SAMARITAN · News English translation Source: samaritanapi.com Page 1 NEWS · OFFICIAL ENGLISH TEXT FROM THE SOURCE SITE Exposing AGESIC's futility and hypocrisy toward us Original Spanish title: Exponiendo la inutilidad y hipocresía de AGESIC contra nosotros Source page: https://samaritanapi.com/samaritan/exponiendo-la-inutilidad-y-hipocresia-de-AGESIC-contra-nosotros/ This PDF uses the article’s own English body (en) as published in the site’s bilingual data file, reproduces the original graphics, and adds an English version of the cover graphic plus captions translating Spanish labels that appear inside screenshots. Cover graphic (English version of the original poster) Original Spanish cover text: “Exponiendo la inutilidad de parásitos estatales que se dicen ‘expertos informáticos’ y ‘expertos en ciberseguridad’ [También mostramos cómo ellos venden datos de ciudadanos uruguayos].” This is an article in response to AGESIC that arose from a mistake made by a CertUY unit, which did not understand how domain registrations work; this ultimately resulted in a completely misguided legal request being sent to us due to an employee’s error. The first point is to show how useless AGESIC is. The question is... how did this legal request reach us? The reason is that they sent it to us as well... They went to WHOIS, assuming that the WHOIS privacy provider had something to do with the registrar... thinking they would contact them... so they went to the proxy contact domain generated for Samaritan Owner and sent it there, thinking it was PrivacyGuardian. @ADanielhilll SAMARITAN · News English translation Source: samaritanapi.com Page 2 Figure 1 — CERTuy abuse ticket vs. WHOIS / PrivacyGuardian record Original filename: estupides-gubernamental.png. The email and WHOIS panel are already in English. Orange arrows mark that CERTuy copied a PrivacyGuardian proxy address and also sent the message to an unrelated mailbox. These are the IT “experts” who are responsible for Uruguay’s cybersecurity and manage technology for the Uruguayan government... They don’t know the basics about WHOIS records and the domain registrant’s proxy contact... This is clearly a serious mistake given what the email reveals and requests. This happened on August 6 during a futile attempt to shut down the operation from Uruguay, since the website promoting the service is not the service itself. The service is not hosted here; it is merely the public interface. Therefore, there is nothing illegal about our service’s public websites. Figure 2 — Message headers of the CERTuy notice Original filename: registros-mx.png. The blue underline highlights the Message-Id domain correo.agesic.gub.uy. The person who sent this email was an employee named Matias Scarone, but he isn’t the only one responsible—he doesn’t answer to the entire public agency. Someone higher up at AGESIC ordered the cybersecurity team to take action against Samaritan, and all those people fully approved sending the email by mistake, lol. But the absurdity of this public agency doesn’t end there... AGESIC cited “Law No. 20,327” [Cybercrime Law] and Law No. 18,331—the data protection law—as references, even @ADanielhilll SAMARITAN · News English translation Source: samaritanapi.com Page 3 though the company they’re sending this to isn’t even in the same country or on the same continent. Figure 3 — Legal citations in the CERTuy notice Original filename: definitivamente-cine.png. Source text is already in English. Obvious mistakes made by these incompetent public officials: • Attempting to file a complaint based on Uruguayan laws in a clearly international context involving a private company • Referring to alleged violations of laws related to government databases when it is the domain registrar—and not the server provider where Samaritan is actually hosted—that is at issue, rather than a simple website • Attempting to take legal action against a static, promotional website that does not host any databases or services—it is simply a landing page with a blog section about a specific service Unhappy with all these errors, they began to make requests: Not content with presenting information in a completely incorrect context, they began demanding action against “samaritan-api.top” and that every account record—such as phone numbers, email addresses, IP addresses, and other data—be saved. Among many other demands, they acted as if they had any authority whatsoever, without even mentioning that the service AGESIC was reporting on isn’t even there. @ADanielhilll SAMARITAN · News English translation Source: samaritanapi.com Page 4 Figure 4 — “Requested actions” section of the CERTuy notice Original filename on the source site used a slur; the image content is the English list of eight demands sent to NameSilo / PrivacyGuardian. And to top off their idiocy, they mention that everything should be saved in anticipation of a valid request from