Threat actor

Actor desconocido

No trusted actor was identified for this claim. The previously captured value is considered an interface artifact or the result of automated extraction, not a confirmed alias.

Incidents
49
High impact
8
First seen
Feb 11, 2016
Latest seen
Jan 5, 2026

Linked incidents

49 incidents
unauthorised financial transaction

Funds Stolen from Kontigo: Over 340,000 USDC Stolen from User Accounts

Kontigo, a financial services platform for digital assets focused on Venezuelan users, suffered an unauthorized access incident in early January 2026, resulting in the theft of 340,905.28 USDC from 1,005 user accounts. The company isolated the affected systems, activated security protocols, and reimbursed 100% of the stolen funds to the affected users. This was a theft/exploitation of funds, not a data breach; the attack vector was not disclosed.

Kontigo
destructive malware wiper

Destructive 'Lotus' wiper attack hits PDVSA and the Venezuelan energy sector

On December 15, 2025, Petróleos de Venezuela (PDVSA) reported a cyberattack aimed at disrupting its operations, which affected its administrative systems and temporarily interrupted the delivery of oil shipments, forcing staff to resort to manual record-keeping. Kaspersky linked the incident to a previously unknown destructive malware dubbed “Lotus,” which deletes recovery mechanisms, overwrites physical disks, and deletes files, rendering the computers irrecoverable; samples were uploaded from Venezuela in mid-December and referenced pdvsa.com. PDVSA blamed the United States and “stateless actors,” an accusation that neither Washington confirmed nor security researchers supported with technical evidence.

Petróleos de Venezuela, S.A. (PDVSA)
Leak of confidential information

Unattributed claim regarding an alleged database of Venezuelan citizens

On December 12, 2025, a LeakBase URL was indexed in connection with a claim regarding an alleged database containing personal information on 14 million Venezuelan citizens. The alleged data reportedly included national ID numbers, types of identification, first names, last names, and gender. The original thread is no longer available following the seizure of LeakBase in March 2026; no independent corroboration was found from media outlets, NGOs, security firms, or breach trackers, and the value previously stored as an alias is considered an interface artifact or scraping error.

Conjunto de datos de ciudadanos venezolanos (origen no identificado)
unauthorised financial transaction

Cyberattack on the Montalbán Mayor’s Office Bank Account

In August 2025, the Montalbán City Hall in Carabobo, Venezuela, suffered a cyberattack targeting its official bank account. The breach resulted in the unauthorized withdrawal of municipal funds. Mayor José Alí Soto León confirmed the incident in an official statement and noted that the State Attorney General’s Office had launched an investigation.

Alcaldía de Montalbán
Leak of confidential information

Claim of an attack against Venezuela’s Bolivarian National Police (PNB) (perpetrator unconfirmed)

On January 25, 2025, an unauthorized access incident was reported involving the systems of Venezuela’s Bolivarian National Police (PNB) (perpetrator unconfirmed). The breach involved the compromise of institutional email accounts and the subsequent leak of credentials from a webmail portal. In addition, it was reported that a compressed file named “policianacionalbolivariana.rar” was distributed, containing internal documents and confidential email communications, which could expose personal information such as staff members’ names and email addresses.

Cuerpo de Policía Nacional Bolivariana (CPNB)
Distributed denial of service

Comando Con Venezuela denounces massive attacks (more than 44 million) against the website “Resultados con Vzla,” which published the election results from June 28

Comando Con Venezuela reported that it had mitigated more than 44 million attacks in 24 hours against resultadosconvzla.com while receiving more than 32 million requests. Several media outlets have reported on the claim. Separately, VE sin Filtro documented the blocking of the site by Venezuelan providers via DNS/HTTP(S).

