Leak of confidential information

Kapustkiy Reports Data Breach Involving SUNAVAL Domains

On January 14, 2017, Softpedia reported that Kapustkiy had compromised three .gob.ve sites, including snv.gob.ve and sunaval.gob.ve. Both domains fall under the same entity, the National Securities Superintendency (SUNAVAL). The incident evidence for these domains comes primarily from Softpedia and reposts, so it is classified as partially verified.

Overview

Missing evidence

official confirmationDirect mirror of the forensic data from SUNAVAL's domains

Impact details

Softpedia reports that Kapustkiy has compromised government domains related to SUNAVAL and has released a database dump containing names, email addresses, phone numbers, and hashed passwords. No service disruption has been reported, nor has there been any official confirmation.

namesemail addressesphone numberspassword hashespublic websitesecurities regulatory authorities' websites

Classification & severity

Category
Information content security
Subtype
Leak of confidential information
Confidence
Medium

Softpedia reports that Kapustkiy has compromised domains related to SUNAVAL and analyzed a database dump containing personal and contact information, as well as encrypted passwords; no official confirmation has been released.

Severity assessment

Medium
Functional impact
None
Information impact
Credentials
Affected scope
Multiple systems
Critical service
None
Public confidence
Limited
Recoverability
Regular

There have been reports of a breach involving domains belonging to the securities regulatory authority, with a leaked dataset containing personal and contact information, as well as encrypted passwords; no service disruption has been reported, nor is there any official confirmation.

Data exfiltration· Confirmed Confidentiality

Timeline

Claim

Kapustkiy Reports Data Breach Involving SUNAVAL Domains

Evidence & sources

2 sources