malconguerra2
malconguerra2 is a forum user identified in multiple data breach claims targeting Venezuelan organizations, including government records.
- Incidents
- 22
- High impact
- 16
- First seen
- Sep 28, 2025
- Latest seen
- Jul 3, 2026
Linked incidents
malconguerra2 calls for the sale of Venezuela’s electronic tax stamp database
On July 3, 2026, the actor malconguerra2 posted an offer on an underground forum to sell a JSON repository attributed to the Venezuelan system for managing and issuing electronic tax stamps used by regional entities. The claim states that the dataset contains 1.5 GB and approximately 1.5 million records, including profiles of individual and corporate taxpayers, system operator data, password hashes, persistent tokens, bank references, and payment traceability for administrative procedures. No official confirmation or independent forensic validation has been found; this record documents the public claim and the associated risk, not a breach confirmed by an authority.
malconguerra2 alleges leak of confidential SIVERC Venezuela documents
On June 22, 2026, malconguerra2 posted a complaint on DarkForums against SIVERC, the Venezuelan System for the Registration, Control of Medicines, and Evaluation of Health Products, which is affiliated with the INHRR. The post claims that 121 GB of confidential documents and approximately 85,000 historical records were exposed, including regulatory documents, information on active companies, product histories, bank forms, tax documents, and personal data. DarkWebInformer publicly reposted the claim. No official confirmation or independent technical validation has been found, so the breach remains unconfirmed.
malconguerra2 alleges a leak of information from SUNACOOP
On June 2, 2026, malconguerra2 claimed to have published confidential information attributed to the National Superintendency of Cooperatives (SUNACOOP), with 58,200 alleged records. Secondary OSINT sources corroborate the metadata and describe registration and cooperative data. No official confirmation from SUNACOOP was found.
malconguerra2 alleges a data leak at SENIAT
On June 1, 2026, the actor malconguerra2 claimed to have distributed a database attributed to SENIAT. The claim refers to 24 million records and 30 GB. Secondary OSINT sources corroborate the volume and describe tax data from 2025–2026; no official confirmation from SENIAT or independent forensic validation was found.
malconguerra2 calls for an attack against Ridery
On May 13, 2026, a threat actor known as malconguerra2 posted a database on darkforums.su that allegedly contained personal and confidential information on 12,000 drivers from the Venezuelan ride-hailing app Ridery. The actor credited another individual, Sp33dM4x, for the breach. The compromised data reportedly includes names, photos, phone numbers, addresses, vehicle details, and descriptions.
malconguerra2 calls for an attack against MRW Venezuela
On April 14, 2026, a threat actor using the alias malconguerra2 claimed on DarkForums to have leaked more than 7.6 million confidential records attributed to MRW Venezuela. Public sources of threat intelligence and breach tracking refer to a similar claim involving logistics data, but no official confirmation from MRW was found in the sources reviewed.
malconguerra2 alleges data leak from Venezuelan raffle platforms
On April 3, 2026, an actor using the alias malconguerra2 claimed to have leaked approximately 26 million records attributed to Venezuelan raffle or lottery platforms. The review found weak public references to possible platforms within the raffle ecosystem, but not enough evidence to create individual incidents or to confirm a breach of CONALOT.
malconguerra2 calls for an attack on QuoVadis
On March 17, 2026, a threat actor known as malconguerra2 claimed to have leaked 43,000 records of confidential data from QuoVadis, a Venezuelan travel and tourism agency, on the darkforums.su forum. The compromised data reportedly includes email addresses and reservation details containing fields such as id, date of inquiry, reservation, PNR, status, and airline.
malconguerra2 calls for action against BT Travel Venezuela
On March 16, 2026, a threat actor using the alias malconguerra2 claimed on DarkForums to have leaked confidential data attributed to BT Travel Venezuela. Subsequently, public reports described an alleged data breach at BT Travel involving tens of thousands of customers, but no official confirmation from the company was found in the sources reviewed.
malconguerra2 calls for an attack on Krece
On March 4, 2026, a threat actor using the alias malconguerra2 claimed on BreachForums to have leaked approximately 6 million confidential records attributed to the Venezuelan app Krece. That same day (March 4, 2026), Krece issued an official statement confirming unauthorized access to part of its systems, resulting in the exposure of company and user data, though it maintained that login credentials and payment data remained intact and that services continued to operate normally (reported by elDiario.com and prensaoriente.com.ve on March 5, 2026). The figure of ~6 million records remains a claim by the actor/media that has not been independently verified.
malconguerra2 condemns attack on the Venezuelan School of Planning Foundation (FEVP)
On February 24, 2026, the threat actor known as malconguerra2 claimed to have compromised the Venezuelan School of Planning Foundation (FEVP). The actor posted the allegedly stolen data on BreachForums. The compromised dataset reportedly includes a JSON-like structure containing sensitive personal information, such as identification numbers (cédula), names, document types, and values, as well as email addresses and Telegram contact identifiers.
