Crystal Vault V2

Exposed Credentials Report — Venezuelan Government Infrastructure

Updated: February 22, 2026 | 38+ organizations | 30 credential sets | 245 evidence files (167 MB) | All confirmed LIVE

30
Credential Sets
38+
Orgs Affected
15
Internal IPs
7
Source Repos
2,500+
PII Records
167 MB
Raw Evidence
Contents

1. Database Credentials — Remote Scanning (.env / Docker)

12 unique credential sets recovered from publicly accessible .env and docker-compose.yml files. No authentication required — direct browser download.

#TypeHostDatabaseUserPasswordSourceStatus
1PostgreSQLbd-srud-des.ovs.gob.ve:5432registro_denunciassrud12345678OVS .env (6 subdomains)1/4 LIVE
2PostgreSQL172.16.100.146:5432siesec2siesec12345678OVS siesec2 .envLIVE
3PostgreSQL172.16.100.130:5432cupazcupazCup4z00OVS .env (commented)LIVE
4MySQLlocalhost:3306emprendedoradministradorAdmiN*1512#emprende.alcaldiadeindependencia .envLIVE
5MySQLlocalhost:3306laravelroot(empty)rrhh.alcaldiadeindependencia .envLIVE
6MySQL127.0.0.1:3306bolivar_paginabolivar_paginaV5YmcyF74LWILj4kpeb.e-bolivar .envLIVE
7Oracle172.20.80.11:1521SIMASIMA1241201A0peb.e-bolivar .envLIVE
8MySQLdatabase:3306moprootpasswordmppop.gob.ve docker-composeLIVE
9MySQLmysql:3306yii2advancedyii2advancedsecretfonbe.gob.ve docker-compose2/3 LIVE
10PostgreSQL172.16.0.10:5432sistemas_ipasmepostgres123456consulta.ipasme .envLIVE
11MySQL127.0.0.1:3306aseosistemaAdmiN*1512#siremi.alcaldiadeindependencia .envLIVE
12MySQL127.0.0.1:3306incretgo_db2incretgo_conexionOti*t3cn0l0g1424*otiincret.gob.ve .env +SMTPLIVE
Notable: IPASME (#10) — Teacher Social Security
Postgres superuser with password 123456 managing pensions, savings, and benefits for ALL education workers in Venezuela. Three database aliases (DB, AFILIADOAHORROS, COMUNES) all point to the same sistemas_ipasme database on internal 172.16.0.10.
Notable: INCRET (#12) — Database + SMTP Same Password SMTP
Password Oti*t3cn0l0g1424*oti reused for BOTH MySQL database AND the SMTP mail account [email protected] on mail.incret.gob.ve:465. Enables sending emails as a government agency.

2. Database Credentials — Source Code (.git Dumps)

18 additional credential sets extracted from 7 reconstructed source code repositories. PHP source code is invisible via normal HTTP (server executes it), but exposed .git/ directories allow full source recovery.

#TypeHostDatabaseUserPasswordSource
13PostgreSQL172.31.8.44:5432mpptop_2017nominan0m1n4SIGESP covensol_config.php
14PostgreSQL172.31.8.44:5432mpptop_2016_nominanominan0m1n4SIGESP covensol_config.php
15PostgreSQL172.31.8.93:5432sigesp_vycsigesps1g3spSIGESP covensol_config.php
16PostgreSQL172.31.8.44:5432induccion_2016_nominanominan0m1n4SIGESP covensol_config.php
17PostgreSQLlocalhost:5432db_vycsucre_*postgresvycsucreadminSIGESP covensol_config.php
18PostgreSQLec2-52-7-159-155:5432d1haaqhp97miaeztyeqxnzxedboc979d9069...65fa1eMINMUJER database.php (AWS RDS)
19PostgreSQLlocalhostfasacpostgres123456MINMUJER database.php (legacy)
20MySQLlocalhostfasarcroot(empty)MINMUJER database.php (legacy)
21MySQL127.0.0.1:3306siremisistemaAdmiN*1512#SIREMI database.php
22MySQLlocalhostsbtebpav_minagua_dbsbtebpav_minaguas_userMinaguasroot#HIDROVEN Conexion.php
23MySQLlocalhostsima_dbrootxsM6U1teIzPGP6gHIDROVEN Conexion.php
24MySQLlocalhostminagua_dbroot(empty)HIDROVEN Conexion.php (dev)
25PostgreSQLlocalhost:5432db_chamba_produccionpostgresOUUO5bHo...raI0= (enc)Chamba Juvenil database.php
26PostgreSQLlocalhost:5432db_pcj_17052019postgresOUUO5bHo...raI0= (enc)Chamba Juvenil database.php
27SFTP190.202.144.60:1022chamba1s0p0rt3++Chamba Juvenil sftp.json
28SMTPmail.incret.gob.ve:465[email protected]Oti*t3cn0l0g1424*otiINCRET .env (same as DB #12)
29TelegramBot 8534453577AAHrCe_QOQRLK_nToS0pb4f5Y4ba5zBSJBQChamba Juvenil config.php
30TelegramBot 7265564977AAHJcYuxTQX7coz-qatLEd9j5Ai1RLDv_fYChamba Juvenil BotController.php

