GordonFreeman
GordonFreeman is a threat actor observed on VCert and cybercrime forums with multiple claims against Venezuelan organizations in 2026; several associated posts use the tags L4TAMFUCK3R/L4TAMFUCK3RS.
- Incidents
- 20
- High impact
- 15
- First seen
- Feb 10, 2026
- Latest seen
- Jun 23, 2026
Linked incidents
BANAVIH dataset allegedly offered for sale with 54,000 files
On June 23 and 24, 2026, public threat intelligence sources reported that the group or tag L4TAMFUCK3R/L4TAMFUCK3RS claimed to be selling a dataset from BANAVIH, Venezuela’s National Housing and Habitat Bank. The claim indicates approximately 54,000 folders and about 5.8 GB of data, potentially including documents related to housing loans, property ownership, institutional verification, and personal information. HackNotice has preserved the text of the claim and mentions cantpwn and GordonFreeman as leaders of the group. The claim remains unconfirmed by official sources and has not been independently validated through forensic analysis.
GordonFreeman / L4TAMFUCK3R claims a leak from Venezuela’s Ministry of Penitentiary Services
On June 22, 2026, GordonFreeman posted on DarkForums a claim attributed to the L4TAMFUCK3R team regarding the registration system of the Venezuelan Ministry of the People’s Power for the Penitentiary Service (MPPSP). The actor claims to have obtained 22,900 images and personal data of employees registered in that system. Public dark web monitoring sources have reported the claim, but no official confirmation from the ministry or independent forensic validation has been found; therefore, this record documents the public claim and the associated risk, not a breach confirmed by the victim.
Alleged leak of the Venezuelan Central Bank’s (BCV) “Sovereign Gold Platform,” claimed by GordonFreeman / L4TAMFUCK3R$
Between June 17 and 18, 2026, a suspected data breach of the Venezuelan Central Bank’s (BCV) Sovereign Gold Platform was reported, attributed to GordonFreeman / L4TAMFUCK3R$. The claim indicates approximately 186,500 records. Public coverage on June 18 states that the alert remains classified as suspected/unconfirmed and that the BCV had not issued an official statement at the time of the report. June 17 is recorded as the date of the actor’s claim, and June 18 as the primary date of public reporting.
GordonFreeman alleges a leak of payroll data from a government system that would affect Education, Defense, and Health
On June 11, 2026, GordonFreeman/L4TAMFUCK3R$ claimed to have obtained payroll data linked to the Venezuelan Ministries of Education, Defense, and Health following an alleged breach of a government system. The publicly available evidence shows a single, bundled claim, not three separate intrusions per ministry. The counts reported in publicly available screenshots are 392,286 for Education, 22,507 for Defense, and 9,459 for Health, for a total of 424,252 records. No official confirmation or independent validation was found.
GordonFreeman alleges leak of INTT records
On June 6, 2026, Gordon Freeman published a claim regarding a database from the National Institute of Land Transportation, labeled “INTT Venezuela 2026,” with 788,000 alleged records. No official confirmation from the INTT or independent validation of the dataset was found.
GordonFreeman Reports Digitel User Data Breach
On June 6, 2026, Gordon Freeman published a claim regarding a Digitel Venezuela 2026 database with an alleged 394,000 users. No official confirmation from Digitel or independent technical validation of the dataset was found.
GordonFreeman reports a data breach at Movistar Venezuela 2026
On May 15, 2026, GordonFreeman posted a claim on DarkForums titled “DATABASE MOVISTAR VENEZUELA 2026 DB 4.15 Million Customer Numbers,” alleging 4.15 million current records of Movistar Venezuela phone numbers. The evidence reviewed indicates that the ValidMarket record publicly listed on May 19 corresponds to the same dataset or a repost of the same claim, based on the matching target, volume, and title. The incident remains a single, deduplicated record; there is no official confirmation from Movistar nor independent forensic validation of the complete dataset.
GordonFreeman reports an attack on CANTV ABA ULTRA
On May 14, 2026, the threat actor GordonFreeman claimed to have compromised a Ubiquiti UISP administration panel belonging to CANTV ABA ULTRA in eastern Venezuela. According to reports, the breach exposed data on 7,500 users and 4,000 network devices, specifically related to the GPON OLT fiber-optic infrastructure. The attacker leaked a sample containing email addresses and system identifiers, while also threatening physical sabotage.
Operation Hecatombe: Alleged Data Breach Involving SAIME, SAREN, and the Border ID Card
On May 8, 2026, L4TAMFUCKERS/GordonFreeman claimed on dark web sources and through OSINT monitoring that an alleged “Operation Hecatombe Venezuela” was targeting the Venezuelan government’s identity systems. The alleged data set combines a SAIME biographical database of approximately 35.2 million records, SAREN civil documents totaling several terabytes, and approximately 92,000 Border ID card records. The publicly available evidence supports a single bundled claim/operation, not separate intrusions by agency. No official confirmation or independent verification of authenticity was found. Cashea is excluded from this record because it appears in related news reports as a separate claim.
