Leak of confidential information

MDGhost Claims Responsibility for Attack on Consorcio Credicard

On May 13, 2026, the threat actor MDGhost claimed to have breached Consorcio Credicard, a major Venezuelan payment platform. The attacker posted a database containing more than 5 million records on a hacking forum. The compromised data reportedly includes personally identifiable information, such as names, national ID numbers, addresses, account types, and email addresses.

Overview

Missing evidence

The exact contents of the database and the method of compromise are not fully detailed, although JSON keys such as 'dni,' 'name,' and 'direccion' suggest PII.

Impact details

5,000,000 Exposed records

Unofficial and unconfirmed public reports describe a breach involving more than 5 million records associated with Consorcio Credicard customers and merchants. No official statement or independent verification was found.

identity datacontact informationfinancial account metadatamerchant profile datapayment terminal metadatapayment processing database

Classification & severity

Category
Information content security
Subtype
Leak of confidential information
Confidence
Medium

Severity assessment

High
Information impact
Sensitive personal data
Affected scope
National
Critical service
Potential
Public confidence
Moderate

Potential for significant impact if the incident is genuine, given the nature of payment processing, the types of customer and merchant data involved, and the reported scale of the incident; public evidence is based on information from media reports and social media, with no official or forensic confirmation.

Data exfiltration· Claimed Confidentiality

Timeline

Claim

MDGhost listed Consorcio Credicard as a suspected victim.

Evidence & sources

3 sources