3. Keys, Tokens & Secrets

TypeValueSourceImpact
RSA KEYFull 2048-bit PKCS#8 private keyChamba Juvenil registrochamba.keyDecrypt traffic, impersonate services
SMTP[email protected] / Oti*t3cn0l0g1424*otiincret.gob.ve .envSend emails as government agency
SFTP190.202.144.60:1022 / chamba / 1s0p0rt3++Chamba Juvenil sftp.jsonDirect file system access to production server
TELEGRAM8534453577:AAHrCe_QOQRLK_nToS0pb4f5Y4ba5zBSJBQChamba Juvenil config.phpControl government notification bot
TELEGRAM7265564977:AAHJcYuxTQX7coz-qatLEd9j5Ai1RLDv_fYChamba Juvenil JS + BotControllerControl secondary bot (chat IDs: 830259515, 6021886971)
API KEY38db809be13a400c8c5061e304ba99cdHIDROVEN mapas_estatus.phpThunderforest Maps API access
HTPASSWDcarnetizacion:$apr1$t5G51mJ9$s.F3jKcudPJnlFq5zxrYD.carnet.guarico.gob.ve/.htpasswdAPR1 hash — crackable (hashcat mode 1600)
LDAP172.31.8.51 / dc=mtt,dc=gob,dc=veSIGESP covensol_config.phpActive Directory for entire MTT domain

4. Database Dumps & Backups

HIDROVEN — 14 SQL Dumps (150 MB total)

ALL directly downloadable via HTTP from sima.hidroven.gob.ve/sql/. National water utility production data spanning 15 months.

FileSizeDateContents
respaldo_2025-06-05.sql104 MBJun 5, 2025NEWEST full production backup
respaldo_2025-06-02_16-12-22.zip14 MBJun 2, 2025Compressed backup
respaldo_2024-11-11.sql4.3 MBNov 2024Monthly backup
respaldo_2024-04-09.sql4.3 MBApr 2024Monthly backup
respaldo_2024-04-04_19.sql3.9 MBApr 2024Monthly backup
respaldo_2024-04-04_03.sql3.4 MBApr 2024Monthly backup
respaldo_2024-03-28.sql3.4 MBMar 2024Monthly backup
Mimagua_FullDATA.sql4.2 MBFull reservoir inventory + coordinates + personnel
DATABASE_minaguas_FULL.sql4.2 MBFull dataset (duplicate)
Minagua_10_embalses_data.sql3.4 MB10 reservoir operational data
minaguas_data_2023_y_2024.sql871 KB2023-2024 reservoir data
minaguas_data_2023.sql696 KB2023 reservoir data
minagua_db.sql52 KBSchema + user table (bcrypt hashes, cedulas)
minagua_empty_db.sql8 KBEmpty schema

SIGESP — PostgreSQL Backups + Salary Declarations

FileSizeContents
dumpdetabladecuentas.backup9.3 KBPostgreSQL account table dump
tabladesaldos.backup410 BAccount balances
Declaracion_Salarios_XML_08-2016.xml2.7 KBAug 2016 salary declaration (RIF numbers)
Declaracion_Salarios_TXT_08-2016.txt577 BSalary declaration text format
Evidence: LIVE-DUMPS/hidroven-db/ (14 files, 150 MB) • LIVE-DUMPS/sigesp-dumps/ (5 files, 26 KB)

