Threat actor

GordonFreeman

GordonFreeman is a threat actor observed on VCert and cybercrime forums with multiple claims against Venezuelan organizations in 2026; several associated posts use the tags L4TAMFUCK3R/L4TAMFUCK3RS.

Incidents
20
High impact
15
First seen
Feb 10, 2026
Latest seen
Jun 23, 2026

Linked incidents

20 incidents
Leak of confidential information

BANAVIH dataset allegedly offered for sale with 54,000 files

On June 23 and 24, 2026, public threat intelligence sources reported that the group or tag L4TAMFUCK3R/L4TAMFUCK3RS claimed to be selling a dataset from BANAVIH, Venezuela’s National Housing and Habitat Bank. The claim indicates approximately 54,000 folders and about 5.8 GB of data, potentially including documents related to housing loans, property ownership, institutional verification, and personal information. HackNotice has preserved the text of the claim and mentions cantpwn and GordonFreeman as leaders of the group. The claim remains unconfirmed by official sources and has not been independently validated through forensic analysis.

Banco Nacional de Vivienda y Hábitat (BANAVIH)
Leak of confidential information

GordonFreeman / L4TAMFUCK3R claims a leak from Venezuela’s Ministry of Penitentiary Services

On June 22, 2026, GordonFreeman posted on DarkForums a claim attributed to the L4TAMFUCK3R team regarding the registration system of the Venezuelan Ministry of the People’s Power for the Penitentiary Service (MPPSP). The actor claims to have obtained 22,900 images and personal data of employees registered in that system. Public dark web monitoring sources have reported the claim, but no official confirmation from the ministry or independent forensic validation has been found; therefore, this record documents the public claim and the associated risk, not a breach confirmed by the victim.

Ministerio del Poder Popular para el Servicio Penitenciario de Venezuela (MPPSP)
Leak of confidential information

Alleged leak of the Venezuelan Central Bank’s (BCV) “Sovereign Gold Platform,” claimed by GordonFreeman / L4TAMFUCK3R$

Between June 17 and 18, 2026, a suspected data breach of the Venezuelan Central Bank’s (BCV) Sovereign Gold Platform was reported, attributed to GordonFreeman / L4TAMFUCK3R$. The claim indicates approximately 186,500 records. Public coverage on June 18 states that the alert remains classified as suspected/unconfirmed and that the BCV had not issued an official statement at the time of the report. June 17 is recorded as the date of the actor’s claim, and June 18 as the primary date of public reporting.

Banco Central de Venezuela (BCV)
Leak of confidential information

GordonFreeman alleges a leak of payroll data from a government system that would affect Education, Defense, and Health

On June 11, 2026, GordonFreeman/L4TAMFUCK3R$ claimed to have obtained payroll data linked to the Venezuelan Ministries of Education, Defense, and Health following an alleged breach of a government system. The publicly available evidence shows a single, bundled claim, not three separate intrusions per ministry. The counts reported in publicly available screenshots are 392,286 for Education, 22,507 for Defense, and 9,459 for Health, for a total of 424,252 records. No official confirmation or independent validation was found.

Sistema gubernamental de nomina de Venezuela (ministerios de Educacion, Defensa y Salud)
Leak of confidential information

GordonFreeman alleges leak of INTT records

On June 6, 2026, Gordon Freeman published a claim regarding a database from the National Institute of Land Transportation, labeled “INTT Venezuela 2026,” with 788,000 alleged records. No official confirmation from the INTT or independent validation of the dataset was found.

Instituto Nacional de Transporte Terrestre (INTT)
Leak of confidential information

GordonFreeman Reports Digitel User Data Breach

On June 6, 2026, Gordon Freeman published a claim regarding a Digitel Venezuela 2026 database with an alleged 394,000 users. No official confirmation from Digitel or independent technical validation of the dataset was found.

