Leak of confidential information

SwichSmoke Leaks CANTV User Data and Movilnet Messages (Operation Venezuela)

In July 2011, an attacker identifying himself as SwichSmoke claimed to have compromised CANTV, Venezuela’s largest state-owned telecommunications company, and leaked data on Pastebin under the hashtags #OpCantv and “Operation Venezuela.” According to the attacker’s own post, the leak (with access obtained starting July 25) included a user database containing names, addresses, phone numbers, email addresses, passwords, national ID numbers, PINs, and credit card numbers, part of CANTV’s proxy server, and some text messages from its mobile subsidiary, Movilnet. The incident was reported on July 29, 2011, by the data breach tracker databreaches.net and was part of a broader SwichSmoke campaign targeting Venezuelan government entities. There is no public record of an official acknowledgment by CANTV.

Impact details

SwichSmoke publicly leaked CANTV customer data and material related to CANTV/Movilnet on Pastebin, as confirmed by DataBreaches. Reportedly, the exposed data included names, addresses, phone numbers, email addresses, passwords, national ID numbers, PINs, credit card numbers, proxy data, and Movilnet messages. No service disruption has been detected, nor has any official confirmation been found.

namesaddressesphone numbersemail addressespasswordsID numbers

Classification & severity

Category
Information content security
Subtype
Leak of confidential information
Confidence
High

The Pastebin author, “reclamo,” and coverage by DataBreaches support the public leak of CANTV customer data, CANTV proxy material, and Movilnet messages by SwichSmoke. No official confirmation has been found from CANTV.

Severity assessment

High
Functional impact
None
Information impact
Sensitive personal data
Affected scope
Organization-wide
Critical service
None
Public confidence
Significant
Recoverability
Regular

A public data breach affecting CANTV customer data and Movilnet messages—including sensitive identifiers, credentials/PINs, and credit card information—has been confirmed; no impact on service availability has been reported.

Data exfiltration· Confirmed Confidentiality

Timeline

Compromise

According to the attacker's post, access to CANTV was obtained starting on July 25, 2011.

Claim

SwichSmoke publishes CANTV user data, part of its proxy, and Movilnet messages on Pastebin (#OpCantv / Operation Venezuela).

Publication

The databreaches.net breach tracker reports that CANTV was hacked by SwichSmoke.

Update

databreaches.net reports new SwichSmoke data breaches as part of the "Operation Venezuela" campaign targeting Venezuelan government entities.

Evidence & sources

5 sources