Uruguayan authorities—even though there is no valid court order from any judge, prosecutor, or law enforcement official in Uruguay to order anything from a company that isn’t even on the same continent. For a valid request, international cooperation is required from a valid authority in the country of the company from which data or actions are being requested—not to mention that we didn’t even violate the terms of service because it’s the domain and not the hosting service, and not to mention that this is a static landing page and not the service itself, you bunch of morons. Figure 5 — Signature block of the CERTuy email Original filename: bocaboca.png. English rendering of on-image text: Matias Scarone — Cybersecurity Operations Center — Tel: (+5982) 1502378 — Montevideo, Uruguay — gub.uy/certuy — gub.uy/agesic The AGESIC representative who sent the email was Matias Scarone. He’s the one to blame for accidentally sending the email to LaPampaLeaks... This person is clearly not only incompetent at his job (like most CertUY employees), but he also has terrible opsec and has been fully identified by us, along with his entire online history. @ADanielhilll SAMARITAN · News English translation Source: samaritanapi.com Page 5 Exposing a government parasite who claims to be an IT specialist Figure 6 — Source investigation board (identity / employment linkage) English rendering of on-image text: Panel labels in the original graphic: “Satellite image of the residence”; “Citizen data from DNIC” (document number, given names, surnames, sex, date of birth, department, current age); “Email sent by AGESIC”; “Employee name: Matias Scarone”; “Investigation note” (search of the National Civil Identification Directorate database for people who attended UTU named Matías Scarone returned two citizens); “Filtering to find the correct person”; “Samaritan — UTU educational history”; “Confirmed ID: 50449175”; LinkedIn account and profile capture; YOUNOW account fields (name, email, username, IP, IP location, ISP). We will expose this person here using a Maltego-style investigation toolkit that will be operational in an upcoming Samaritan update. Matias Scarone, better known as Matias Javier Scarone Calvo, born on 08/28/2000, is 25 years old and lives in Montevideo, in the Centro neighborhood. This data comes from using the Samaritan API to search for this individual, along with other verification methods such as data breaches and OSINT. The personal information comes from government databases that AGESIC, through CertUY, should have protected from hacking. @ADanielhilll SAMARITAN · News English translation Source: samaritanapi.com Page 6 Figure 7 — Source investigation board (account / breach correlation) English rendering of on-image text: Recurring field labels: username, email, password hash, password, IP address, IP location. Notes on the board: Note on XSPLIT.COM breaches -- the AGESIC employee appears in 2 breaches of the same website; with this we found 2 user accounts with different email addresses. 2 Taringa profiles [Taringa.net data breach]. Investigation note -- he uses the same password on his main email and the second username mentions his first and last name. Google Maps capture. MySpace profile. Just by tracing the email’s digital footprint, you can see how this “cybersecurity expert” reuses his passwords—with “carbonero28” being the one he consistently used—and leaves his Google Maps reviews public, allowing anyone to create a map based on his location history. Not only that, but this person was using the username “Matiasscar28.” By trying that same password on an account for a shady forum about unlocking and rooting phones, we were able to log in easily. Clearly, this “cybersecurity expert” has very poor opsec. @ADanielhilll SAMARITAN · News English translation Source: samaritanapi.com Page 7 Figure 8 — Still from the original video (multimedia/jjjj.mp4) The source article embeds a video of a forum profile. This frame shows the public profile page. English rendering of on-image text: Header: Quick links / FAQ / Donate / Notifications / Private messages. Title: “Viewing profile — Matiasscar28”. Username, rank “Novice”, flag Uruguay, group “Newly Registered Users”. Contact / user statistics: registered 3 Sep 2019; last active 23 Aug 2026; 1 total message; most active forum/topic related to “Root”. Then people are surprised by hacks targeting the Uruguayan government—or that the three waves of hacking scandals in Uruguay were all caused by the same person... This is what happens when those tasked with protection are nothing more than state parasites who know just enough about computer science to get by but have a fancy degree. Imagine that we found this just by looking into one person—imagine all the employees at AGESIC’s CertUY... it’s pathetic and sad. AGESIC’s Sale of Data to Private Entities AGESIC has been selling citizens’ data since before Samaritan even