GordonFreeman Claims Attack Against Movilnet
On April 29, 2026, threat actors operating under the names GordonFreeman and L4TAM FUCKERS claimed to have compromised Movilnet, a major state-owned Venezuelan mobile operator. The attackers allegedly exploited an IDOR vulnerability in MongoDB using time-based predictable ObjectIds and sequential enumeration to leak a database containing 200,000 phone numbers and sensitive user data. The stolen information was subsequently leaked on a hacker forum.
Overview
Missing evidence
Impact details
200,000 Exposed records
Actor and the press report a claimed data breach affecting more than 200,000 Movilnet users via IDOR; no official confirmation has been found.
Classification & severity
- Category
- Information content security
- Subtype
- Leak of confidential information
- Confidence
- Medium
Severity assessment
High- Functional impact
- None
- Information impact
- Sensitive personal data
- Affected scope
- Multiple users
- Critical service
- Potential
- Public confidence
- Moderate
The complaint and public disclosure describe more than 200,000 records of telecommunications users, including identifiers, addresses, and billing information. No official confirmation was found.
Timeline
GordonFreeman listed Movilnet as a presumed victim.