JUST IN: Andrej Karpathy, a top AI scientist at Anthropic, is reportedly barred from accessing the company’s most advanced AI model because he is not a U.S. citizen.
🚨 CYBER INTELLIGENCE ALERT: CRITICAL COMPROMISE OF THE MINISTRY OF FINANCE - GUATEMALA 🇬🇹
⚠️ MASSIVE EXFILTRATION OF 130K RECORDS AND 324GB OF SENSITIVE DOCUMENTATION
[STATUS: UNDER INVESTIGATION]
The threat actor "GordonFreeman" of LAT4MFUCK3RS has claimed full compromise of the RGAE (General Registry of State Acquisitions) system of the Guatemalan Ministry of Finance. The attacker claims to have exploited critical API-level vulnerabilities to bypass perimeter protections (WAF/Cloudflare) and extract the complete database of suppliers and registered individuals.
👤 Threat Actor: LAT4MFUCK3RS., GordonFreeman
🎯 Affected Entity: Ministry of Public Finance (RGAE).
📂 Data Volume: 130,000 records (2020-2026) + 235,000 PDF files.
📦 Total Size: 324.5 GB of exfiltrated information.
📊 ANALYSIS OF EXPOSED INFORMATION (PII AND DOCUMENTARY)
The leak includes not only structured data, but also legal and financial documentation that compromises the identity of thousands of citizens and companies:
Structured Data (Database):
Full names, Tax Identification Number (NIT), National Identification Code (CUI).
Residential addresses, telephone numbers, and email addresses.
Type of organization (Individual/Legal Entity).
Critical Documentation (PDF Files):
University degrees and scanned copies of national identity cards.
SAT invoices, tax clearance certificates, and business licenses.
Company incorporation documents and notarial deeds.
Bank statements, balance sheets, and administrative contracts.
🔍 TECHNICAL EVIDENCE AND VECTORS
The attacker detailed the methods used, confirming a systemic flaw in the portal's security architecture.
🛡️ WAF Evasion: Use of simulated legitimate traffic to avoid volume-based blocking.
🔓 API Vulnerabilities:
IDOR/BOLA: Unauthorized access to request sections (/api/Request/GetSections).
Open APIs: Unauthenticated endpoints directly connected to SAT systems (/api/sat/email).
🛡️ MITIGATION AND RECOMMENDATIONS
🛑 Urgent API Closure: The Ministry of Finance must audit and immediately close the exposed API endpoints and reconfigure authentication under the principle of least privilege.
⚠️ Massive Risk of Impersonation: Given the exfiltration of DPIs and signatures, banking institutions and the SAT (Tax Administration Service) must strengthen identity verification controls for both in-person and remote transactions.
🔒 Social Engineering Alert: The 130,000 affected individuals are at extreme risk of targeted phishing attacks or extortion, as attackers possess their physical addresses and financial solvency details.
⚡ MONITORING
🌐 Intelligence Platform: https://t.co/wk9bZJ3laQ
#CyberSecurity #Guatemala #DataBreach #MinistryOfFinance #RGAE #SAT #PII #CyberAlert #VECERT #LAT4MFUCK3RS
🚨 GUATEMALA UNDER DIGITAL SIEGE: AN UNPRECEDENTED 2026 FOR CYBERATTACKS 🇬🇹💻🛡️
What was once considered a distant or sporadic threat has today become a critical reality. 2026 has emerged as the year with the highest concentration of cybersecurity incidents in Guatemala's recent history, surpassing all statistical forecasts.
From government infrastructure to the most prestigious educational institutions, the country finds itself at the epicenter of a digital offensive coordinated by multiple threat actors.
📊 A Snapshot of the Current Impact
According to monitoring by VECERT Threat Intelligence, the numbers speak for themselves:
4 Critical Incidents in a single week (April 2026).
9 Government and Educational Domains compromised in the recent period.
Over 172,000 lines of data exfiltrated, including financial information, PII, and national security records.
