Petróleos de Venezuela, S.A. (PDVSA), Venezuela's state-owned oil company, experienced a significant cyberattack that disrupted its export operations and administrative systems. While PDVSA publicly claimed that the attack was limited to administrative functions and did not affect operational continuity, internal communications and multiple media reports indicate that the disruption was more severe, with systems managing the main crude terminal offline and oil cargo deliveries suspended. The company attributed the attack to foreign actors, specifically blaming the United States and domestic conspirators, and linked the incident to recent geopolitical tensions, including the U.S. seizure of a sanctioned Venezuelan oil tanker.
Despite PDVSA's assurances of minimal impact, sources cited by Reuters and Bloomberg reported that all systems were down, with staff instructed to disconnect from the network and shut down computers. Some employees referred to the incident as a ransomware attack, though no technical details or attribution have been independently confirmed by cybersecurity experts. The attack has drawn international attention due to its timing amid escalating U.S.-Venezuela tensions and the critical role of PDVSA in Venezuela's economy and international relations.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
By Monday, restoration work was still ongoing, but PDVSA had begun resuming deliveries using manual processes. By December 17, reports said some cargoes, including Chevron U.S.-bound shipments, were loading again after the initial shutdown.
After disclosing the incident, PDVSA said the attack targeted administrative systems and claimed operational continuity was maintained. The company accused the United States and domestic collaborators of trying to destabilize Venezuela and undermine its energy sector, though no public evidence was provided.
As part of its response, PDVSA instructed employees to shut down computers, disconnect external devices, and disable Wi‑Fi and Starlink connections. Reports also said antivirus remediation and network isolation measures contributed to operational disruption.
Over the weekend of December 13-14, PDVSA suffered a cyberattack that affected administrative and export-management systems. Reports from internal sources said key systems tied to cargo handling and the main crude terminal went offline, halting or suspending oil loadings and deliveries.
Shortly before the cyber incident, U.S. forces seized a tanker carrying Venezuelan crude linked to PDVSA, escalating tensions between Washington and Caracas. Multiple reports cite this seizure as the geopolitical backdrop to the later attack.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
5 references tracked. Mallory keeps watching after this page renders.
thecyberthrone.in
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourcedarkreading.com
Open sourcesecurityaffairs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.