Inter (Venezuela's largest internet provider) Listed by N0n Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Inter, Venezuela’s largest internet provider, was listed by the N0n ransomware group on 18 September 2026. An undisclosed number of people may be affected; anyone who has an account with the provider should check for unusual activity and secure their credentials.
On September 18, 2026, the ransomware group N0n listed Inter, widely described as Venezuela’s largest internet service provider, on its leak site. The listing is an extortion-style claim published by the group; it is not an independent verification that systems were compromised or that any particular files left the company. As of writing, Inter has not publicly confirmed the claim.
What is known so far is therefore limited to what appears on that listing: a named telecommunications operator in Venezuela, a set of assertions about subscriber and network material, pressure language about severed traffic, and an active deadline. For customers and partners, the practical question is how to treat an unverified claim of this kind without treating the attackers’ marketing as settled fact.
What the listing says
According to the N0n listing, Inter is presented as a telecommunications and ISP target in Venezuela. The group claims the material at issue includes more than 15,300,000 subscriber connection-record entries; tens of thousands of subscriber addresses paired with services those subscribers contacted; a complete internal network map across regional operations; and evidence of core infrastructure configuration. The listing also states that network traffic remains severed until settlement, and it marks the case as active with a deadline of 2026-09-20 18:39 UTC.
The number of people affected is unknown in public reporting tied to this record. Method of intrusion, dwell time, and independent confirmation of file contents are not disclosed outside the group’s own description. Those description lines should be read as the claimant’s assertions, not as an audited inventory. Inter has not, as of writing, publicly confirmed the incident or the accuracy of the listed items.
Who is N0n?
N0n appears in public reporting as a ransomware and extortion-style actor that uses leak-site pressure: name a victim, assert possession of data or disruptive access, set a deadline, and threaten publication or continued disruption if payment demands are not met. Groups in this category often mix real stolen material, recycled older dumps, exaggeration, and pure bluff; a listing alone does not prove which of those applies in any single case.
For this Inter entry specifically, only the claims on the listing are available in the facts at hand. There is no confirmed technical write-up in this record that independently validates how N0n supposedly obtained access, whether traffic was actually cut, or whether the stated volumes exist as described. Readers should treat “the group claims” and “the listing states” as the accurate framing until a company statement, regulator notice, or other primary confirmation appears.
About Inter
Inter is identified in the listing context as a major internet and telecommunications provider in Venezuela. Organisations in this sector typically operate access networks, subscriber provisioning and billing systems, routing and core infrastructure, and customer-support platforms. They sit on paths that carry everyday connectivity for households and businesses, so claims involving an ISP attract attention even when those claims remain unverified.
A leak-site listing against a national-scale provider matters because of the sensitivity of connectivity records and the potential operational impact if service disruption claims were true. That consequence is about the role such a company plays in daily life and commerce; it is not proof that any particular allegation on the N0n page is accurate. Public detail beyond the listing’s framing of Inter as Venezuela’s largest internet provider is limited in the material provided for this article.
The information in question
Named data types in the structured breach fields are recorded as not disclosed in the usual categorical sense; the narrative summary on the listing, however, makes specific claims. N0n claims subscriber connection records on a very large scale, subscriber address material linked to contacted services, a full internal network map across regional operations, and core infrastructure configuration evidence. None of that has been independently confirmed in the facts given here, and the exact contents of any alleged package remain unconfirmed.
If files of the kinds ISPs commonly hold were involved in a real incident, firms in this sector typically retain account identifiers, service plans, installation or billing addresses, technical logs related to sessions or connections, and internal diagrams or configurations used to run the network. Those categories explain why an ISP listing raises concern. They are not a statement that Inter’s systems yielded any specific field or that the volumes N0n advertises are correct.
The real-world impact
For individuals, the conditional risk is misuse of contact and location-linked subscriber information, targeted phishing that references real service details, account-takeover attempts against email or payment channels tied to an ISP bill, and social engineering that cites supposed connection history. For businesses that buy connectivity from a large provider, conditional risks include exposure of circuit or site details and follow-on fraud against staff who manage telecom accounts.
For the organisation, a public extortion listing can create reputational pressure, customer anxiety, and operational distraction whether or not the underlying claim is fully true. The listing’s own language about severed traffic until settlement is a pressure tactic; whether traffic was actually interrupted is not established by the leak-site post alone. A listing does not establish negligence, security culture, or engineering quality at the named company; it establishes only that a group chose to publish an accusation and a deadline.
Scale figures such as “15,300,000+” entries and “tens of thousands” of addresses are the group’s claimed numbers. People affected remain unknown in independent terms. Until confirmation exists, impact assessment stays conditional: if subscriber-related material were taken and published, harm would track the usual patterns for telecom data; if the claim is inflated or false, the main immediate harm is confusion and fear driven by the listing itself.
If your data was involved
Inter has not publicly confirmed this incident as of writing, so no one should assume their records are in a dump solely because N0n named the company. If you are a customer or former customer and want to act cautiously on a conditional basis, practical first steps include the following:
- Treat unexpected calls, messages, or emails that reference your Inter service, address, or “leaked connection data” as high-risk phishing until verified through official channels you initiate yourself.
- Change passwords on the email account used for ISP billing and enable multi-factor authentication where available; do the same for any payment or self-care portals tied to the service.
- Monitor bank and card statements for small test charges and unfamiliar telecom-related debits; freeze or replace credentials for stored payment methods if your provider’s portal supports that.
- Prefer official Inter support paths you look up independently rather than links or numbers supplied in unsolicited breach notices.
- Be sceptical of anyone demanding payment, cryptocurrency, or “settlement” fees on the company’s behalf; that pattern matches extortion noise, not legitimate customer care.
- Run a free exposure scan of your email address against known breach datasets to see whether your address has already appeared in unrelated, previously published breaches, which is a separate check from this unconfirmed listing.
A leak-site post is a claim under deadline pressure, not a court finding or a regulator’s inventory. Stay calm, verify through primary sources when they appear, and harden the accounts most likely to be abused if telecom-related personal data ever does surface.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
PayPal support operations (Transcom WorldWide) Listed by N0n Ransomware GroupArgentem Creek Partners (investment firm) Listed by N0n Ransomware GroupVietnamese betting operator (GC789 network / Boundless TE) Listed by N0n Ransomware GroupBeLi Teacher / FSC education centers (AWS) Listed by N0n Ransomware GroupLatest breaches
Publicly posted by n0n — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.