Comando Con Venezuela (resultadosconvzla.com)
Distributed denial of service

IPYS Records a DoS/DDoS Attack Against Sandy Aveledo's Website in 2023

IPYS Venezuela included journalist Sandy Aveledo’s website among the sites that were taken offline following DoS/DDoS attacks in 2023. No independent public alert with an exact date was found during the review; therefore, the record is partially verified and dated only by the publication of the annual report.

Sandy Aveledo
Distributed denial of service

IPYS records a DoS/DDoS attack against “Portuguesa al Día” in 2023

IPYS Venezuela included Portuguesa al Dia among the websites that were offline following DoS/DDoS attacks in 2023. No independent public alert with an exact date was found during the review, so the record is partially verified and dated only by the publication of the annual report.

Portuguesa al Dia
Distributed denial of service

La Gran Aldea Suffers a DDoS Attack Between November 23 and 25, 2023

From shortly after noon on November 23 until the afternoon of November 25, 2023, La Gran Aldea suffered a DDoS attack involving automated requests targeting specific articles. The website slowed down, and two articles became inaccessible.

La Gran Aldea
Distributed denial of service

"Fake News Hunters" Suffers Second DDoS Attack in a Week

On September 14, 2023, Cazadores de Fake News suffered a DDoS attack that temporarily rendered its website inaccessible. Espacio Público reported that this was the second attack in less than a week, following the publication of fact-check articles on political disinformation.

Cazadores de Fake News
Phishing

Venezuelan media outlets are being impersonated on WhatsApp to request verification codes

Between July 21 and August 16, 2023, unidentified individuals used the brand identities of Red Digital Noticias, Correo del Caroni, Radio Fe y Alegria Noticias, and Que Pasa En Venezuela on WhatsApp to contact readers or members of broadcast groups and request verification codes. The source has not confirmed that any accounts were compromised.

Correo del Caroni
Phishing

El Nacional Warns of Fake Calls Asking for WhatsApp Codes

On June 12, 2023, El Nacional issued a warning stating that it does not call users to request WhatsApp activation codes, in response to phishing attempts aimed at stealing accounts.

El Nacional
Phishing

Unknown individuals are impersonating El Pitazo to ask readers for their WhatsApp codes

Between May 26 and June 6, 2023, unknown individuals impersonated El Pitazo on WhatsApp to call readers and ask for verification codes, a tactic aimed at hijacking accounts.

El Pitazo
Distributed denial of service

Aporrea.org reports a DDoS attack against its website in May 2023

On May 7, 2023, Aporrea reported a DDoS attack against aporrea.org, with the attack resuming on May 8 after a temporary pause. Public records and subsequent annual reports document the case as part of the digital attacks of 2023.

Aporrea.org
brand or domain impersonation

Panorama Newspaper Reports Identity Theft on Its Website

In May 2023, Diario Panorama reported an identity theft incident associated with its website domain. IPYS/Voces del Sur documented activity observed on January 2, February 10, and between March 13 and May 15, with a public report filed on May 3 and service availability affected on May 9.

Diario Panorama
impersonation or false copyright complaint

El Nacional and QPEV Face Restrictions Following a False Report Sent Using Roberto Deniz’s Identity

Between March 4 and 6, 2023, Que Pasa En Venezuela and El Nacional faced temporary restrictions following a false report of plagiarism or copyright infringement sent from an account impersonating journalist Roberto Deniz. No theft of credentials, data breach, or compromise of Deniz’s accounts was reported.

El Nacional
Unprivileged account compromise

Hack of the Palpitar Trujillano Instagram account and blocking of the Noticia y Punto website (December 2022)

In December 2022, the Instagram account of the Venezuelan media outlet Palpitar Trujillano (with more than 100,000 followers), which covers Trujillo, Mérida, and Zulia, suffered four cyberattacks and suspensions: Meta suspended the original account on December 10 following reports from third parties, and the alternate accounts created afterward were hacked or deleted on December 15, 20, and 25, as documented by IPYS Venezuela and Espacio Público. The outlet’s director, Andrés Briceño Sulbarán, described the incidents as sabotage against freedom of expression and filed a complaint with the CICPC in Valera; those responsible remain unidentified. Meanwhile, the website of the Zulia-based media outlet Noticia y Punto (noticiaypunto.com) has been blocked since December 22 by the providers Cantv, Digitel, and Movistar—a block verified by IPYS using OONI’s DNS methodology. The type of verifiable incident in the case of Palpitar Trujillano corresponds to an “account takeover.”

