Fmp.gob.pe Listed by cloak Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Fmp.gob.pe was listed by the cloak ransomware group on December 20, 2024, after internal files were exfiltrated in a ransomware attack. The number of people affected has not been disclosed; anyone who may have had dealings with the organisation should check for signs of compromise and take appropriate protective steps.
Ransomware groups continue to target public-sector organizations that hold sensitive citizen data, using double-extortion tactics that combine encryption with the threat of public data leaks. Against this backdrop, the Peruvian housing-finance entity Fmp.gob.pe appeared on a ransomware leak site in late 2024, underscoring the persistent pressure on government-linked financial services across Latin America.
On 20 December 2024 the cloak ransomware group listed Fmp.gob.pe, claiming to have exfiltrated internal files during a ransomware attack. The number of people affected remains unknown, and public detail on the precise scope of the incident is limited. The listing itself constitutes an unverified claim by the group rather than an independently confirmed breach disclosure.
Breaking down the breach
According to the available record, Fmp.gob.pe was listed by the cloak ransomware group on 20 December 2024. The group asserts that internal files were exfiltrated as part of a ransomware attack. No further technical details—such as the initial access vector, the duration of unauthorized access, the volume of data taken, or any ransom demand—have been publicly disclosed. The number of individuals potentially affected is recorded as unknown. Because the only source of the allegation is the group’s own leak-site listing, the claim has not been independently verified in the public record.
The group behind it: cloak
Cloak is a ransomware operation that has appeared on public threat-intelligence trackers as a double-extortion actor. Like many contemporary ransomware groups, it typically encrypts victim systems and simultaneously steals data, then threatens to publish the material on a dedicated leak site if payment is not made. Public reporting on cloak has noted its use of standard ransomware tooling and its practice of posting victim names and sample files to pressure organizations. In the present case the group claims to have obtained internal files from Fmp.gob.pe; no additional statements or sample data releases specific to this victim have been documented beyond that listing.
Who is Fmp.gob.pe?
Fmp.gob.pe is the online presence of Fondo MIVIVIENDA, a Peruvian government initiative established to expand access to affordable housing. The fund designs and channels financial products—primarily mortgage loans and housing-support programs—aimed at low- and middle-income families. It works with banks and other intermediaries to promote sustainable urban development and improve living conditions. As a public-sector financial entity, it routinely processes applications that contain personal identification, income documentation, property details and banking information. A compromise of such an organization therefore carries implications both for the individuals who rely on its programs and for the integrity of Peru’s housing-finance infrastructure.
The information in question
The only data category named in the public record is “internal files exfiltrated in a ransomware attack.” No inventory of specific file types, databases or personal-data fields has been released. Organizations of this kind typically hold applicant identity documents, contact details, income and employment records, credit histories, property valuations and loan-account information. Whether any of those categories were among the files claimed by cloak remains unconfirmed. Until official verification is provided, the exact contents of the alleged exfiltration cannot be stated as fact.
Why it matters
For individuals who have applied for or received housing support through Fondo MIVIVIENDA, the possible exposure of internal files raises concrete risks: identity theft, fraudulent loan applications, phishing campaigns that exploit knowledge of an applicant’s housing status, and long-term credit-file damage. Even if only administrative or operational documents were taken, those materials can still reveal internal processes, partner bank relationships or system configurations that adversaries could reuse in later attacks. For the organization itself, the incident may disrupt service delivery, erode public trust in a government housing program, and trigger regulatory scrutiny under Peru’s data-protection framework. Because the scale of the alleged compromise is unknown, the full extent of these risks cannot yet be quantified.
Were you affected?
If you have ever submitted an application or held a loan through Fondo MIVIVIENDA, treat the listing as a prompt to review your accounts rather than as confirmed proof of personal exposure. Monitor bank and credit statements for unfamiliar activity, enable multi-factor authentication on financial and email accounts, and be alert to unsolicited messages that reference housing applications or loan balances. You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach data sets. Official notifications, if any, will come from Fondo MIVIVIENDA or Peruvian authorities; until such notice arrives, the prudent course is heightened vigilance rather than assumption of compromise.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
suffolkva.us Listed by cloak Ransomware GroupTown of Ponoka Listed by cloak Ransomware GroupF************.pe Listed by cloak Ransomware GroupPonoka.ca Listed by cloak Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Fmp.gob.pe Listed by cloak Ransomware Group →
Publicly posted by cloak — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.