Cypher404x Claims Attack Against Movistar Venezuela
On April 27, 2025, a Movistar Venezuela database was offered on DarkForums (actor’s alias: Cypher404x, reported by the press as anonymous); A sample was published on April 28, and the complete file was made available for free on April 29, 2025. The data breach affects approximately 3,250,000 users (more than 4 million records) and includes national ID numbers, full names, cities of residence, and phone numbers. The NGO VE Sin Filtro independently verified that the data belongs to Movistar users; it has not been confirmed that it was obtained directly from Movistar’s systems.
Overview
Missing evidence
Impact details
4,000,000 Exposed records
3,250,000 Affected people
Publicly verified data breach: A file containing approximately 3,250,000 users and more than 4 million records from Movistar Venezuela was published on April 29, 2025. VE sin Filtro independently verified the content, including ID numbers, full names, addresses/cities, and phone numbers, but was unable to confirm whether the data came directly from Movistar’s systems. There was no confirmed service disruption.
Classification & severity
- Category
- Information content security
- Subtype
- Leak of confidential information
- Confidence
- Medium
Severity assessment
High- Functional impact
- None
- Information impact
- Personal data
- Affected scope
- National
- Critical service
- Potential
- Public confidence
- Moderate
The public assessment of coverage and validation of unfiltered VE data covers approximately 3.25 million Movistar Venezuela users and more than 4 million records, but no service disruption or direct intrusion vector has been confirmed.
Timeline
Cypher404x listed Movistar Venezuela as a suspected victim.