Noticia y Punto
Unprivileged account compromise

NFT scammers hijack the IVSS Twitter account to promote the fake 'GoblinTown' collection

On July 5, 2022, Venezuela’s Independence Day, the official Twitter account of the Venezuelan Institute of Social Security (@ivssoficial, with approximately 284,000 followers) was compromised by attackers who posted a fake offer of free NFTs from the “GlobinTowm” collection (a knockoff of the real Goblin.Town collection). The links were designed to steal credentials, cryptocurrency funds, and user data. The IVSS warned its followers not to click on the links and migrated to a new account (@Somosivss). This was the second incident in less than a month following the same pattern, after the hijacking of the El Universal newspaper’s account.

Instituto Venezolano de los Seguros Sociales (IVSS)
Unprivileged account compromise

El Universal's Twitter account is hacked to promote a 'Goblintown' NFT scam

On June 4, 2022, the verified Twitter account of the Venezuelan newspaper El Universal (with over 5 million followers) was hijacked and renamed “goblintown.wtf.” The attackers altered the bio and profile pictures and posted fraudulent tweets promising an airdrop of 10,000 “Goblins,” linking to a phishing site designed to drain victims’ cryptocurrency wallets. IPYS Venezuela issued an alert, and the newspaper’s technical team began the recovery process with Twitter.

El Universal
banking platform outage or service disruption

Massive Cyberattack Against Banco de Venezuela, S.A. (September 2021)

In mid-September 2021, Banco de Venezuela suffered a massive cyberattack that severely disrupted its financial services and online platform for several days. Although the Venezuelan government officially characterized the incident as a “terrorist attack” and a “massive hack” intended to tamper with banking data and sabotage the economy, the specific threat actor and the exact nature of the attack—such as whether ransomware was deployed or data was exfiltrated—remain unverified.

Banco de Venezuela, S.A.
Distributed denial of service

DDoS Attack Against the Venezuelan News Site La Gran Aldea (September 10–12, 2020)

The independent Venezuelan news site La Gran Aldea (lagranaldea.com) was hit by a distributed denial-of-service (DDoS) attack that prevented readers from accessing the site organically starting at noon on Thursday, September 10, and continued through Saturday, September 12, 2020, leaving it virtually offline for nearly two days. According to the outlet’s technical team and its director, Alejandro Hernández, most of the requests originated from Venezuelan IP addresses, and the spam traffic peaked at 700 visits per minute. The outlet reported slow loading times and the inability to access two articles that were specifically targeted (one about Gustavo Perdomo, CEO of Globovisión, and another about Jorge Giménez Ochoa, president of the Venezuelan Soccer Federation). IPYS Venezuela condemned the attack. No specific perpetrator was publicly identified.

La Gran Aldea
Distributed denial of service

El Diario (elDiario.com) Suffers DDoS Attack That Left Its Website Offline for Three Hours

On July 26, 2020, the independent Venezuelan news portal El Diario (elDiario.com) suffered a distributed denial-of-service (DDoS) attack that rendered its website inaccessible for approximately three hours. According to the outlet’s own report, in less than an hour it received more than 18 million requests to access its homepage, with a single IP address sending half a million requests, originating primarily from Russia, China, and Nigeria. The outlet framed the incident as part of a pattern of DDoS attacks used as a mechanism of censorship against the independent press in Venezuela.