Corporación Digitel C.A.
Leak of confidential information

GordonFreeman reports a data breach at Movistar Venezuela 2026

On May 15, 2026, GordonFreeman posted a claim on DarkForums titled “DATABASE MOVISTAR VENEZUELA 2026 DB 4.15 Million Customer Numbers,” alleging 4.15 million current records of Movistar Venezuela phone numbers. The evidence reviewed indicates that the ValidMarket record publicly listed on May 19 corresponds to the same dataset or a repost of the same claim, based on the matching target, volume, and title. The incident remains a single, deduplicated record; there is no official confirmation from Movistar nor independent forensic validation of the complete dataset.

Movistar Venezuela
Leak of confidential information

GordonFreeman reports an attack on CANTV ABA ULTRA

On May 14, 2026, the threat actor GordonFreeman claimed to have compromised a Ubiquiti UISP administration panel belonging to CANTV ABA ULTRA in eastern Venezuela. According to reports, the breach exposed data on 7,500 users and 4,000 network devices, specifically related to the GPON OLT fiber-optic infrastructure. The attacker leaked a sample containing email addresses and system identifiers, while also threatening physical sabotage.

Compañía Anónima Nacional Teléfonos de Venezuela (CANTV) - ABA Ultra
Leak of confidential information

Operation Hecatombe: Alleged Data Breach Involving SAIME, SAREN, and the Border ID Card

On May 8, 2026, L4TAMFUCKERS/GordonFreeman claimed on dark web sources and through OSINT monitoring that an alleged “Operation Hecatombe Venezuela” was targeting the Venezuelan government’s identity systems. The alleged data set combines a SAIME biographical database of approximately 35.2 million records, SAREN civil documents totaling several terabytes, and approximately 92,000 Border ID card records. The publicly available evidence supports a single bundled claim/operation, not separate intrusions by agency. No official confirmation or independent verification of authenticity was found. Cashea is excluded from this record because it appears in related news reports as a separate claim.

Servicio Administrativo de Identificación, Migración y Extranjería (SAIME)
Leak of confidential information

GordonFreeman Claims Attack Against Movilnet

On April 29, 2026, threat actors operating under the names GordonFreeman and L4TAM FUCKERS claimed to have compromised Movilnet, a major state-owned Venezuelan mobile operator. The attackers allegedly exploited an IDOR vulnerability in MongoDB using time-based predictable ObjectIds and sequential enumeration to leak a database containing 200,000 phone numbers and sensitive user data. The stolen information was subsequently leaked on a hacker forum.

Telecomunicaciones Movilnet, C.A.
Leak of confidential information

Cantpwn Claims Responsibility for Attack on the National Armed Forces Social Security Institute

On April 25, 2026, the threat actor cantpwn claimed that data attributed to the National Armed Forces Social Security Institute (IPSFA) had been leaked. No official confirmation or independent forensic validation of the material was found.

Instituto de Previsión Social de la Fuerza Armada Nacional Bolivariana (IPSFANB)
Leak of confidential information

Gordon Freeman Calls for an Attack on Petróleos de Venezuela, S.A. (PDVSA)

On April 22, 2026, a threat actor known as GordonFreeman claimed to have leaked 10,000 records belonging to employees of the Venezuelan state-owned oil company PDVSA on the cybercrime forum darkforums.su. The compromised dataset reportedly includes email addresses, phone numbers, and identification numbers. The exact state-owned entity or the vulnerability exploited to access PDVSA’s data has not yet been specified.

Petróleos de Venezuela, S.A. (PDVSA)
Leak of confidential information

Unknown actor puts a Conviasa (Venezuelan state-owned airline) database up for sale

In April 2026, a listing appeared on dark web forums offering a database attributed to Conviasa, Venezuela’s state-owned airline, described as data exfiltrated from the company (“DATABASE CONVIASA AIRLINES (VENEZUELA) 2026,” cited as having a volume of ~165 GB). ASEC’s (AhnLab) dark web trends report confirmed that Conviasa data was among that of several Venezuelan entities posted on clandestine forums during April 2026. The perpetrator was not publicly identified, nor was the scope of the breach officially confirmed by Conviasa.