5. PII & Personal Data (2,500+ records)

SIGESP — Employee Payroll & Bank Accounts (9 files, 2.5 MB)

ALL directly downloadable via HTTP from sigesp.industrias.gob.ve

FileSizePII Content
txtpersonalnomina.csv1.1 MBCedulas, BANK ACCOUNT NUMBERS, salaries
personal_comunas2.csv611 KBCedulas, names, salaries, BANK ACCOUNT NUMBERS
Personal_Comunas.csv254 KBCedulas, names, dates of birth
nomina.csv274 KBPayroll codes and payment amounts
personal_inppj.txt34 KB298 INPPJ judicial employee records
personal_nomina_inppj.csv30 KBINPPJ payroll + bank account numbers
personal_conviasa.csv3.7 KBCONVIASA airline employees + HOME ADDRESSES
personalnomina_conviasa.csv2.6 KBCONVIASA payroll + bank accounts
errors.log197 KBApp error logs with SQL queries

Other PII Sources

SourceRecordsData Types
Chamba Juvenil lista_separada.txt44Plaintext cedula numbers
Chamba Juvenil schemaFull DBCedulas, names, emails, phones, DOB, GPS, housing, disabilities, social media
HIDROVEN user accounts3Emails, cedulas, bcrypt hashes (cost 5 — trivially crackable)
HIDROVEN personnel~20+Reservoir operator names, cedulas, phones, emails
Carnet Guarico APIUnlimitedAny citizen by cedula — name, position, department, photo (no auth)
SIREMI schemaFull DBCedulas, family groups, children's data, payments
MINMUJER photos52Event/attendance photos (still being served)
MINMUJER document scans123Government document scans (still being served)
Gravatar hash reversal1,137Email addresses de-anonymized from 3,961 hashes across 162 domains
WordPress enumeration142+Admin usernames across government sites
Government emails225+Official + personal Gmail addresses on gov business
Document metadata442+Personnel names from PDF/Office files
Evidence: LIVE-DUMPS/sigesp-pii/ (9 files, 2.5 MB) • LIVE-DUMPS/minmujer/ (175 files, 14 MB) • LIVE-DUMPS/chamba-secrets/ (3 files)

6. Election Infrastructure

CRITICAL PSUV Election Management API — Full GraphQL Introspection
api-psuv-elecciones.guarico.gob.ve — Ruling party election system with full schema exposed
Types: CentroVotacion, Mesa, Employee, ReporteVotacion Mutations: createAdmin, loginEmployee, setVotacion, aperturaCentroVotacion, cierreCentroVotacion Impact: Full voting center management — create admins, record votes, open/close centers Co-hosted: Shares IP 190.205.119.210 with portainer.guarico.gob.ve (Docker/K8s panel)
HIGH Vote Registration Module — Hidden in Youth Employment App
Chamba Juvenil source code contains registro_voto.php, listar_registros_votos.php, Registro_voto.php controller
Title: "ESTRUCTURA DE REGISTRO DEL VOTO" Context: Full vote tracking system embedded within a youth employment registration platform

5 additional GraphQL endpoints with introspection: gitlab.inti.gob.ve, api-asistencia.guarico.gob.ve, api-festividades.guarico.gob.ve, demo-api-sgd.guarico.gob.ve, api-distribucion-gas.guarico.gob.ve

Evidence: LIVE-DUMPS/election-api/ (4 files, 68 KB) — graphql_full_introspection.json, portainer + voter registry HTML

7. Internal Network Map — 15 IPs

IP AddressSystemSource
172.16.0.10IPASME PostgreSQL — teacher social security.env
172.16.100.146OVS PostgreSQL (siesec/siesec2).env
172.16.100.130OVS secondary PostgreSQL (cupaz).env (commented)
172.20.80.11Bolivar State Oracle — SIMA water management.env
172.31.8.44SIGESP PostgreSQL — payroll databases (MPPTOP)covensol_config.php
172.31.8.93SIGESP PostgreSQL — APOYO system (sigesp_vyc)covensol_config.php
172.31.8.51SIGESP LDAP — Active Directory (dc=mtt,dc=gob,dc=ve)covensol_config.php
172.16.0.205INHRR internal Git server (root SSH).git/config
172.17.2.248FONACIT internal GitLab (root/sidcai).git/config
150.188.84.156Infocentro internal GitLab (dmora/codeigniter).git/config
172.31.89.189VYC Sucre Gitea backend (taken down)OpenID config
172.16.2.8FUNDABIT internal API server.git source
190.202.144.60Chamba Juvenil SFTP production server (port 1022)sftp.json
ec2-52-7-159-155MINMUJER AWS RDS (US-East-1)database.php
bermudez.cgesucre.gob.veCGE Sucre internal Git (SIACE system).git/config