El Diario (elDiario.com)
website outage or take down

An attack took down the website sebastianasinsecretos.com, run by Venezuelan journalist Sebastiana Barráez

According to Freedom House’s 2019 Freedom on the Net report, Venezuelan independent journalist Sebastiana Barráez created her own website, sebastianasinsecretos.com, to circumvent the blockade imposed in Venezuela against the news outlet Infobae. That site was targeted in two attacks during 2019. One of these attacks took the site offline after it republished an article about threats made by the armed group ELN against the May 1 march called for by Juan Guaidó—an article originally published on Infobae on April 25, 2019. Despite the attacks, the journalist continued to publish on other platforms.

Sebastiana Barráez (periodista, Punto de Corte)
national power outage disputed cyberattack claim

March 2019 Nationwide Blackout: Maduro Denounces an Alleged Cyberattack on the El Guri Dam and the Corpoelec Control Center

On March 7, 2019, the largest power outage in Venezuela’s history began, leaving most of the country (affecting all 23 states and the Capital District) without electricity for several days. The government of Nicolás Maduro publicly denounced an alleged “cyberattack” against the computer system of the Simón Bolívar Hydroelectric Plant (El Guri Dam) and Corpoelec’s “electronic brain” in Caracas, attributing it to the United States and the Venezuelan opposition. The claim of a cyberattack is disputed and was not proven: experts and electrical engineers pointed out that the facilities do not use the internet and cannot be hacked remotely, and attributed the blackout to a lack of maintenance, a wildfire that damaged transmission lines from El Guri, corruption, and the brain drain of technical talent. The U.S. denied any responsibility, and no technical evidence of the attack was presented.

Corporación Eléctrica Nacional (CORPOELEC)
Distributed denial of service

Massive DDoS Attack Takes the Investigative Journalism Website Armando.info Offline (March 2019)

The Venezuelan investigative journalism website Armando.info suffered a denial-of-service (DDoS) attack that rendered it virtually inaccessible. On March 3, 2019, co-founder and co-editor Ewald Scharfenberg reported via Twitter that, since March 2, the site had been under a “massive cyberattack” that prevented it from staying online, forcing the outlet to publish its content through Facebook and partner outlets such as La Patilla. According to IPYS Venezuela’s annual digital rights report (reproduced by El Nacional), attacks on the Armando.info server had been recorded since February 2019; the most intense episode occurred on March 2, beginning at 9 p.m. on Saturday and lasting all night until Sunday morning, directed primarily from Russia and reaching up to 9 million requests to the server in a single hour. The attack is part of a coordinated offensive against independent Venezuelan media outlets: on March 4, the websites Efecto Cocuyo, El Pitazo, and El Cooperante were also taken offline by attacks on their servers (confirmed by IPYS Venezuela, Venezuela Sin Filtro, and NetBlocks), alongside blocks of Twitter and SoundCloud by CANTV. Armando.info had been a recurring target of cyberattacks after exposing corruption in the state-run CLAP food program and conducting other investigations.

Armando.info
website defacement

Unidentified individual defaces the facades of Venezuelan embassies housed by the Ministry of Foreign Affairs

On February 7, 2019, Venezuelan embassy websites hosted on the Ministry of Foreign Affairs/MPPRE’s infrastructure published false statements of support for Juan Guaidó. Sources cite eleven affected countries, using phrases such as “at least ten” or “more than ten”: Argentina, Mexico, Brazil, Colombia, Russia, Canada, Uruguay, Guatemala, Italy, Egypt, and Costa Rica. The evidence points to a shared compromise of the MPPRE’s infrastructure, not to eleven separate intrusions targeting different embassies. No credible claim of responsibility from a specific actor was found.