🔍 The Most Alarming Incidents
The diversity of the targets demonstrates that no sector is immune:
Education (50% of attacks): Massive data breaches at USAC (SIIF) and Rafael Landívar University have exposed sensitive data belonging to thousands of students and faculty members.
Defense and Security: The compromise of DIGECAM—resulting in the leak of 62,000 firearm serial numbers—poses a direct risk to public and national security.
Government: Unauthorized access to the Ministry of Labor and Social Welfare and the Ministry of Defense (MINDEF) by threat actors such as Izanagi and X Forum Bot.
👥 Identified Threat Actors
The criminal ecosystem has evolved. These are no longer random attacks, but rather the work of specialized profiles:
MrGoblinciano: The primary disruptor within the education sector.
GordonFreeman: Responsible for the largest defense-related data leak of the year.
Izanagi: Focused on breaching public administration systems. Evil Zone and X Forum Bot: Automating the Collection and Sale of Leaked Data
Guatemala had not anticipated a volume of attacks of this magnitude for this year. The accelerated digitalization of institutions was not accompanied by commensurate security safeguards, leaving vulnerabilities that are now being systematically exploited.
🛡️ STATUS: SURVEILLANCE. Institutions must shift from a reactive stance to a proactive one. Constant monitoring and threat intelligence are the only tools capable of curbing this trend.
#CyberSecurity #Guatemala #DataBreach #InfoSec #ThreatIntelligence #VECERT #USAC #Landivar #DIGECAM #GobiernoGT 🇬🇹🛡️⚠️🚨🏛️
🚨 CRITICAL CYBERINTELLIGENCE ALERT: MASSIVE COMPROMISE OF EDUCATIONAL INFRASTRUCTURE – MINISTRY OF EDUCATION (GUATEMALA) 🇬🇹🎓📄🔓
A massive, high-impact breach has been detected targeting the servers of the Ministry of Education of Guatemala. Threat actor "GordonFreeman"—a member of the group L4TAMFUCK3RS—claims to have infiltrated the institutional network, exfiltrating a massive volume of sensitive documents.
🏢 Affected Entity: Ministry of Education (MINEDUC), Guatemala.
👤 Threat Actor: GordonFreeman (L4TAMFUCK3RS).
📂 Leak Volume:
178 GB of total data.
150,000 exfiltrated PDF files.
📅 Publication Date: April 30, 2026.
📊 Breach Scope (PII and Sensitive Data)
The attacker claims to possess access to highly sensitive information regarding every user within the Ministry:
Personal Documentation: 150,000 PDF files containing administrative, personal, and educational records pertaining to students, teachers, and administrative staff.
Network Persistence: The actor claims to maintain internal access to the institutional network, despite existing state security protocols.
Proof of Concept (PoC): A sample of 2.4 GB (approximately 1,979 documents) has been released to validate the authenticity of the breach.
🛡️ Immediate Response Recommendations
🔒 File Server Isolation: The MINEDUC technical team is urged to isolate document repositories to halt any ongoing data exfiltration.
🔑 Privileged Account Audit: Review all access logs for the affected servers and revoke any suspicious sessions.
Monitor: https://t.co/wk9bZJ2Nli
#CyberSecurity #Guatemala #MINEDUC #DataBreach #L4TAMFUCK3RS #GordonFreeman #InfoSec #Privacy #VECERT #CyberAttack 🇬🇹🛡️⚠️🚨🎓
🚨 INTELLIGENCE ALERT: INTRUSION AND DEFACEMENT CAMPAIGN – GOVERNMENT TARGETS (GUATEMALA) 🇬🇹💻⚠️
A series of active compromises targeting critical infrastructure and government portals in Guatemala has been detected. The threat actor, operating through a Telegram channel, has leaked administrative access credentials and executed defacement attacks (visual alteration) on service portals.
Threat Actor: NemorisHacking
🌐 Origin: Identified as being linked to the group JXLLTEAM, which is associated with the alias KeyBreaker.
⚠️ Status: ACTIVE OFFENSIVE.
📅 Date: April 30, 2026.