8. Git Repository Exposures — 28 Domains

18 of 22 .git/config files still serving as of February 22, 2026. 7 repos fully reconstructed (64,262 files).

DomainRemote URLNotesStatus
asistencia.minmujer.gob.ve (+ 5 subs)git.heroku.com/cementerio.gitCemetery system on 6 MINMUJER subdomainsLIVE
sigesp.industrias.gob.vegitlab.mtt.gob.ve/cmorales/SIGESP-MPPT.git37K file payroll systemLIVE
sima.hidroven.gob.vegithub.com/jcarri07/minaguas-project.gitWater managementLIVE
registro.chambajuvenil.gob.vegithub.com/jhonatanrojas/registrochamba.gitYouth employment + vote moduleLIVE
siremi.alcaldiadeindependencia.gob.vegithub.com/bollanog/siremi.gitWaste management + citizen recordsLIVE
carnet.guarico.gob.vegithub.com/InformaticaDGI/carnet-web.gitState ID card systemLIVE
calidad.baer.gob.vegitlab.com:biodarks/sigae-auth-front.gitMilitary auth systemLIVE
siverc.inhrr.gob.ve[email protected]:root/sivercbackup.gitEpidemiological surveillance, root SSHLIVE
revecaapi.oncti.gob.vecontrolador.mincyt.gob.ve/oncti/reveca_api.gitScience observatoryLIVE
recibos.tves.gob.ve[email protected]/desarrolladoresdetves/recibos_actual.gitState TV receiptsLIVE
sistema.fondoefa.gob.vegitlab.com/tecnodevelop/saica.gitArmed Forces Education FundLIVE
chacao.gob.vegit.artesanossiglo21.com/revista/chacao.gitcredential.helper=store (plaintext passwords)LIVE
cervante.sarep.gob.vegithub.com/jkhiyami/sarep.gitRegistry/notaryLIVE
enunclic.infocentro.gob.vecontrolador.mincyt.gob.ve/servicios-infraestructura/sitio-mantenimiento.gitInfocentro maintenanceLIVE
sgg.mincyt.gob.ve(same repo as enunclic)MINCYTLIVE
infoapp2.infocentro.gob.vegithub.com/JarceloElement/infoappInfocentro app (branch: dev)LIVE
sig.mincyt.gob.vecontrolador.mincyt.gob.ve/desarrollo/sigmincyt.gitGIS/mapping (HTTP, no TLS)LIVE
registro.fundabit.gob.vegithub.com/relly27/formulario-improv.gitEducation ITLIVE
iaim.baer.gob.vegitlab.com (BAER)Military agroindustrialDOWN
sidcai.fonacit.gob.vehttp://172.17.2.248/root/sidcai.gitFONACIT, internal IP, root userDOWN
infovirtual.infocentro.gob.ve[email protected]:dmora/codeigniter.gitInfocentro, internal IPDOWN
siace.cgesucre.gob.vehttp://bermudez.cgesucre.gob.ve/siacesucre/siaces.gitCGE Sucre comptrollerDOWN
Evidence: LIVE-DUMPS/git-configs/ (18 files, 29 KB)

9. Laravel APP_KEYs — 6 Unique (RCE / Session Forging)

KeyScopeStatus
base64:G6lOwhNpWp3spLvoxDq5COBMJmtrYsTNlHjhR1+6nnI=OVS (6 subdomains)2/6 LIVE
base64:Zs/kTGD0dUQSid7ngUluBzTnRH+5887+jgU4Ib4KMao=emprende + siremi .alcaldiadeindependencia (shared!)LIVE
base64:3tylXo58E+JBds06/yevWhAjY9q3gN27TBhwH60iHMI=rrhh.alcaldiadeindependenciaLIVE
base64:ipBRf+v/hXurl1H85fY4jvmGRPc4KEKDqsa456OqJjs=peb.e-bolivarLIVE
w2dfI2xnNIM2cIxL02rlCscgplIiACVeconsulta.ipasme (non-base64)LIVE
base64:DVRtdtLbzXdcAQKEzoUXPqmNlFkvHR24i2WSvQSwAws=incret.gob.veLIVE

10. LIVE-DUMPS Evidence Archive — 245 Files, 167 MB

Raw evidence files downloaded directly from live servers on February 22, 2026 as proof of exposure.

