Target

Compañía Anónima Nacional Teléfonos de Venezuela (CANTV)

Communications · State-owned cantv.com.ve

Incidents
10
High impact
3
First seen
Jul 29, 2011
Latest seen
May 14, 2026

Linked incidents

10 incidents
Leak of confidential information

GordonFreeman reports an attack on CANTV ABA ULTRA

On May 14, 2026, the threat actor GordonFreeman claimed to have compromised a Ubiquiti UISP administration panel belonging to CANTV ABA ULTRA in eastern Venezuela. According to reports, the breach exposed data on 7,500 users and 4,000 network devices, specifically related to the GPON OLT fiber-optic infrastructure. The attacker leaked a sample containing email addresses and system identifiers, while also threatening physical sabotage.

GordonFreeman
route leak

CANTV (AS8048) BGP route leak diverts Venezuelan traffic through Sparkle’s Italian transit network (January 2026)

On January 2, 2026 (detected around 15:40 UTC by Cloudflare Radar), a BGP route leak originating from AS8048 (CANTV, Venezuela’s state-owned telecommunications operator): eight IP prefixes, including blocks belonging to Dayco Telecom (200.74.224.0/20) that host critical infrastructure such as banks and mail servers, appeared routed through CANTV via the Italian ISP Sparkle (AS6762) and the Colombian ISP V.tal GlobeNet (AS52320) on the AS route. Networking analyst Graham Helton (Low End Orbit) reported this and hypothesized that it might have been intelligence gathering prior to Maduro’s capture. Cloudflare (Bryton Herdes) dismissed that theory and concluded that it was almost certainly due to a configuration flaw (overly lax export policies) rather than a deliberate attack, noting that AS8048 appeared in the route about 10 times (which made the route LESS attractive, contrary to what a man-in-the-middle attacker would seek) and that it was one of approximately eleven similar incidents since December 2025.

Unknown actor
service disruption claim

CyberTeam Claims Attack Against Compañía Anónima Nacional Teléfonos de Venezuela (Cantv)

On July 14, 2025, the hacktivist group CyberTeam claimed to have carried out a cyberattack against CANTV, Venezuela’s state-owned telecommunications provider. The claim comes from a single post on the OSINT aggregator VenariX-ES (X) that reposts content from the actor itself; there is no official confirmation or independent forensic validation. The claims of access to the “UISP network” and the disruption of internet, television, and telephone services do not appear in the cited public source and contradict the impact fields in the log (service_disrupted=false); they are considered unsubstantiated. The scope is unknown.

CyberTeam
Leak of confidential information

Anonymous Person Accuses Compañía Anónima Nacional Teléfonos de Venezuela (CANTV) of a Data Breach

On August 26, 2024, the hacktivist group Anonymous—specifically, threat actors operating under the names White_Hunters and Cyber Hunters—claimed to have gained unauthorized access to the systems of Compañía Anónima Nacional Teléfonos de Venezuela (CANTV). The attackers allegedly leaked 6.5 million records containing personal information, including first names, last names, and identification numbers. There has been no official statement from CANTV confirming the leak.

Anonymous
Distributed denial of service

Anonymous Claims Responsibility for DDoS Attack Against Compañía Anónima Nacional Teléfonos de Venezuela (CANTV)

Following the July 28, 2024, elections, CANTV was identified by sources citing official statements as one of the state-run platforms affected by DDoS attacks. Reports indicate that international links and government servers received anomalous traffic, with an incident targeting CANTV that exceeded its usual capacity several times over. There is no public evidence of a data breach.

Anonymous
Service outage

GhostSec claims to have disconnected 4,097 CANTV modems via TR-069 during the June 28 elections in Venezuela

Coinciding with Election Day on July 28, 2024, in Venezuela, the hacktivist group GhostSec claimed to have exploited misconfigured modems belonging to the state-owned company CANTV, manipulating passwords, network settings, and the TR-069 remote management protocol to prevent CANTV from reconfiguring them remotely. According to the claim reported by the media, 4,097 modems were taken offline, including the Stavix MP-X421R (1,930), Huawei DG8245V-10 (1,654), ZTE F670L (414), and ZTE ZXH108N v2.5 (99) were disconnected. The group stated that its target was the state-owned company and the government, not the general public, since most users still had 4G mobile access. The figures and scope come from the group’s own statement and were not officially confirmed by CANTV.

GhostSec
website defacement or dns redirection

The Binary Guardians defaces or redirects the CANTV portal during the campaign against .ve domains

On August 7, 2017, CANTV was named by EFE, El Pitazo, Runrun.es, and IT Projects as one of the websites affected by The Binary Guardians. Days later, the president of CANTV publicly described an attack on NIC.ve/DNS that redirected multiple official .ve websites. There is no public evidence of data exfiltration from the operator.

The Binary Guardians
Distributed denial of service

DDoS attack against CANTV links targeting a PDVSA IP address (December 2016)

On December 2, 2016, a denial-of-service attack was recorded against CANTV’s international links, targeting the IP address 200.11.137.56 assigned to PDVSA. LANautilus/Telecom Italia reported the attack, and Digital Attack Map recorded a peak of 5,559 Mbps for about six minutes. The CrediCard outage occurred on the same day and was reported by authorities as an attack on the banking sector, but sources at CANTV indicated that the interbank network was separate from the internet and that the two events should not be treated as a single technical incident.

Actor desconocido
website defacement

Anonymous Venezuela defaces the CANTV website (www.cantv.com.ve)

On June 22, 2014, the hacktivist group Anonymous Venezuela (@AnonymousVene10) claimed responsibility for the attack on CANTV’s main website, www.cantv.com.ve, posting messages mocking the state-owned operator and the government (“HACKED AND ERADICATED!”, “What happened, CANTV Fail???”) and claiming that CANTV “spies” on citizens. The attack coincided with a fiber-optic outage reported by CANTV (beginning June 21) that left several states —the Capital District, Anzoátegui, Falcón, Aragua, Carabobo, and Miranda—and also affected ATMs, point-of-sale terminals, and telephone lines. Media sources have documented the group’s claim of responsibility, although there was no independent technical verification of the defacement by the operator.

Anonymous Venezuela
Leak of confidential information

SwichSmoke Leaks CANTV User Data and Movilnet Messages (Operation Venezuela)

In July 2011, an attacker identifying himself as SwichSmoke claimed to have compromised CANTV, Venezuela’s largest state-owned telecommunications company, and leaked data on Pastebin under the hashtags #OpCantv and “Operation Venezuela.” According to the attacker’s own post, the leak (with access obtained starting July 25) included a user database containing names, addresses, phone numbers, email addresses, passwords, national ID numbers, PINs, and credit card numbers, part of CANTV’s proxy server, and some text messages from its mobile subsidiary, Movilnet. The incident was reported on July 29, 2011, by the data breach tracker databreaches.net and was part of a broader SwichSmoke campaign targeting Venezuelan government entities. There is no public record of an official acknowledgment by CANTV.

SwichSmoke