Group 'Sistem Fail' Claims Responsibility for Data Leak Affecting 90,000 Patria System Accounts
In May 2023, a group calling itself “Sistem Fail” (via the Twitter account @FailSistema) claimed to have obtained data from approximately 90,000 accounts on the Patria System, the Venezuelan government’s platform used as an e-wallet and for the distribution of state bonuses and subsidies. According to the group, a configuration error exposed more than 90,000 accounts to the internet and made them accessible to attackers. The compromised information reportedly included users’ home addresses, personal data, bank accounts, and vehicle information. As proof, the group published a video and screenshots of user accounts. The attack occurred amid wage protests in Venezuela and coincided with an attack on the Public Prosecutor’s Office website claimed by another group (The Binary Guardians).
Impact details
90,000 Exposed records
The group claims to have accessed and exposed data from approximately 90,000 user accounts in the Patria System due to a configuration error, including addresses, personal information, bank account information, and vehicle information.
Classification & severity
- Category
- Information content security
- Subtype
- Leak of confidential information
- Confidence
- High
Severity assessment
High- Information impact
- Sensitive personal data
- Affected scope
- Multiple users
- Critical service
- Potential
- Public confidence
- Significant
The media has reported a data breach at Patria affecting 90,000 accounts, but there is no official confirmation.
Timeline
The group "Sistem Fail" claims via @FailSistema to have obtained data from 90,000 accounts in the Patria System, attributing it to a configuration error, and publishes a video and screenshots as proof.
Venezuelan and international media outlets (including NTN24, among others) are reporting on the incident, along with a simultaneous attack on the Public Prosecutor’s Office website, which was claimed by The Binary Guardians.