disputed breach claim

Claim on the dark web regarding an alleged data breach in the Venezuelan electoral system attributed to Smartmatic, which the company denies (2024)

An anonymous actor released screenshots allegedly showing data from the Venezuelan electoral system with references to Smartmatic. Smartmatic denied the authenticity and attribution of the screenshots, noting that it has not provided electoral services in Venezuela since 2017 and did not have access to the REP. The report is classified as a disputed claim, not a confirmed breach.

Impact details

Disputed dark web claim; Smartmatic denied the claim’s authenticity and any connection to its systems. No service disruption or verified data breach.

alleged electoral dataSmartmatic dataset under discussionalleged electoral systemscreenshot

Classification & severity

Category
Undetermined
Subtype
disputed breach claim
Confidence
Low

Smartmatic categorically denies the alleged data leak, and no independent validation of the dataset has been found.

Severity assessment

Medium
Functional impact
None
Information impact
Suspected
Critical service
None
Public confidence
Moderate

This could be sensitive information if true, but the claim is controversial and has not been validated.

Data exfiltration· Claimed

Timeline

Claim

An anonymous threat actor posted screenshots on the dark web and social media that allegedly showed classified data from the Venezuelan voting system, with references such as “VOTO CHAVISTA” and “REP Smartmatic 2024.”

Disclosure

The specialized media outlet The Cyber Express publicly reported on the claim regarding the alleged breach of the Venezuelan electoral system.

Update

Smartmatic denied the claim, stating that it has not provided services for Venezuelan elections since 2017 (it ceased operations in 2018) and that the image contained a significant error (“REP Smartmatic 2024”), as it never had access to voter registration records in Venezuela.

Other

Context: The same threat actor had previously attacked the Venezuelan telecom operator Digitel, publishing its data on the Medusa ransomware group’s leak site after failing to receive a $5 million ransom.

Evidence & sources

3 sources