Ministerio del Poder Popular para Relaciones Exteriores (MPPRE) — embajadas de Venezuela en el exterior
Unprivileged account compromise

Journalist Sebastiana Barráez’s Twitter account was hacked after she reported torture at the Dgcim

On September 27, 2018, Venezuelan journalist Sebastiana Barráez, who specializes in military affairs, reported that her Twitter account @SebastianaB had been hacked shortly after she published an article on the Punto de Corte website about the mistreatment and torture of military personnel detained at the headquarters of the General Directorate of Military Counterintelligence (Dgcim) in Boleíta, Caracas. After losing control of her account, the journalist created a new profile (@SebastianaSin). The incident was interpreted by press organizations as retaliation linked to her investigative work.

Sebastiana Barráez (periodista, Punto de Corte)
website outage or take down

Attack Takes the Punto de Corte Website Offline After It Published an Interview with Luisa Ortega Díaz (July 2018)

On July 11, 2018, shortly after publishing an interview by journalist Sebastiana Barráez with former Attorney General Luisa Ortega Díaz, the Venezuelan news website Punto de Corte, led by political scientist Nicmer Evans, suffered an attack that crashed its platform and took it offline, preventing readers from accessing it. According to a technical analysis conducted by the NGO Espacio Público, the attack involved unauthorized access from several servers operating in parallel, with the apparent aim of mass file encryption, which forced the website to migrate to a new server. Evans noted that in the earlier months of 2018, there had already been attempts to sabotage the site (February 22, April 26, and June 2). Press freedom organizations framed the incident as part of a pattern of censorship and blocking of digital media in Venezuela. The perpetrator of the attack was not publicly identified.

Punto de Corte
Distributed denial of service

DDoS Attacks Against the El Pitazo News Portal Involving More Than 1,800 IP Addresses (June–July 2018)

The Venezuelan news website El Pitazo suffered distributed denial-of-service (DDoS) attacks in late June and early July 2018, amid blockades of its domains by internet service providers in Venezuela. According to Espacio Público, during an incident that occurred between 8:50 p.m. on Friday and 6:40 a.m. on Saturday, more than 1,800 different IP addresses simultaneously attempted to access the server to overload it, targeting the three domains the outlet used to circumvent censorship (elpitazo.com, elpitazo.info, and elpitazo.ml). The outlet’s technical team managed to contain the attack, and the website continued to publish content via social media. The traffic attributed to Germany, Brazil, Poland, and the United States that is circulating on El Pitazo corresponds to a separate, later attack (November 2018), not to the June–July 2018 incident.

El Pitazo
Distributed denial of service

Cyberattack (DDoS) against the Vendata website, the open data platform of IPYS and Transparencia Venezuela

On May 8, 2018, the website of the civil society organization Vendata (vendata.org)—an open data platform created by the Venezuelan Institute for Press and Society (IPYS) and Transparencia Venezuela, the Venezuelan chapter of Transparency International—was the target of a cyberattack. According to error logs, the attack originated from multiple compromised computers that affected vendata.org and the Blue Host server where the data was hosted. Espacio Público and IPYS described it as a denial-of-service (DDoS) attack, which involves sending thousands of simultaneous connection requests to the same IP address to crash the website, forcing administrators to block and shut down the server. Those responsible were not identified. The incident occurred amid government smear campaigns against Transparencia Venezuela, which the Presidency has labeled a “subversive organization” funded by the U.S.

Vendata (IPYS / Transparencia Venezuela)
website outage or take down

A cyberattack on Runrunes’ server caused its website to go down (March 2018)

Starting on Saturday, March 3, 2018, the Venezuelan investigative journalism website Runrunes (Runrun.es) reported that its server was under a cyberattack that caused its website to go down. On March 5, via its Twitter account, the outlet announced that its servers had been under attack since Saturday and that, despite the censorship, it would continue to report via Twitter and Facebook. The case was documented by the NGO Espacio Público (article published on March 6, 2018). This incident is distinct from the denial-of-service attacks that Runrunes suffered later in May 2019 and December 2021.

