Threat actor

GhostSec

GhostSec / Ghost Security is a hacktivist group linked to campaigns such as #OpVenezuela. Its activities in Venezuela include distributed denial-of-service attacks, website defacements, data leaks, and propaganda campaigns; each victim must be verified separately because much of the evidence comes from the actor itself.

Incidents
6
High impact
0
First seen
Jul 28, 2024
Latest seen
Aug 20, 2024

Linked incidents

6 incidents
Distributed denial of service

GhostSec Claims Responsibility for Attack on the Social Protection Fund for Bank Deposits (FOGADE)

On August 20, 2024, the threat actor GhostSec, operating through the X account @Wond3rGhost, claimed responsibility for a distributed denial-of-service (DDoS) attack against the Venezuelan government entity Fondo de Protección Social de los Depósitos Bancarios (FOGADE). The attack was linked to the #venezuelalibre and #OpVenezuela campaigns, rendering the fogade.gob.ve website inaccessible. It is unclear whether any data was leaked or whether there were any material losses resulting from the incident.

Fondo de Proteccion Social de los Depositos Bancarios (FOGADE)
Distributed denial of service

GhostSec Claims Responsibility for Attack on the Embassy of the Bolivarian Republic of Venezuela in Norway

In August 2024, Anonymous allegedly launched a distributed denial-of-service (DDoS) attack against the Embassy of the Bolivarian Republic of Venezuela in Norway, a government organization operating within the Venezuelan government sector. It is unclear whether any data was leaked or whether there were any material losses as a result of the incident.

Embajada de la República Bolivariana de Venezuela en Noruega
Distributed denial of service

GhostSec Claims Responsibility for Attack on the Ministry of Popular Power for Ecosocialism (MINEC)

In August 2024, GhostSec allegedly launched a distributed denial-of-service (DDoS) attack against the Ministry of Popular Power for Ecosocialism (MINEC), a government organization operating in the public sector in Venezuela. It is unclear whether any data was leaked or whether there were any material losses resulting from the incident.

Ministerio del Poder Popular para el Ecosocialismo (MINEC)
Distributed denial of service

GhostSec Claims Responsibility for Attack on the Presidential Press Office of the Bolivarian Republic of Venezuela

On August 18, 2024, the hacktivist group GhostSec—specifically through the individual known as W0nd3rGhost—carried out a distributed denial-of-service (DDoS) attack against the official website of the Venezuelan Presidential Press Office. The attack was part of the broader #OpVenezuela campaign and rendered the government’s communication platform temporarily inaccessible to the public. While the incident caused a service disruption, there were no confirmed reports of data breaches or long-term damage to the agency’s digital infrastructure.

Prensa Presidencial de la República Bolivariana de Venezuela
Distributed denial of service

GhostSec Claims Responsibility for Attack on the Decentralized Tax Administration Service of Zulia State (SEDATEZ)

On August 18, 2024, the hacktivist group GhostSec (via the X handle @Wond3rGhost) claimed responsibility for a distributed denial-of-service (DDoS) attack against the Decentralized Tax Administration Service of Zulia State (SEDATEZ). The attack, carried out as part of the #OpVenezuela campaign, reportedly took the organization’s website (sedatez.gob.ve) offline. It is unclear whether any data was compromised or whether the incident caused financial losses.

Servicio Desconcentrado de Administración Tributaria del Estado Zulia (SEDATEZ)
Service outage

GhostSec claims to have disconnected 4,097 CANTV modems via TR-069 during the June 28 elections in Venezuela

Coinciding with Election Day on July 28, 2024, in Venezuela, the hacktivist group GhostSec claimed to have exploited misconfigured modems belonging to the state-owned company CANTV, manipulating passwords, network settings, and the TR-069 remote management protocol to prevent CANTV from reconfiguring them remotely. According to the claim reported by the media, 4,097 modems were taken offline, including the Stavix MP-X421R (1,930), Huawei DG8245V-10 (1,654), ZTE F670L (414), and ZTE ZXH108N v2.5 (99) were disconnected. The group stated that its target was the state-owned company and the government, not the general public, since most users still had 4G mobile access. The figures and scope come from the group’s own statement and were not officially confirmed by CANTV.

Compañía Anónima Nacional Teléfonos de Venezuela (CANTV)