📊 TTPs and Methodology (Tactics, Techniques, and Procedures)
The actor employs public exposure techniques and credential compromise to demonstrate control over the systems:
Attack Vector: Probable compromise via information stealers or brute force, given that user credentials and passwords for official portals have been published in plaintext.
Web Defacement: Alteration of legitimate websites to display messages from the group, utilizing archiving services (https://t.co/iD3CoYkvfx) to preserve evidence of the attack.
Credential Exfiltration: Direct publication of administrative login credentials on Telegram channels to facilitate third-party access to State systems.
Use of External Forums: Utilization of free forum platforms (https://t.co/gClD1r6eWu, https://t.co/nbo2nfYcI1) to centralize their "special services" and operations.
🎯 Identified Victims
The attack has impacted key institutions within the Guatemalan government:
Office of the Attorney General (PGN):
Asset: https://t.co/S9OQ5SKy37.
Compromise: Leak of username and password.
Superintendence of Telecommunications (SIT):
Asset: https://t.co/O8rnOK6GhM.
Compromise: Exposure of access credentials.
Financial Services / Virtual POS:
Asset: https://t.co/PrEjFiIvUs. Attack: Confirmed defacement across multiple platform routes.
🛡️ Immediate Response Recommendations
🔒 Credential Reset: The PGN and SIT are urged to immediately invalidate compromised accounts and perform a global rotation of administrative passwords.
🔑 MFA Implementation: Enable Multi-Factor Authentication on all single-window portals and citizen services.
Monitor: https://t.co/wk9bZJ2Nli
#CyberSecurity #Guatemala #PGN #SIT #DataBreach #Defacement #NemorisHacking #JXLLTEAM #VECERT #InfoSec 🇬🇹🛡️⚠️🚨🏛️
🚨 CRITICAL CYBERINTEL ALERT: MASSIVE STUDENT DATA EXFILTRATION – UNIVERSIDAD DA VINCI (GUATEMALA) 🇬🇹🎓📂🔓
A massive data leak has been detected affecting the Universidad Da Vinci de Guatemala (UDV). Threat actor "Dianna" claims to have compromised the university's systems, citing severe deficiencies in its Web Application Firewall (WAF) security.
🏢 Affected Entity: Universidad Da Vinci de Guatemala (https://t.co/DBCuBWr2dk).
👤 Threat Actor: Dianna.
📂 Leak Volume:
98,099 JSON files containing student information.
16,000 student photographs.
🛠️ Exposure Vector: APIs exposed on the university's virtual campus subdomain (https://t.co/q0tUNXsDQn).
📅 Publication Date: May 2026.
📊 Breach Scope (PII and Biometrics)
The exfiltrated information enables comprehensive and detailed profiling of the student body:
Identity and Legal: First names, surnames, ID numbers, tax ID numbers (CIF), and marital status.
Biographical Data: Date and place of birth.
Geolocation: Full residential address, department, municipality, and zone.
Direct Contact: Mobile phone numbers, landline numbers, alternative contact numbers, and email addresses.
Visual Identification: 16,000 photographs linked to student profiles.
🛡️ Immediate Response Recommendations
🔒 API Shutdown: Universidad Da Vinci must immediately identify and restrict access to the APIs on https://t.co/q0tUNXsDQn that are serving data without authentication.
🔑 WAF Audit: Review and harden Web Application Firewall rules to prevent the mass scraping of JSON and multimedia files.
👁️ Community Notification: Inform students about the data leak so they may exercise extreme caution regarding suspicious phone calls or emails. Monitor: https://t.co/wk9bZJ2Nli
#CyberSecurity #Guatemala #UniversidadDaVinci #UDV #DataBreach #HigherEducation #PII #VECERT #InfoSec #Unverified 🇬🇹🛡️⚠️🚨🎓
🚨 CRITICAL CYBER THREAT ALERT: HEALTHCARE INFRASTRUCTURE COMPROMISE – INE GUATEMALA 🇬🇹⚕️📊 [STATUS: UNCONFIRMED]
A post has been detected from the threat actor NemorisHacking, claiming to have breached the data portal of Guatemala's National Institute of Statistics (INE). The actor asserts that they have exfiltrated sensitive information related to health records and personal data.