Runrunes
website outage or take down

Cartoonist Rayma Suprani’s website hacked after she published a cartoon about the Óscar Pérez case

On January 27, 2018, Venezuelan cartoonist Rayma Suprani reported via Twitter that her website had been hacked, stating, “Our website was hacked; I think they didn’t like today’s cartoon. We’re working to get it back online.” She attributed the attack to a cartoon she published that same day depicting the villa in El Junquito where Óscar Pérez, a former CICPC official, died on January 15 along with several colleagues during a military operation; in the illustration, the villa was depicted with a red flag bearing the image of President Nicolás Maduro and the slogan “vote.” The incident was reported by Venezuelan media outlets (TalCual and Maduradas). The perpetrator of the attack was not publicly identified, nor was any technical impact documented beyond the temporary takedown of the site.

Rayma Suprani
Unprivileged account compromise

Hack of the social media accounts of the Venezuelan National Assembly and Capitolio TV

On January 15, 2018, the Twitter and Instagram accounts and the YouTube channel of the Venezuelan National Assembly, as well as its parliamentary channel Capitolio TV, were compromised and fell out of the Assembly’s control. The hijacking of the accounts prevented the live broadcast of legislative sessions, affecting some 121,000 YouTube subscribers and more than 11,000 Twitter followers. The media outlet’s management announced that they would provide updates on alternative channels while resolving the issue. No specific perpetrator was publicly identified; the incident occurred amid ongoing pressure against the opposition-controlled Parliament.

Asamblea Nacional de Venezuela
telecommunications service outage

Cyberattack Leaves 7 Million Movilnet Users Without Mobile Service and Causes Nine Fiber-Optic Outages in Venezuela

In August 2017, amid a wave of attacks against Venezuelan government websites, an incident affected the GSM platform of the state-owned carrier Movilnet on Wednesday, August 9, cutting off communication for 7 of its 13 million users. Authorities also reported nine outages in the country’s fiber-optic network that disrupted internet access in seven states. The Minister of Science and Technology, Hugbel Roa, described the events as “terrorist acts” and attributed them to the collaboration of “foreign agents” seeking to disrupt the country’s connectivity; security agencies launched an investigation. The hacktivist group The Binary Guardians claimed responsibility for the wave of attacks against government websites during those days, although their specific involvement in the Movilnet outage and the fiber-optic cuts has not been independently confirmed.

Telecomunicaciones Movilnet, C.A.
website outage or take down

Cyberattacks against the website of the human rights NGO COFAVIC (December 2016 and March 2017)

On March 20, 2017, the website of the Venezuelan human rights organization COFAVIC (Committee of Relatives of Victims of the Events of February–March 1989) was compromised, preventing its staff from accessing and managing the platform for approximately four hours, until access was restored with the help of cybersecurity experts. The attack coincided with COFAVIC’s participation in the 161st session of the Inter-American Commission on Human Rights (IACHR) and was part of a wave of attacks against Venezuelan NGO and media websites between March 7 and 20, 2017. A similar incident had previously affected COFAVIC’s website on December 20, 2016, allegedly in retaliation for a December 9 report on murders in the states of Sucre and Miranda. Front Line Defenders and PROVEA linked the attacks to the organization’s human rights advocacy work. The perpetrator was not publicly identified.

COFAVIC (Comité de Familiares de Víctimas de los Sucesos de Febrero-Marzo de 1989)
website outage or take down

Correo del Caroni Takes Its Website Offline Following a Cyberattack

Between March 10 and 11, 2017, Correo del Caroni took its website offline following a cyberattack to protect its information. El Pitazo and Efecto Cocuyo reported that the site remained offline after approximately 17 hours.

Correo del Caroni
website outage or take down

Hack of the Venezuelan Episcopal Conference’s website

On March 10, 2017, the Venezuelan Episcopal Conference reported that its website had been hacked and that its technical team was working to restore it. The incident occurred during the same week as attacks against Venezuelan media outlets and organizations, but it is recorded as a separate incident based on the victim and date.

