Leak of confidential information

Cantpwn Claims Responsibility for Attack on the National Armed Forces Social Security Institute

On April 25, 2026, the threat actor cantpwn claimed that data attributed to the National Armed Forces Social Security Institute (IPSFA) had been leaked. No official confirmation or independent forensic validation of the material was found.

Overview

Missing evidence

No official statement from the victim or independent forensic confirmation was found in public sources.The public evidence supports the existence of a claim/report, but not the authenticity or integrity of the alleged commitment.It is unclear whether the data was actually extracted, leaked, or resulted in material losses, unless a source specifically states otherwise.There is no independent or official confirmation that cantpwn violated Venezuela's IPSFA on April 25, 2026.The main piece of evidence is the actor’s Spear.cx leak list (sensitive, not recovered) plus a new tertiary X publication; nor is there any independent corroboration.A statement from the IPSFA/Ministry of Defense, reports from an NGO or the media, or a verified technical analysis would be needed to go beyond a mere assertion by a threat actor.

Impact details

195,104 Exposed records

The breach of the IPSFA database, which is publicly accessible via OSINT/X, affects records of military personnel and their family members, including biometric, identity, military, financial, and address data. No official confirmation has been found.

biometric dataidentity recordsmilitary service recordsfinancial recordsfamily member recordsresidential location data

Classification & severity

Category
Information content security
Subtype
Leak of confidential information
Confidence
Medium

Severity assessment

High
Information impact
Government-sensitive
Affected scope
Organization-wide
Critical service
Potential
Public confidence
Significant

The report concerns military social security records containing biometric, identity, financial, and family-related data. The evidence is a public report from OSINT/social media, not an official confirmation.

Data exfiltration· Claimed Confidentiality

Timeline

Claim

cantpwn listed the National Armed Forces Social Security Institute as a suspected victim.

Evidence & sources

1 source