Guatemala Military Intelligence Directorate Listed by cyclops Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Guatemala Military Intelligence Directorate Listed by cyclops Ransomware Group (reported June 30, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Ransomware groups continue to target government and defence-linked organisations, treating internal networks as sources of leverage and potential intelligence value. In that landscape, listings on criminal leak sites have become a recurring signal that sensitive material may have left official control, even when independent confirmation remains limited.
On 30 June 2023, the Guatemala Military Intelligence Directorate was listed by the ransomware group known as cyclops. Public reporting describes the incident as a ransomware attack in which internal files were allegedly exfiltrated. The number of people affected is unknown, and fuller technical detail has not been disclosed. For an organisation tied to national defence intelligence, any confirmed or claimed compromise of internal material carries weight for operational security and for individuals whose information may appear in such holdings.
Inside the incident
According to available public facts, the Guatemala Military Intelligence Directorate was named on a cyclops listing dated 30 June 2023. The reported characterisation is that internal files were allegedly exfiltrated in a ransomware attack. No public figure has been given for the volume of data, the number of systems involved, or the count of individuals whose records may have been included. Methods of initial access, dwell time, encryption status, and any ransom demand are undisclosed in the material provided. The listing itself should be read as a claim by the group rather than as independently verified confirmation of every asserted detail.
The broader institutional context noted in reporting places the directorate within Guatemala’s defence structure. The Guatemalan Armed Forces comprise the National Army, the National Defense Navy (including Marines), the Air Force, and the Presidential Honor Guard, with the Ministry of National Defence responsible for budget, training, and policy and based in Guatemala City. Beyond that framing, incident-specific forensics and official attribution statements are not part of the disclosed record summarised here.
Inside cyclops
Cyclops is known publicly as a ransomware actor that follows a pattern common to many contemporary groups: intrusion, data theft, and pressure through the threat of publication on a dedicated leak site. Such groups typically advertise victims to amplify urgency and to demonstrate that exfiltration occurred. Their operations often rely on compromised credentials, exposed remote services, or other initial footholds, followed by lateral movement and packaging of files for removal from the network.
For this incident, the only actor-specific assertion in the facts is the listing of the Guatemala Military Intelligence Directorate and the description of internal files exfiltrated in a ransomware attack. No further statements attributed to cyclops about this victim—such as sample file counts, screenshots, or deadlines—are included in the provided record. Claims on leak sites are therefore treated as unverified assertions unless separately confirmed by the victim organisation or by independent investigation.
Guatemala Military Intelligence Directorate and its sector
Military intelligence directorates exist to collect, analyse, and protect information relevant to national defence, internal security coordination, and the safety of armed forces personnel and operations. In Guatemala, that function sits within a defence establishment that includes land, naval, and air components under ministerial oversight. Organisations of this type routinely handle classified and unclassified internal material: operational reporting, personnel and administrative records, correspondence, logistics data, and analytical products.
A breach—or a credible claim of one—matters because intelligence and defence bodies are high-value targets. Exposure can affect not only institutional secrecy but also the safety and privacy of service members, civilian employees, and third parties named in files. Even when the precise scope remains unknown, the sector’s sensitivity means that any confirmed exfiltration of internal files warrants careful assessment of what left the organisation and who might be affected.
What was likely exposed
The facts name the exposed material as internal files exfiltrated in a ransomware attack. No inventory of file types, no classification levels, and no confirmation of personal data categories have been disclosed. People affected are listed as unknown.
Organisations in military intelligence and defence administration typically hold personnel records, identity and contact details, internal memoranda, operational and administrative documents, and systems-related information. It is reasonable to expect that a tranche of “internal files” could include some mix of those categories, but it is not established fact that any specific field—names, national ID numbers, medical data, or operational plans—was present in the stolen set. Exact contents remain unconfirmed.
The real-world impact
For the organisation, loss of control over internal files can mean operational risk, the need to rotate credentials and access paths, and potential exposure of methods or relationships that were not intended for public or adversary view. Remediation may require sustained incident response, coordination across defence components, and review of what external parties could learn from the material.
For individuals who might appear in such files—service members, civilian staff, contractors, or people mentioned in reports—the practical risks include unwanted contact, social engineering, identity misuse, or reputational harm if personal or professional details surface. Because the scale and data types are not fully public, those risks cannot be quantified from the available facts alone. The absence of a published affected-person count does not mean no one is affected; it means the public record does not yet define the population.
If your data was in this claimed breach
If you have a connection to Guatemalan defence or intelligence institutions and are concerned your information may have been involved, treat the situation as a possible exposure rather than a claimed personal compromise. Monitor financial and government accounts for unusual activity, be cautious of unexpected messages that reference military or administrative details, and consider updating passwords and enabling stronger authentication on important email and service accounts. Preserve any official notices you receive from authorities.
You can also run a free exposure scan of your email address to check whether your information has already appeared in known breach datasets, which may help you prioritise further monitoring and credential changes.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
important information(Knight) Listed by cyclops Ransomware GroupPechexport Listed by cyclops Ransomware GroupCvlan Listed by cyclops Ransomware GroupSuperloop ISP Listed by cyclops Ransomware GroupLatest breaches
Publicly posted by cyclops — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.