Conferencia Episcopal Venezolana (CEV)
website outage with public content loss

Accion Solidaria Loses Content and Goes Offline After a Web Attack

On March 9, 2017, Accion Solidaria suffered an attack on its website; PROVEA reported a loss of published content and that the site remained offline as of its March 15 report. This is classified as a service disruption with possible destructive compromise, not as a confirmed DDoS attack.

Accion Solidaria
Distributed denial of service

El Pitazo suffers a DDoS attack and is inaccessible for about 17 hours

On March 9, 2017, El Pitazo suffered a DDoS attack following an initial phase of deindexing or preventive blocking, and its website was inaccessible for approximately 17 hours. Sources describe it as one of the clearest cases of a DDoS attack amid the wave of attacks against Venezuelan media outlets and organizations.

El Pitazo
Distributed denial of service

PROVEA Suffers a DDoS Attack Attempt and Is Offline for About 30 Minutes

On March 9, 2017, PROVEA reported an attack on its web platform that took it offline for about 30 minutes. Subsequent reports by the IACHR/OAS classify it as a DDoS attack, while contemporary sources cautiously describe it as an attempted cyberattack.

PROVEA
website compromise or malicious redirection

Caraota Digital Goes Offline for More Than 12 Hours Due to a Web Attack

On March 8, 2017, Caraota Digital suffered attacks against its website: one redirected users to a sales page, and another took the site offline for about 12 to 13 hours. Sources place this within a wave of attacks against Venezuelan media outlets and NGOs, but the technique used is not a “clean” DDoS; it is classified as a service disruption due to compromise or a web attack.

Caraota Digital
Distributed denial of service

Aporrea.org suffers a prolonged DDoS attack that leaves it inaccessible for several days (February 2017)

The Venezuelan news website Aporrea.org suffered a distributed denial-of-service (DDoS) attack that began on February 16, 2017, and kept it totally or partially offline for about a week, until service was restored around February 22. According to the outlet itself, the attack generated a flood of traffic—up to 17 million network packets per second—from a wide variety of sources, which overwhelmed its network and prevented users from accessing the site. Administrators detected sources of the attack in Venezuela, the United States, Brazil, China, and a European country, and had to migrate to another server and hire a network protection service to get back online. The perpetrator was not identified; Aporrea attributed the attack to attempts to silence its critical editorial stance. Note: The mention of “17 million megabytes per second” is not supported by the sources, which refer to 17 million packets per second.

Aporrea.org
Distributed denial of service

The El Cambur news portal went offline due to repeated attacks on its servers

Between January 30 and February 3, 2017, the Venezuelan online news portal El Cambur suffered repeated and massive attacks on its main servers, which took its website offline for about two days. According to its administrator, Rodolfo Rico, who spoke with IPYS Venezuela, this was the third time the site had been attacked in this manner, and on this occasion, the attack damaged the proxy system that generated the images linked to posts on its official Twitter account for several weeks. IPYS Venezuela recorded it as one of five cyberattacks in 2017 that limited access to or compromised the security of web platforms in Venezuela, as part of a wave of attacks against critical media outlets attributed by press organizations to alleged pro-government actors. The administrator was unable to determine the origin of the attacking IP addresses, as they were masked using a VPN.

El Cambur
Distributed denial of service

DDoS attack against CANTV links targeting a PDVSA IP address (December 2016)

On December 2, 2016, a denial-of-service attack was recorded against CANTV’s international links, targeting the IP address 200.11.137.56 assigned to PDVSA. LANautilus/Telecom Italia reported the attack, and Digital Attack Map recorded a peak of 5,559 Mbps for about six minutes. The CrediCard outage occurred on the same day and was reported by authorities as an attack on the banking sector, but sources at CANTV indicated that the interbank network was separate from the internet and that the two events should not be treated as a single technical incident.