GordonFreeman Claims Attack Against Movilnet
On April 29, 2026, threat actors operating under the names GordonFreeman and L4TAM FUCKERS claimed to have compromised Movilnet, a major state-owned Venezuelan mobile operator. The attackers allegedly exploited an IDOR vulnerability in MongoDB using time-based predictable ObjectIds and sequential enumeration to leak a database containing 200,000 phone numbers and sensitive user data. The stolen information was subsequently leaked on a hacker forum.
Cantpwn Claims Responsibility for Attack on the National Armed Forces Social Security Institute
On April 25, 2026, the threat actor cantpwn claimed that data attributed to the National Armed Forces Social Security Institute (IPSFA) had been leaked. No official confirmation or independent forensic validation of the material was found.
Gordon Freeman Calls for an Attack on Petróleos de Venezuela, S.A. (PDVSA)
On April 22, 2026, a threat actor known as GordonFreeman claimed to have leaked 10,000 records belonging to employees of the Venezuelan state-owned oil company PDVSA on the cybercrime forum darkforums.su. The compromised dataset reportedly includes email addresses, phone numbers, and identification numbers. The exact state-owned entity or the vulnerability exploited to access PDVSA’s data has not yet been specified.
Unknown actor puts a Conviasa (Venezuelan state-owned airline) database up for sale
In April 2026, a listing appeared on dark web forums offering a database attributed to Conviasa, Venezuela’s state-owned airline, described as data exfiltrated from the company (“DATABASE CONVIASA AIRLINES (VENEZUELA) 2026,” cited as having a volume of ~165 GB). ASEC’s (AhnLab) dark web trends report confirmed that Conviasa data was among that of several Venezuelan entities posted on clandestine forums during April 2026. The perpetrator was not publicly identified, nor was the scope of the breach officially confirmed by Conviasa.
GordonFreeman Calls for Action Against SENIAT
On April 15, 2026, a threat actor using the alias GordonFreeman claimed on DarkForums to have leaked approximately 13.8 million data records attributed to Venezuela’s SENIAT. Public reports described the claim as an alleged or reported large-scale data breach involving the tax administration, but the sources reviewed did not contain any official confirmation from SENIAT or any analysis of independently validated datasets.
GordonFreeman Claims Responsibility for Attack on SEN CORPOELEC
On April 14, 2026, a threat actor using the alias GordonFreeman claimed on DarkForums to have carried out an attack affecting Venezuela’s National Electric System (SEN) and CORPOELEC. Public threat intelligence reports described the claim as unverified and referred to a risk to critical infrastructure. No official confirmation or independently validated technical evidence was found in the sources reviewed.
Gordon Freeman Claims Attack on Yummy Rides
On March 8, 2026, Yummy Rides suffered the unauthorized extraction of the full names and profile photos of approximately 30,000 drivers, exploiting an unpatched vulnerability. CEO Vicente Zavarce addressed the incident on X, describing it as a thwarted “attempt” and stating that no financial or sensitive user data was compromised. However, the actor GordonFreeman (attributed by VECERT) published the database of ~30,000 images linked to full names as a free download on the dark web, with screenshots as proof, and the NGO RedesAyuda (Luis Serrano) publicly refuted the company’s account, confirming that a data breach did occur.
GordonFreeman calls for an attack on RAPIKOM
On March 8, 2026, a threat actor operating under the alias GordonFreeman leaked a database containing approximately 5,000 commercial records belonging to RAPIKOM, a Venezuelan installment shopping / affiliate-based e-commerce platform (BNPL model, a competitor of Cashea). The compromised data, which was published on darkforums.su, reportedly included bank accounts, phone numbers, email addresses, RIFs, payment details, and passwords. This incident occurred alongside a series of similar cyberattacks targeting other Venezuelan technology platforms during the same period.
GordonFreeman Claims Responsibility for Attack on SUVE Metro in Caracas
On February 27, 2026, a threat actor using the alias GordonFreeman claimed on DarkForums to be selling approximately 650,000 user records and transit card details attributed to the Caracas Metro’s SUVE system. A subsequent public source echoed the claim, but the authenticity and origin of the dataset remain unconfirmed.
Gordon Freeman Calls for an Attack on Bancrecer Venezuela
On February 11, 2026, public threat intelligence sources reported that GordonFreeman claimed to be selling a purported Bancrecer Venezuela database containing approximately 65,000 financial records. The sources describe account numbers, names, phone numbers, and other alleged financial details, but there is no confirmation from Bancrecer nor any independent validation of the data’s authenticity.
GordonFreeman Claims Responsibility for Attack on the Central Bank of Venezuela (BCV)
On February 10, 2026, public sources reported that GordonFreeman claimed to have gained unauthorized access to the Central Bank of Venezuela’s (BCV) webmail system. A public mirror of DarkForums and a public post by VECERT document the existence of the claim, but there is no official confirmation or independent evidence that the access was genuine, exploited, or sold.