malconguerra2 calls for an attack on Cashea
On February 21, 2026, the actor malconguerra2 claimed on DarkForums to have published 46.5 GB of confidential Cashea data, including 79,006,942 transaction records, store records, and data from partner merchants. Cashea officially confirmed a data exfiltration involving users and merchant partners from the Merchant Web environment, which occurred between January 30 and February 21, 2026, attributed to the use of valid credentials from a partner merchant’s employee account that had been compromised outside the platform, as well as insufficient controls on APIs. The company stated that the information involved consists of operational and transactional data, such as names, ID numbers, phone numbers, orders, and merchant information; it also indicated that it did not identify any compromise of user passwords, internal administrative credentials, cloud infrastructure, private keys, system secrets, or financial payment processing components. The DarkForums.ru link added on July 4, 2026, corresponds to a repost or update of the same dataset from February, not a separate incident.
malconguerra2 calls for the release of 420GB of data from the Venezuelan Armed Forces
On January 23, 2026, a thread on BreachForums attributed to malconguerra2 was posted, announcing an alleged 420 GB dataset related to the Venezuelan armed forces. A publicly accessible page on DarkForums with the same title and date also mentions malconguerra2 and lists several military units as affected, but no official confirmation was found.
malconguerra2 calls for an attack on the National Experimental University of Security (UNES)
On January 21, 2026, the threat actor known as malconguerra2 claimed responsibility for a massive data breach targeting the National Experimental University of Security (UNES) in Venezuela. The actor posted on DarkForums, claiming to have exfiltrated 1 TB of confidential data, including student records, diplomas, and résumés. Evidence associated with the leak suggests that the data may have originated from internal server backups (C:\inetpub\wwwroot\admin\backup) dating back to December 2025.
malconguerra2 calls for an attack against the Scientific, Penal, and Criminal Investigations Corps (CICPC)
On January 20, 2026, a threat actor operating under the alias "malconguerra2" posted a data set on BreachForums that allegedly belonged to the Scientific, Penal, and Criminal Investigations Corps (CICPC). According to dark web intelligence reports, the leaked dataset contains more than 22.6 million records, with a total size of 1.66 GB, and includes a folder of photographs. The exact nature of the compromised data beyond the photographs remains unclear.
malconguerra2 calls for an attack on the National Land Transportation Institute (INTT) (500 GB)
On January 16, 2026, a threat actor known as malconguerra2 claimed to have published approximately 500 GB of data attributed to Venezuela’s National Land Transportation Institute (INTT). The available report is limited and does not detail the affected systems or the contents of the sample, so the claim has not been independently confirmed.
malconguerra2 demands the release of 31.7 GB of data from the Chacao Police Department
On December 27, 2025, a thread was posted on DarkForums attributed to malconguerra2 and titled as an alleged 31.7 GB dataset from the Chacao Police dated December 25, 2025. The local report does not disclose any sample content, affected systems, or public corroboration beyond the forum’s source URL.
malconguerra2 calls for the release of 207.5 GB of data from the Bolivarian National Police
On December 22, 2025, a public post on DarkForums attributed to malconguerra2 announced an alleged 207.5 GB dataset associated with the Bolivarian National Police (PNB). The visible thread indicates JSON/PNG/PDF formats and “TOTAL JSON INFORMATION: 153.5K”; this figure is listed as the claimed number of exposed records, not as a confirmed number of affected individuals. No official confirmation was found.
malconguerra2 calls for an attack against the CPNB
On October 18, 2025, a threat actor using the alias malconguerra2 claimed on DarkForums to have data related to the CPNB, identified in the thread title as the Bolivarian National Police Force. The available evidence supports the existence of a claim on the forum, but does not confirm the authenticity, source, or content of the alleged data.
malconguerra2 calls for an attack against Cordialito
On October 8, 2025, a threat actor using the alias malconguerra2 claimed on DarkForums to have leaked data associated with Cordialito, described in the thread title as a dataset from a betting house containing 423,000 lines. The available evidence supports the claim, but does not confirm the authenticity of the breach or the contents of the alleged dataset.
malconguerra2 calls for an attack against the Bolivarian Militia of Venezuela
On October 3, 2025, a threat actor operating under the alias “malconguerra2” claimed on a dark web forum to have compromised the Bolivarian Militia of Venezuela (Milicia Bolivariana). The actor leaked a 15.2 GB database containing approximately 163,500 records, which allegedly include confidential information about members, such as photographs, identification documents, and details about the military headquarters.
malconguerra2 calls for an attack against the Venezuelan National Armed Forces
On September 28, 2025, a threat actor using the alias malconguerra2 claimed on DarkForums to possess data related to the Venezuelan National Armed Forces and affiliated entities. The available, verified evidence supports a claim made on the forum but does not confirm the authenticity of the breach, the method of extraction, or the scope of the alleged data.