existed; it has an entire system for selling data to private entities based on APIs from public agencies like the DNIC. It’s very similar to Samaritan, but instead of Telegram bots, the clients are private companies. @ADanielhilll SAMARITAN · News English translation Source: samaritanapi.com Page 8 Figure 9 — Interoperability Platform collage (original graphic, Spanish UI) Original filename: loles.png. English rendering of on-image text: Decree No. 71/025 of 25 February 2025 regulates articles 31 of Law 18.600 and 159 of Law 18.719 on AGESIC’s authority to enable private entities to consume services that public entities make available through the Interoperability Platform. Source: presidencia.gub.uy legal PDF. Center: AGESIC “Interoperability Platform” page and list of attached public agencies (DGI, Customs, Fire Department, DNIC, Scientific Police, etc.). Right: “Chapter I: Access to the Interoperability Platform by private parties” (Articles 2–3) and “Chapter II: Digital identification mechanisms” (Article 4). Callout: “AGESIC developed an API for querying citizen data for the State for public agencies, then enabled by decree that this service may be provided to private companies.” Example card: “digital ID-card service — filiation data and photo of the ID card.” Example of what AGESIC can provide from the DNIC @ADanielhilll SAMARITAN · News English translation Source: samaritanapi.com Page 9 Figure 10 — Interoperability catalog page for DNIC Original filename: dnic.png. English rendering of on-image text: Title: “National Civil Identification Directorate”. Catalog entries: “Live-birth certificate” — online service with the Ministry of Public Health to issue birth certificates nationwide. “Basic information service” — query filiation data associated with an ID-card number and view the web version. “Digital ID-card service” — query filiation data of an ID card and its image, for the purpose of verifying a document. Sidebar lists other agencies on the catalog (Electoral Court, DIGEFE, Official Printing Office, Cadastre, State Procurement Regulator, Internal Audit, social-security bank, etc.). A real-world example of all this is informes.com.uy, which can provide property ownership history data for an address and other information aimed at real estate companies. When you go to the “About Us” section, it mentions an AGESIC PDF that refers to what we discussed earlier. @ADanielhilll SAMARITAN · News English translation Source: samaritanapi.com Page 10 Figure 11 — informes.com.uy “About us” vs. AGESIC Open Data License Original filename: agesic.png. English rendering of on-image text: Left (“Open Data Sources” on informes.com.uy): public data on the platform come from Uruguay Open Data and are licensed under the Uruguay Open Data License Version 0.1, which allows commercial and non-commercial use, including reproduction, distribution, publication, translation, adaptation and transformation, and combination with own or third-party data. Right (AGESIC PDF “Uruguay Open Data License — Version 0.1”): Authorization — open data and metadata may, for commercial and non-commercial use, be assigned, reproduced, distributed, published, translated, adapted, transformed, communicated or made available to the public by any means; merged with own or third-party data; and integrated into business processes, products and applications, internal and external, on public and private electronic networks. Sources cited for this: • The private company’s website: https://informes.com.uy • https://www.gub.uy/agencia-gobierno-electronico-sociedad-informacion-conocimiento/tematica/ catalogo-plataforma-interoperabilidad This is the last we’ll say about AGESIC... They’re a bunch of shameless hypocrites and parasites of the Uruguayan government who, while claiming to protect Uruguay’s cybersecurity [which they clearly aren’t doing very well...], are secretly selling citizens’ data behind the scenes while persecuting us for doing exactly the same thing. Why? Because we don’t give the government money to sell citizens’ data. In the end, the problem isn’t selling data; the problem is that we don’t ask the Uruguayan government for authorization or pay it for it—since, deep down, we aren’t all that different. Although I suppose the fact that we’ve been pointing out since early 2025 that there’s clearly no one competent at AGESIC is a big part of the problem. Translator’s note: Body text is the site’s own English version (blogPosts[].body.en), not a re-translation. Cover art was redrawn in English to match the original Spanish poster. Screenshots of official English emails were kept as-is. Screenshots whose interface is in Spanish are reproduced unchanged, with an English rendering of the visible labels immediately underneath. The embedded video was replaced by a representative still frame. This PDF documents a third-party publication; it is not an official AGESIC document. @ADanielhilll