🏢 Affected Entity: National Institute of Statistics (INE), Guatemala.
👤 Threat Actor: NemorisHacking.
🛠️ Compromised Asset (Alleged): Data portal (https://t.co/kIrqkydWxA) and the https://t.co/sl0shQS912 epidemiological management platform.
📂 Breach Volume: Over 10,000 individual records.
📅 Date of Detection: May 1, 2026.
⚠️ Status: UNCONFIRMED.
📊 Visual Evidence Analysis
[The evidence] shows access to an instance of the https://t.co/sl0shQS912 platform (a WHO tool for outbreak investigation):
Sensitive Data: The dashboard displays sections for "Cases," "Contacts," "Laboratory Results," and "Events."
Geographic Context: A notification regarding active outbreaks in Guatemala and El Progreso—specifically related to COVID-19—is visible.
System Administration: The actor demonstrates access to data visualization and referral management features, suggesting a compromise at the user or administrator privilege level.
🛡️ Immediate Response Recommendations
🔒 https://t.co/sl0shQS912 Forensic Audit: The INE and the Ministry of Health of Guatemala are urged to review access logs for the https://t.co/sl0shQS912 platform and identify the point of compromise.
🔑 Session Termination and MFA: Force the termination of all active sessions on the data portal and mandate multi-factor authentication (MFA) for all technical personnel.
#CyberSecurity #Guatemala #INE #SaludPublica #DataBreach #NemorisHacking #GoData #VECERT #InfoSec #SinConfirmar 🇬🇹🛡️⚠️🚨⚕️
🚨 NATIONAL SECURITY ALERT: DIGITAL INFRASTRUCTURE COLLAPSE – GUATEMALA (RENAP & SAT) 🇬🇹🏛️🚗🔓
The most severe threat to Guatemala's digital sovereignty in its history has been detected. Threat actor GordonFreeman, in coordination with the group Team L4TAMFUCKERS, claims to have breached the entirety of the RENAP and SAT systems, exfiltrating the identity data of the entire population and the country's complete vehicle registry.
🏢 Affected Entities:
RENAP: National Registry of Persons.
SAT: Superintendence of Tax Administration.
👤 Threat Actors: GordonFreeman, Izanagi, cantpwn, and YoSoyGroot (Team L4TAMFUCKERS).
📊 Breach Volume:
18 Million Records (RENAP): Birth, marriage, and death certificates, as well as biometric and sensitive data for the entire nation.
5.6 Million Vehicle Records (SAT): Ownership data, Tax ID numbers (NIT), names, tax addresses, chassis numbers, engine numbers, license plates, and electronic ownership certificates.
📊 Breach Scope (Absolute Exposure)
The leak grants total control over citizens' identities and property:
Civil Identity: Access to the complete database of Guatemalan citizens, spanning from birth to death.
Vehicle Information: Exhaustive details on every vehicle in the country, including Electronic Circulation Cards and Titles of Ownership.
Persistence: The attackers claim to have established persistence within the infrastructure, meaning they maintain hidden access points even if attempts are made to close known vulnerabilities.
🛡️ Immediate Response Recommendations
🔒 Declaration of Digital Emergency: The Government of Guatemala must immediately activate its national security and cyber defense protocols.
🔑 Privileged Account Audit: It is imperative to conduct a threat hunt to locate the persistence points and web shells that the group claims to have installed.
Monitor: https://t.co/wk9bZJ2Nli
#CyberSecurity #Guatemala #RENAP #SAT #DataBreach #L4TAMFUCKERS #GordonFreeman #NationalEmergency #VECERT #InfoSec 🇬🇹🛡️⚠️🚨🏛️
@MasQueOcaTienda ¿Por qué eliminaron el blog con las actualizaciones del status de high frontier? Como puedo saber cuál es el estado de mi pedido. Hago dos tweets porque hasta ahora no han contestado lo que mando en el form de contacto de su página.