Loading...

Threat Actor Claims Access to Ecuador Electoral Registry Systems

Screenshot of a forum post claiming unauthorized access to Ecuador's National Electoral Council (CNE) systems. The post alleges full SSH access to internal infrastructure, compromise of the electoral registry database, exfiltration of 13.5 million voter records, and the ability to alter voter data. Several supporting screenshots and a network architecture diagram are included alongside a ransom demand.
Threat actor post alleging compromise of Ecuador's electoral infrastructure, including claimed access to voter registry systems and approximately 13.5 million voter records. BreachNews has not independently verified the claims.

A threat actor claims to have compromised internal systems belonging to Ecuador’s National Electoral Council (CNE), alleging full access to voter registration infrastructure and the exfiltration of more than 13.5 million voter records.

The claim was posted on a cybercrime forum by a threat actor who alleged unauthorized access to multiple systems within the CNE environment.

BreachNews has not independently verified the authenticity of the claims or confirmed that the alleged access originated from CNE systems.

Compilation image created by BreachNews showing redacted screenshots allegedly provided by a threat actor claiming access to Ecuador's electoral systems. The image includes a network architecture diagram, redacted SSH and Oracle database screenshots, a reported voter record count of 13.5 million records, and a summary of the actor's claims. Sensitive infrastructure details, connection information, and operational data have been obscured.
Redacted compilation of screenshots shared by a threat actor claiming access to Ecuador’s National Electoral Council infrastructure. BreachNews redacted sensitive technical details and has not independently verified the authenticity of the evidence or the alleged compromise.

Actor claims access to voter registry infrastructure

According to the forum post, the threat actor allegedly gained access to internal CNE systems through a RAT-based intrusion and later pivoted across additional network assets.

The actor claims to have obtained SSH access to internal hosts, accessed Oracle database systems tied to the electoral registry, and extracted 13,504,210 voter records.

Redacted screenshots published alongside the claim appear to show command-line access to internal systems, database enumeration activity, and what the actor describes as voter registry infrastructure.

The screenshots also appear to reference electoral database services and record counts, though BreachNews cannot independently verify the authenticity of the images.

Threats extend beyond data theft allegations

Unlike many breach claims focused solely on data exfiltration, the threat actor alleges the compromise could affect operational election systems.

The post claims the voter registry environment is interconnected with systems responsible for election result transmission and consolidation. The actor further alleges the ability to add, modify, or delete voter records and claims persistence mechanisms remain active within the environment.

The threat actor demanded 4 BTC and threatened data destruction, backup poisoning, and voter database manipulation if negotiations are not initiated.

At the time of publication, no evidence has been provided publicly to substantiate the more serious claims regarding election system manipulation.

Claims raise concerns over election infrastructure security

The allegations go beyond a conventional database breach. If accurate, unauthorized access to voter registration infrastructure could create risks affecting both sensitive citizen data and public confidence in electoral processes.

Election systems remain high-value targets for cybercriminals, hacktivist groups, and nation-state actors due to their political significance and potential impact on public trust.

The claim also comes amid broader concerns surrounding cyberattacks targeting government and critical infrastructure organizations. Earlier this year, BreachNews reported on a confirmed breach of FBI wiretap systems, highlighting continued interest in sensitive public sector networks.

CNE had not issued any public statement regarding the allegations at time of publication.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Related Posts

Newsletter signup

Get the latest data breach and security news.

Please wait...

Thank you for signing up!

BREACHNEWS.COM

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site