CiberLATAMbywhalemate

Uruguay SENACLAFT clarifies DDC after leak

SENACLAFT issued guidance on outsourced due diligence in Uruguay after El Observador reported a 300 GB leak from a local firm.

Whalemate Labs · AI-assisted researchPublished:2 min read

Uruguay’s SENACLAFT published a statement clarifying outsourced customer due diligence procedures under anti-money laundering compliance. The notice appeared on the government portal and in the agency’s news section, while El Observador reported a 300 GB leak from a Uruguayan law and accounting firm.

Uruguay’s SENACLAFT published an official statement on September 4 clarifying the use of customer due diligence, or DDC, procedures carried out by third parties. The notice appeared on the Uruguayan government portal and in the agency’s institutional news section. It is aimed at the regulated ecosystem and entities subject to anti-money laundering and counterterrorism financing obligations.

What did SENACLAFT clarify about outsourced due diligence?

SENACLAFT explained how DDC procedures performed by third parties can be used within the current regulatory compliance framework. The official message included a PDF with "clarifications regarding the use" of those procedures, with a focus on anti-money laundering and the prevention of terrorist financing.

The institutional post also stressed that outsourced due diligence remains the responsibility of the obligated party. In other words, even if part of the process is carried out by a third party, the regulatory framework does not shift or weaken because of that arrangement.

What happened to the Uruguayan law and accounting firm?

El Observador reported on September 8 about a hack and the leak of 300 GB of information from a Uruguayan law and accounting firm. According to that coverage, it found no evidence of exposed credentials, passwords, access keys, specific banking information, or concrete identity documents.

The report followed a notice circulated by a threat intelligence account on X, VECERTRadar, which said the actor cutzinger claimed to have exposed data from Uruguay. That report also noted that the incident remained unconfirmed independently and that there was no external technical verification of the alleged leak’s actual scope.

What is the connection between both events?

Both developments unfolded in the same regulated Uruguayan environment and put third-party handling and sensitive information back in focus. On one side, SENACLAFT reinforced through official channels how outsourced due diligence should be understood. On the other, a leak attributed to a local firm brought attention again to how data is handled in professional services that operate under compliance obligations.

Sources

View all