Target

Petróleos de Venezuela, S.A. (PDVSA)

Energy · State-owned pdvsa.com

Incidents
4
High impact
3
First seen
Dec 2, 2016
Latest seen
Apr 22, 2026

Linked incidents

Leak of confidential information

Gordon Freeman Calls for an Attack on Petróleos de Venezuela, S.A. (PDVSA)

On April 22, 2026, a threat actor known as GordonFreeman claimed to have leaked 10,000 records belonging to employees of the Venezuelan state-owned oil company PDVSA on the cybercrime forum darkforums.su. The compromised dataset reportedly includes email addresses, phone numbers, and identification numbers. The exact state-owned entity or the vulnerability exploited to access PDVSA’s data has not yet been specified.

GordonFreeman
destructive malware wiper

Destructive 'Lotus' wiper attack hits PDVSA and the Venezuelan energy sector

On December 15, 2025, Petróleos de Venezuela (PDVSA) reported a cyberattack aimed at disrupting its operations, which affected its administrative systems and temporarily interrupted the delivery of oil shipments, forcing staff to resort to manual record-keeping. Kaspersky linked the incident to a previously unknown destructive malware dubbed “Lotus,” which deletes recovery mechanisms, overwrites physical disks, and deletes files, rendering the computers irrecoverable; samples were uploaded from Venezuela in mid-December and referenced pdvsa.com. PDVSA blamed the United States and “stateless actors,” an accusation that neither Washington confirmed nor security researchers supported with technical evidence.

Actor desconocido
service disruption claim

Anonymous Claims Responsibility for Attack on Petróleos de Venezuela, S.A. (PDVSA)

PDVSA was named by official sources and the media in connection with the wave of cyberattacks against Venezuelan state platforms following the July 28, 2024, elections. Public information primarily points to availability/DDoS attacks against digital platforms, but does not confirm any data breaches, disruptions to oil production, or material losses.

Anonymous
Distributed denial of service

DDoS attack against CANTV links targeting a PDVSA IP address (December 2016)

On December 2, 2016, a denial-of-service attack was recorded against CANTV’s international links, targeting the IP address 200.11.137.56 assigned to PDVSA. LANautilus/Telecom Italia reported the attack, and Digital Attack Map recorded a peak of 5,559 Mbps for about six minutes. The CrediCard outage occurred on the same day and was reported by authorities as an attack on the banking sector, but sources at CANTV indicated that the interbank network was separate from the internet and that the two events should not be treated as a single technical incident.

Actor desconocido