DirectorySizeFilesContent
hidroven-db/150 MB14SQL database dumps (Mar 2024 → Jun 2025)
sigesp-pii/2.5 MB9CSV payroll, bank accounts, cedulas, CONVIASA
sigesp-dumps/26 KB5PostgreSQL backups, salary declarations (XML/TXT)
election-api/68 KB4GraphQL introspection JSON, Portainer/voter HTML
military/22 KB6.bashrc/.profile/.bash_logout from 2 MINDEFENSA units
env-files/40 KB9Raw .env + docker-compose from live domains
git-configs/29 KB18.git/config files (18 of 22 still serving)
chamba-secrets/13 KB3sftp.json, RSA private key, cedula list
carnet-guarico/1 KB1.htpasswd (APR1 hash)
incret/4 KB1.env with DB + SMTP credentials
minmujer/14 MB17552 photos (7.8 MB) + 123 document scans (6.1 MB)
TOTAL167 MB245Raw proof from live government servers

11. Complete Credential Summary — 30 Unique Sets

See tables in Section 1 (remote, #1-12) and Section 2 (source code, #13-30) above for the full breakdown.

12. Password Reuse Patterns

PasswordUsed ByCount
12345678OVS srud-des, OVS siesec22
123456IPASME postgres superuser, MINMUJER legacy2
AdmiN*1512#Alcaldia Emprende, SIREMI .env, SIREMI source code — 3 systems, same password3
(empty)Alcaldia RRHH, MINMUJER legacy, HIDROVEN dev3
passwordMPPOP WordPress1
n0m1n4SIGESP payroll (x3 databases on 172.31.8.44)3
secret / verysecretFONBE sistema1, FONBE sitreceal2
Oti*t3cn0l0g1424*otiINCRET MySQL DB + INCRET SMTP mail — same password for both2

13. Affected Organizations — 38+

CategoryOrganizations
National MinistriesMPPOP (Public Works), MINAAMP (Agriculture), MINMUJER (Women), MINCYT (Science/Tech), INDUSTRIAS (Industries), MINDEFENSA (Defense — 2 units: OIDIFANB, VICEDUFANB)
National AgenciesOVS, ONCTI, INHRR, HIDROVEN, FUNDABIT, CHAMBA JUVENIL, SAREP, IPASME, INFOCENTRO, FONACIT, IVIC, TVES, FONDOEFA, TIFM, INCRET, CONVIASA (airline — employee PII exposed), INPPJ (judicial — 298 employee records)
MilitaryBAER (Army Agroindustrial Brigade), MINDEFENSA (2 exposed .bashrc — web root = home dir)
FinancialFONBE (Welfare Fund), FONDEMI (Microfinance)
PoliticalPSUV (ruling party — election API with full GraphQL introspection)
State GovtsBolivar, Guarico, Sucre, Aragua
Municipal GovtsIndependencia (Caracas metro), Heres (Bolivar capital), Chacao (wealthiest Caracas district), Los Salias, Atures