Línea Aérea Conviasa (Consorcio Venezolano de Industrias Aeronáuticas y Servicios Aéreos)
Leak of confidential information

GordonFreeman Calls for Action Against SENIAT

On April 15, 2026, a threat actor using the alias GordonFreeman claimed on DarkForums to have leaked approximately 13.8 million data records attributed to Venezuela’s SENIAT. Public reports described the claim as an alleged or reported large-scale data breach involving the tax administration, but the sources reviewed did not contain any official confirmation from SENIAT or any analysis of independently validated datasets.

Servicio Nacional Integrado de Administración Aduanera y Tributaria (SENIAT)
unauthorised access to information systems

GordonFreeman Claims Responsibility for Attack on SEN CORPOELEC

On April 14, 2026, a threat actor using the alias GordonFreeman claimed on DarkForums to have carried out an attack affecting Venezuela’s National Electric System (SEN) and CORPOELEC. Public threat intelligence reports described the claim as unverified and referred to a risk to critical infrastructure. No official confirmation or independently validated technical evidence was found in the sources reviewed.

Corporación Eléctrica Nacional (CORPOELEC)
Leak of confidential information

Gordon Freeman Claims Attack on Yummy Rides

On March 8, 2026, Yummy Rides suffered the unauthorized extraction of the full names and profile photos of approximately 30,000 drivers, exploiting an unpatched vulnerability. CEO Vicente Zavarce addressed the incident on X, describing it as a thwarted “attempt” and stating that no financial or sensitive user data was compromised. However, the actor GordonFreeman (attributed by VECERT) published the database of ~30,000 images linked to full names as a free download on the dark web, with screenshots as proof, and the NGO RedesAyuda (Luis Serrano) publicly refuted the company’s account, confirming that a data breach did occur.

Yummy Rides
Leak of confidential information

GordonFreeman calls for an attack on RAPIKOM

On March 8, 2026, a threat actor operating under the alias GordonFreeman leaked a database containing approximately 5,000 commercial records belonging to RAPIKOM, a Venezuelan installment shopping / affiliate-based e-commerce platform (BNPL model, a competitor of Cashea). The compromised data, which was published on darkforums.su, reportedly included bank accounts, phone numbers, email addresses, RIFs, payment details, and passwords. This incident occurred alongside a series of similar cyberattacks targeting other Venezuelan technology platforms during the same period.

RAPIKOM
Leak of confidential information

GordonFreeman Claims Responsibility for Attack on SUVE Metro in Caracas

On February 27, 2026, a threat actor using the alias GordonFreeman claimed on DarkForums to be selling approximately 650,000 user records and transit card details attributed to the Caracas Metro’s SUVE system. A subsequent public source echoed the claim, but the authenticity and origin of the dataset remain unconfirmed.

SUVE Metro de Caracas
Leak of confidential information

Gordon Freeman Calls for an Attack on Bancrecer Venezuela

On February 11, 2026, public threat intelligence sources reported that GordonFreeman claimed to be selling a purported Bancrecer Venezuela database containing approximately 65,000 financial records. The sources describe account numbers, names, phone numbers, and other alleged financial details, but there is no confirmation from Bancrecer nor any independent validation of the data’s authenticity.

Bancrecer Venezuela
privileged account compromise

GordonFreeman Claims Responsibility for Attack on the Central Bank of Venezuela (BCV)

On February 10, 2026, public sources reported that GordonFreeman claimed to have gained unauthorized access to the Central Bank of Venezuela’s (BCV) webmail system. A public mirror of DarkForums and a public post by VECERT document the existence of the claim, but there is no official confirmation or independent evidence that the access was genuine, exploited, or sold.

Banco Central de Venezuela (BCV)