or sudden spam and phishing calls aimed at your household. Children’s records, if included through family-linked accounts, can be especially damaging because minors often lack credit monitoring and the breach may go unnoticed for years.
The Doxxing and Identity-Chain Implications
Stolen internal files frequently contain email addresses, usernames, phone numbers, and notes that link multiple online handles to real people. Attackers and opportunistic criminals then chain these pieces together: a work email leads to a personal account, which leads to a child’s gaming username, which reveals an address or school name. This identity-chain effect turns a single breach into long-term doxxing risk. Credential leaks like this one routinely cascade into account takeovers on gaming platforms, social media, and email, giving attackers persistent access to your family’s digital life.