Banco de Venezuela, S.A.
Financials · State-owned bancodevenezuela.com
- Incidents
- 3
- High impact
- 3
- First seen
- Sep 15, 2021
- Latest seen
- Mar 28, 2025
Linked incidents
Cybercriminals in the Andes Use Phishing to Empty Accounts Linked to Banco de Venezuela and Sistema Patria
On March 28, 2025, reports citing the CICPC and authorities in Táchira described the dismantling of Los Ciberandinos, a gang that used phishing, mirror sites, fake profiles, and foreign WhatsApp numbers to obtain credentials and drain accounts associated with Banco de Venezuela and the Patria System/Platform. Sources describe a single criminal organization, a single investigation, and a common pattern of credential theft, transfers to third parties, currency conversion, and the purchase of goods. Banco de Venezuela and Patria remain platforms that were exploited or impersonated, not confirmed infrastructure breaches. More than 200 victims were reported, including the municipal governments of San Cristóbal and Jauregui; six people were arrested in total (including a minor); and an alleged leader has fled to Colombia.
LockBit 3.0 Claims Responsibility for Attack on Banco de Venezuela, S.A.
In April 2023, Banco de Venezuela, S.A. was the target of a ransomware attack attributed to the Lockbit 3.0 group. The threat actors added the bank to their dark web leak site on April 19, 2023, threatening to publish stolen confidential information—including Venezuelan ID cards, tax documents (RIF), INCES certificates, and corporate financial records— by May 10, 2023, unless a ransom in cryptocurrency was paid. In response to the incident, the bank issued a statement assuring its customers that its platforms and electronic channels were operating normally with full integrity and security, although it neither explicitly confirmed nor denied the data exfiltration.
Massive Cyberattack Against Banco de Venezuela, S.A. (September 2021)
In mid-September 2021, Banco de Venezuela suffered a massive cyberattack that severely disrupted its financial services and online platform for several days. Although the Venezuelan government officially characterized the incident as a “terrorist attack” and a “massive hack” intended to tamper with banking data and sabotage the economy, the specific threat actor and the exact nature of the attack—such as whether ransomware was deployed or data was exfiltrated—remain unverified.
