Leak of confidential information

GordonFreeman Claims Attack Against Movilnet

On April 29, 2026, threat actors operating under the names GordonFreeman and L4TAM FUCKERS claimed to have compromised Movilnet, a major state-owned Venezuelan mobile operator. The attackers allegedly exploited an IDOR vulnerability in MongoDB using time-based predictable ObjectIds and sequential enumeration to leak a database containing 200,000 phone numbers and sensitive user data. The stolen information was subsequently leaked on a hacker forum.

Overview

Missing evidence

The exact date of the violation is not specified; only the date the leak was published (April 29, 2026) is given.The authenticity of the leaked data remains unverified.

Impact details

200,000 Exposed records

Actor and the press report a claimed data breach affecting more than 200,000 Movilnet users via IDOR; no official confirmation has been found.

phone numbersID numbersaddressesbilling recordspersonal information

Classification & severity

Category
Information content security
Subtype
Leak of confidential information
Confidence
Medium

Severity assessment

High
Functional impact
None
Information impact
Sensitive personal data
Affected scope
Multiple users
Critical service
Potential
Public confidence
Moderate

The complaint and public disclosure describe more than 200,000 records of telecommunications users, including identifiers, addresses, and billing information. No official confirmation was found.

Data exfiltration· Claimed Confidentiality

Timeline

Claim

GordonFreeman listed Movilnet as a presumed victim.

Evidence & sources

2 sources