Petróleos de Venezuela, S.A. (PDVSA)
social media account takeover

Hacking of the Twitter account of the Venezuelan news site Analítica.com

On June 30, 2016, the Twitter account of the Venezuelan news portal Analítica.com (@analitica), which had more than 80,200 followers, was hacked and hijacked. The attackers blocked access for the outlet’s social media team and successively changed the username to @datacaracas, @laboratorijhrva, @frazestranice, @d7893user, and @greeceloveplus, in addition to deleting recent posts. According to the outlet, Twitter’s representative for Latin America informed them via email that there was an intention to sell the account, and it is presumed that a hacker was hired to carry out the attack. Analítica regained control approximately 24 hours later, with Twitter’s intervention. The perpetrator has not been definitively identified.

Analítica.com
social media account takeover

IVSS’s official Twitter account was compromised to spread false messages about the president’s health

On June 8, 2016, the official Twitter account of the Venezuelan Social Security Institute (IVSS) was compromised by unidentified third parties. False messages were posted from the account regarding the health of the then-president of the Republic, claiming that he would be placed in a coma due to the severity of his condition and that he was using a wheelchair as a result of an accident. According to documentation from Espacio Público, the account was recovered approximately 25 minutes after the messages were posted, and those responsible were not identified. IVSS President Carlos Rotondaro denounced the hack, described all the messages as false, and attributed it to an alleged “international destabilization plan.”

Instituto Venezolano de los Seguros Sociales (IVSS)
sim swap social media account takeover

Journalist Nelson Bocaranda’s Twitter account was compromised via SIM swap

On May 6, 2016, the Twitter account of Venezuelan journalist Nelson Bocaranda, founder of Runrun.es, was hijacked by unauthorized individuals through a SIM swap attack: They requested a copy of the journalist’s SIM card from the carrier Movistar using a forged letter to “replace” it, thereby bypassing Twitter’s two-step verification by receiving the code on the cloned number. The attackers deleted his tweets, posted messages falsely linking him to the U.S. government and the CIA (for example, “I confess and declare myself a CIA agent”), exposed private messages, and changed his username from @nelsonbocaranda to @nelsonbocarnda. The journalist, who had more than 2 million followers, regained access to his account about 30 hours later. This was the second time his account had been hacked, following a previous incident in July 2014.

Nelson Bocaranda
social media account takeover and digital harassment

Human rights advocate Humberto Prado’s Facebook account hacked as part of a smear campaign

In late April 2016, the personal Facebook account of Humberto Prado Sifontes, director of the Venezuelan Prison Observatory (OVP), was hacked and used to post false information and a doctored photograph (showing him with a gun and a Polar beer) accusing him of being funded by the company Empresas Polar and of being a “pran” (prison gang leader). At the same time, a smear campaign unfolded on Twitter, where alleged private emails were leaked and the hashtag #HumbertoPradoPranDePolar went viral. The incident occurred following statements Prado made to the media about the prison crisis, in which he pointed to the responsibility of then-Governor Tareck El Aissami. On April 27, 2016, Prado filed a complaint with the Public Prosecutor’s Office. The exact date of the hack varies depending on the source (April 26 according to FIDH; April 23 according to Front Line Defenders).

Humberto Prado Sifontes (Observatorio Venezolano de Prisiones)
social media account takeover

Hacking of broadcaster Luis Chataing’s Twitter account

On February 11, 2016, the Twitter account @LuisChataing belonging to Venezuelan radio host and comedian Luis Chataing was compromised. The attackers posted alleged private WhatsApp conversations with political figures such as Henrique Capriles, Lilian Tintori, and Patricia de Ceballos, along with political messages and references to Empresas Polar. Chataing confirmed the hack via his Instagram account and, following the temporary loss of his profile, created a new Twitter account (@ChataingSupremo). The incident was documented by the NGO Espacio Público and by several Venezuelan media outlets.

Luis Chataing