Glossary & Organization Reference

Technical Terms

TermDefinition
.env fileEnvironment configuration file used by Laravel/PHP frameworks. Contains database passwords, API keys, and application secrets in plaintext. Should never be web-accessible.
.git directoryVersion control metadata folder. When exposed on a web server, allows complete reconstruction of source code including all file history.
APP_KEYLaravel framework encryption key. If leaked, enables Remote Code Execution (RCE) via crafted session cookies and session forging to impersonate any user.
.htpasswdApache HTTP server password file. Contains username and hashed password for HTTP Basic Authentication. APR1 hashes are crackable with hashcat.
GraphQL IntrospectionA feature that exposes the full API schema (types, queries, mutations). When enabled on production systems, reveals all available operations including admin functions.
SFTPSSH File Transfer Protocol. Credentials for SFTP provide direct filesystem access to the remote server.
SMTPSimple Mail Transfer Protocol. SMTP credentials enable sending emails from the associated email address — in this case, a government notification account.
LDAPLightweight Directory Access Protocol. Used for centralized authentication (Active Directory). An exposed LDAP server handles login for an entire organization's domain.
Bcrypt cost factorThe computational cost of bcrypt password hashing. Cost 5 is trivially fast to brute-force; OWASP recommends minimum cost 10.
SQL InjectionA vulnerability where user input is inserted directly into SQL queries without sanitization, allowing attackers to read, modify, or delete database contents.
CORS wildcardSetting Access-Control-Allow-Origin: * allows any website to make authenticated requests to the server, enabling cross-site data theft.
Gravatar hashWordPress stores email addresses as MD5/SHA256 hashes via Gravatar. These can be reversed to recover the original email address through pattern-based brute-force.

Venezuelan Government Organizations

AbbreviationSpanish NameEnglish NameFunction
MPPOPMinisterio del Poder Popular para las Obras PúblicasMinistry of Public WorksNational infrastructure — roads, bridges, public buildings
MINAAMPMinisterio del Poder Popular para la Agricultura UrbanaMinistry of Urban AgricultureUrban farming and food sovereignty programs
MINMUJERMinisterio del Poder Popular para la MujerMinistry for WomenWomen's social programs, gender policy
MINCYTMinisterio del Poder Popular para Ciencia y TecnologíaMinistry of Science & TechnologyResearch funding, technology policy
INDUSTRIASMinisterio del Poder Popular para IndustriasMinistry of IndustriesManufacturing, state factories, SIGESP financial system
MINDEFENSAMinisterio del Poder Popular para la DefensaMinistry of DefenseMilitary — 2 units exposed (OIDIFANB, VICEDUFANB)
OVSOficina de Vigilancia SanitariaSanitary Surveillance OfficeFood safety, pharma, medical device regulation
HIDROVENHidrología de Venezuela, C.A.National Water UtilityWater treatment, dams, aqueducts — critical infrastructure
IPASMEInstituto de Previsión y Asistencia Social del Min. EducaciónTeacher Social Security InstitutePensions, savings, benefits for all education workers
INCRETInstituto Nacional de Capacitación y Recreación de los TrabajadoresNational Worker Recreation InstituteRecreational facilities and worker training
CHAMBA JUVENILPlan Chamba JuvenilYouth Employment PlanGovernment youth jobs program (ages 15-35)
CONVIASAConsorcio Venezolano de Industrias Aeronáuticas y Servicios AéreosVenezuelan National AirlineState airline — employee PII + home addresses exposed
INPPJInstituto Nacional de Previsión del Personal JudicialJudicial Personnel InstituteJudicial system employee benefits — 298 records + bank accounts exposed
BAERBrigada Agroindustrial del Ejército RevolucionarioArmy Agroindustrial BrigadeMilitary farming and food production
SAREPServicio Autónomo de Registros y NotaríasRegistry & Notary ServiceBirth/death certificates, property titles, legal documents
FONBEFondo Nacional de Bienestar y EducaciónNational Welfare & Education FundSocial welfare and education funding
FONDEMIFondo de Desarrollo MicrofinancieroMicrofinance Development FundSmall loans and microfinancing
PSUVPartido Socialista Unido de VenezuelaUnited Socialist Party of VenezuelaRuling party — election management API exposed
SIGESPSistema Integrado de Gestión y Control de las Finanzas PúblicasIntegrated Public Finance Management SystemGovernment-wide financial/payroll system
SIMASistema Integral de Manejo de AguasIntegrated Water Management SystemHIDROVEN's operational water/reservoir management platform

Venezuelan Terms

TermMeaning
CédulaVenezuelan national identity number (like SSN). Format: V-12345678. Used for all government services, banking, voting.
RIFRegistro de Información Fiscal — Tax identification number for individuals and businesses.
AlcaldíaMunicipal government / mayor's office.
GobernaciónState government / governor's office.
ParroquiaParish — smallest administrative division within a municipality.
NóminaPayroll.
EmbalseReservoir / dam.