The United States conducted a large-scale military operation in Venezuela, targeting multiple locations including military installations and residential areas. The raid involved airstrikes, with Bellingcat identifying remnants of an AGM-88 missile at a residential building in Catia La Mar, resulting in civilian casualties. US forces reportedly captured President Nicolas Maduro and First Lady Cilia Flores, with the operation causing significant fatalities among both civilians and military personnel, including Cuban and Venezuelan soldiers. The attack also followed a series of strikes on alleged drug boats in the region.
Amid the military action, speculation arose regarding possible cyber operations preceding the raid. A red team engineer observed unusual BGP routing activity involving Venezuela's state-owned telecom, CANTV, on the day before the attack. The anomalies suggested the potential for a man-in-the-middle attack, possibly enabling surveillance or disruption of communications. While Cloudflare reviewed these claims and expressed skepticism about direct links between the BGP incidents and the US operation, the timing and nature of the network events have prompted calls for further investigation into the electronic aspects of the attack.

See the actors and campaigns active against you right now.
6 events from the most recent confirmed update back to the earliest known activity.
On 2026-01-08, Cloudflare principal network engineer Bryton Herdes said the unusual routing activity was consistent with a common BGP route leak rather than a deliberate cyberattack. He assessed it as unrelated to the US military operation in Venezuela.
Following the strike, the US Department of Defense said a Battle Damage Assessment was underway and did not confirm whether the civilian residential building had been an intended target. This was the first official response described in the reporting.
In findings published on 2026-01-07, Bellingcat reported that remnants recovered from the Catia La Mar strike site matched an AGM-88 series missile. Because Venezuela does not operate that munition, the evidence strongly suggested US involvement in the strike.
Around the time of the US operation, observers noted unusual BGP routing activity involving Venezuela's CANTV network (AS8048). The anomalies prompted speculation that telecom infrastructure had been targeted to support surveillance or disruption during the incursion.
During the 2026-01-03 operation, an apartment complex in Catia La Mar was struck, causing civilian casualties. Rosa Gonzalez, 79, was killed and other residents were severely injured.
On 2026-01-03, the US military carried out a large-scale operation in Venezuela, striking multiple locations including military installations and areas around Caracas. The raid also reportedly destroyed several Venezuelan air defense systems, including Buk-M2E launchers.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.