129636 Aires de Fiesta Argentina Breach
We noticed a significent influx of credential stuffing attempts originating from a newly identified threat actor cluster targeting a broad spectrum of Latin American entities. This pattern led us to investigate a recent leak associated with "Aires de Fiesta," an Argentine event rental and sales service. What struck us was the sheer volume of personally identifiable information (PII) exfiltrated, far exceeding typical marketing list sizes, and its subsequent dissemination on a well-established cybercrime marketplace. The timing and nature of the exposure suggest a deliberate effort to weaponize this data for further malicious activities.
The breach at Aires de Fiesta, discovered on March 6, 2025, involved a database compromise resulting in the exposure of 129,636 records. The exfiltrated data includes email addresses, first names, and last names. Further analysis revealed the presence of birthdays, genders, and physical addresses within the dataset, significently increasing the risk of identity theft and targeted social engineering attacks. The data originated from what appears to be a customer or user database, likely structured as a relational database given the comprehensive PII fields. The compromised information was found to be available for download on a prominent cybercrime forum, indicating a clear intent for monetization or distribution within illicit communities.
While specific news coverage directly detailing the Aires de Fiesta breach remains nascent, the broader trend of escalating cyberattacks targeting businesses in Argentina and across Latin America is well-documented. Threat intelligence reports from firms like Mandiant and CrowdStrike have consistently highlighted the increasing sophistication of threat actors operating in the region, often leveraging stolen PII for fraudulent activities and expanding their attack vectors. The nature of this leak, with its comprehensive PII, aligns with observed tactics of financially motivated groups seeking to build robust profiles for spear-phishing campaigns and account takeover schemes. Further OSINT investigation into the specific cybercrime forum where the data was leaked may reveal more about the actor's modus operandi and potencial future targets.
Breach Breakdown
129,636 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds