A Cyberattack Was Part of the US Assault on Venezuela

We don’t have many details:

President Donald Trump suggested Saturday that the U.S. used cyberattacks or other technical capabilities to cut power off in Caracas during strikes on the Venezuelan capital that led to the capture of Venezuelan President Nicolás Maduro.

If true, it would mark one of the most public uses of U.S. cyber power against another nation in recent memory. These operations are typically highly classified, and the U.S. is considered one of the most advanced nations in cyberspace operations globally.

Posted on January 6, 2026 at 11:08 AM12 Comments

Comments

someone who knows a thing or two January 6, 2026 5:09 PM

mark, your comment isn’t valid. Natanz computers wasn’t online (Stuxnet).
Being online or offline isn’t valid any more. If you are determined,
anything can be hacked.

Clive Robinson here often tells that his computers are offline and secure.
I’m more than sure that considering his history and background, British
GCHQ has long ago backdoored his computers while he was in hospital.
And how you exfiltrate a data? Blink a keyboard LED and record that via a
window, just one example to you.

r2square January 6, 2026 5:39 PM

It also seems comms where jammed during the kidnap operation. Heard some people mentioning the use of [1] Boeing EA-18G Growler . I’ve never heard about this beasts. One of the jamming pods is the [2] ALQ-99 capable of jamming 64 MHz up to 20 GHz. This makes me wonder if we the best way to “resist” such attacks is diving in deep the shortwave spectrum. I guess it’s more difficult to jam that part of the spectrum due to the wavelength and thus the big antennas requirements.

[1] https://en.wikipedia.org/wiki/Boeing_EA-18G_Growler
[2] https://en.wikipedia.org/wiki/AN/ALQ-99

Clive Robinson January 6, 2026 7:05 PM

@ Bruce,

With regards,

“We don’t have many details:”

No, and we don’t have any clues as such either.

Thus the OrangeUn’s comments could as I said over on the Squid page be “something or nothing” and “It all depends on if what was going on can be “tracked back” etc.”,

https://www.schneier.com/blog/archives/2026/01/friday-squid-blogging-squid-found-in-light-fixture.html/#comment-451121

To save people following that link 😉

News: There Were BGP Anomalies During The Venezuela Blackout

When watching the situation in Venezuela unfold, the phrase “It was dark, the lights of Caracas were largely turned off due to a certain expertise that we have” caught my attention

BGP is the first thing that comes to mind. It’s a protocol used by routers to determine what path data takes to get to it’s destination, it does this by exchanging routing information between Autonomous Systems. It is also notoriously insecure and much of the data about BGP is collected in public datasets.“

https://loworbitsecurity.com/radar/radar16/

However BGP anomalies have been logged in public data bases (unavoidable when playing with BGP not only because of the way it works, but also the way it is used).

Have a read of the Low Orbit article and make your own mind up.

But consider the thought,

“It is odd this security incident has not been highlighted more generally…”

Clive Robinson January 6, 2026 7:23 PM

@ Analyst, ALL,

With regards the substack article you link to,

<

blockquote>THE MEDVEDEV COROLLARY

How 150 Minutes Over Caracas Rewrote the Physics of Global Power and Triggered the Second Nuclear Age
“/

<

blockquote>

Over on the current squid page you will find a chat between @ResearcherZero and myself over the “Doomsday Clock” annual comment,

https://www.schneier.com/blog/archives/2026/01/friday-squid-blogging-squid-found-in-light-fixture.html/#comment-451117

You will find the comments we made to be sufficiently similar in result but different in focus.

Clive Robinson January 6, 2026 9:20 PM

@ someone who knows a thing or two,

With regards,

“I’m more than sure that considering his history and background, British GCHQ has long ago backdoored his computers while he was in hospital.”

You are maybe not considering my “history and background” well enough 😉

There are reasons I use pre-1995 computers, and old OS’s and quite a few other things that people find odd or do not understand.

With regards,

“And how you exfiltrate a data? Blink a keyboard LED and record that via a window, just one example to you.”

You will find I’ve written about this in a couple of posts quite some time back to @figureitout back at the time of BadBIOS. He was actually quite shocked when I told him an LED was a bidirectional transducer and could with the right bias be used as a photo diode (worse as with DC Motors and Back EMF accurately giving speed information… By using a “jittered edge square wave you could get the LED to do both jobs at the same time using just one pin on a microcontroller, it’s one of the reasons I like BPSK as Manchester Encoding).

Also I’ve described here a couple of times how to make not just a permanent overt home “SCIF” but a temporary covert “SCIF” as well.

But as you allude to by your handle I also am “someone who knows a thing or two” but what’s the old saying,

“A true gentleman does not SCIF and tell” 😉

Search this blog for “energy gap” and why I know nearly all Commercial “Data Diodes” Pumps and Sluices don’t “gap” with any kind of real security, physical or informational[1].

I’ve been doing “gap crossing” for years and both Passive and Active “fault injection” since before Smart Cards of the 1980’s along with designing surveillance equipment as well.

Yes there is a lot I don’t know, but in general that’s about actual instance implementations, not the classes of attacks / vulnerabilities they are actually in. Which I know via their fundamental “laws of nature” characteristics. It’s why I say occasionally,

“If the laws of nature allow”.

Or as Sir Arthur Conan Doyle put it in part of his maxim[2]

“How often have I said to you that when you eliminated the impossible, what ever remains, however improbable, must be the truth.”

Use it as a filter to asses both yours and others thinking and reasoning.

[1] Sorry folks but if your ICT-Sec relies on assumptions about those devices even those with GCHQ’s “Communications Electronics Security Group”(CESG) and post 2016 “National Cyber Security Centre”(NCSC) nods and approvals you are probably owned already.

[2] It’s known that the fictional Sherlock Holmes was very much based on a real person of Scottish descent acquainted to Conan Doyle. However a more well known and quite real “The Holmes of Lyon” Dr. Edmond Locard, came up with an evidentiary touch stone “Locard’s exchange principle”,

https://en.wikipedia.org/wiki/Locard's_exchange_principle

Which whilst it was based on physical “tangible objects” also works on a lot of informational “intangible objects” like encrypted and encoded information. Where “Methods and Sources” leave their usage fingerprints. Look on it as a much broader form of “Traffic Analysis”. Which is why in other places I sometimes say,

“Where the laws of nature and statistical mechanics allow”

(Here I tend to use “brownian motion” as an analogue as most who have done the first year of High School Science should be sufficiently acquainted with it).

lurker January 6, 2026 11:33 PM

@Analyst, ALL
re Medvedev ultimatum

The implications for Taiwan, for Iran, for any nation that might find itself in American crosshairs, are profound.

Umm, I know I’m a bit slow, but is the writer assuming an American pre-emptive strike on Taiwan to get the target before PRC? We live in interesting times . . .

Clive Robinson January 7, 2026 5:37 AM

@ lurker, ALL,

The “Medvedev ultimatum” or position is that conventional defense spending is in effect useless against the threat the US 5th Gen systems represent.

Thus logically the only states that can now remain safely sovereign are those with a credible nuclear deterrent and long range delivery system(s) to any and all parts of the continental United States and territories it choses to place it’s forces on…

Hence as I’ve noted in the past about North Korea being the actual “Rational Actor” in it’s defence against the USA is to have a “Keep off the lawn” notice writ large for the US voters to see in the form of proven nuclear weapons and delivery mechanism that the US politicians and those of US allies will have to respect.

This does not require an arsenal of such weapons only those that will credibly destroy things like US Carrier groups and military bases from which the 5th Gen systems can be launched and sustained in flight etc.

This includes nuclear based weapons to destroy not just current carrier groups but the non stealth surveillance, in flight refueling, and “Airborne Warning and Control Systems”(AWACS).

Which is why North Korea having observed how the US pulled out “top table” chairs to both India and Pakistan pushed forward it’s defence systems by first developing capable delivery systems, then the banned nuclear enrichment and weapons.

A look at what happened was that at every credible moment the US could have halted North Korea by talks and trade etc agreements were reached the US congress instantly broke them so the North Koreans just carried on…

This is what Medvedev has in effect given voice to. That is to keep a psychotic belligerent like the US in check is to stop it’s capability to carry out it’s policy of the last 75-80 years of “Bomb them back to the stone ages”.

It appears that the only time the US politicians actually acted rationally towards North Korea was during the Korean war when the in theater commander being repeatedly defeated “on the ground” in conventional warfare requested the use of nuclear devices to attack civilian areas like cities and completely destroy them. The US politicians fearing kick back from their home voters said “NO”.

So the US in it’s next “bomb them back” attempt in Vietnam had developed other “Weapons of Mass Destruction”(WMD) in the form of chemical and some biological weapons where they found that attacking the nations food supply would be in effect acceptable to the US voters as they would be blind to it. However civilian on the ground in theater reporting putting US loved ones in body bags every night on TV News at “tea time” was pushing the voters away. Then the now famous picture of a child having had her cloths napalmed off of her body and now badly burnt running for her life on the front of a national magazine was what “killed the war” even for the most staunch of US Conservatives. It’s where they US politicos learned “think of the children” was a good way to manipulate their own population, but they’ve so over played it the US voter is more and more “seeing through it”.

After the chemical and bio WMD use in Vietnam failed, the US tried things in reverse so we had the times of attacking civilian infrastructure the most notable being the encouragement of aircraft hijacking as a new proxie war system that would keep US loved ones out of body bags but feeling afraid to fly etc.

The rational defence against that was to play the game better and also attack visible US Civilian Technology (which incidently is why 9/11 happened). Which was to do in effect what Japan and later South Korea did which was by trade destroy US manufacturing base. Something that China and Europe then continued to do.

At each step of the way US politicians behaved not just in the short term but much worse in the long term totally irrationally and against their own interests…

The result “to save a buck” US Corporates willingly committed “Seppuku” without thought or honour they “outsourced and off shored. The result the US now has no manufacturing of any worth outside of the defence industry –and that’s mostly a “fill yer boots” boondoggle–, no jobs, and sociopaths running the financial sector and walnut corridors… As Cory Docterow pointed out in his 39C3 talk AI is happening “because your boss hates you” and knows in his heart that you not he is what keeps the company going and shareholders happy. It’s also why the fight against Unions has caused so much harm and death and why The World Economic Forum wants personal ownership of real assets outlawed for ordinary citizens so people are forced into the “rights stripping” of “rent seeking” by them. The “You will own nothing and be happy” is two part, the first is what “Rent Seeking” is about and the second well that is to do with what is a form of “Cult Behaviour” or cultural “brain washing” through very early education is all about…

As I explained the other day building up the US Defence Industry is why the current POTUS is in effect encouraging Putin in his aims to destabilise Europe. And so get Europe doubling or tripling defence spending into the US because 7th Gen weapons systems do not come cheap.

But to maintain “control” the US is also desperately trying to do the equivalent of historical “water wars” against the world by controling world Energy supply through oil, coal and nuclear resources. Hence “The War on Green Solutions”. But “The War on Europe” by destabilising the middle East and causing humanitarian crisis after crisis and wave after wave of refugees into Europe has not worked as intended because of Russia acting in a less Covert way toward Europe.

To see this look at Germany it was over ten years behind on it’s “Green Energy” plans and heading into economic stagnation. Russian energy stopped, and within a couple of years Germany is now ten years ahead of it’s “Green Energy” plans and also organising European Defence manufacturing cutting out much of US defense spending from Europe. Which is exactly the opposite of what the US wanted to happen. Other EU nations are heading that way with France being the nail that sticks up causing issue after issue in the EU, When Hungarian leader and “Putins man Orban” is not doing the same via the “one vote dissent” problem the EU has.

I suspect the UK will receive an offer it “can not” nor “will not” refuse from Europe after the EU gets France under Control and Orban neutered. As the UK and France are the only two currently Nuclear Capable nations they are as Medvedev has indirectly pointed out in effect the only sovereign powers in the whole of Europe capable of deterring the US plans. France will quite happily strike back against the US both covertly and overtly because in many ways they are “oh so similar”. The UK however traditionally hung onto the US coat-tails but the US made the mistake of not reciprocating after Brexit… Which was as bad a move as the years of making mistakes around the South China Seas…

As I’ve pointed out Taiwan was the original “China Knock Off” not “Mainland China” they realised that the way to keep the US “on side” and Mainland China out, was with developing superior technology production the US is utterly reliant on. So the South China See nations rapidly ended up controlling the world supply of advanced semiconductors using European technology to do it. From the US perspective they have to be protected untill the US can get the advanced chip generation it needs to develop. Hence the Chips Act and other “bull in a China Shop” incentives. Politically Taiwan does not in any way want TSMC making advanced chips in the US because of the US War Act. So they are playing for time by building up US infrastructure slowly to keep tariffs down and stop others getting in their game. But will they deliver, I suspect not, it’s not the building or machines that make TSMC what it is.

The trick is stopping what the US MIC needs for 7th Gen Weapons and production, at which point the US will if it has not culled certain conservatives do something stupid like start another phase of “War on the World”.

Oh as I noted the other day the US has started in on it’s new “War on XXX” in this case the reason for 7th Gen weapons “drones”. This time it’s not “think of the children” but faux National Security arguments.

I could provide more argument, but that causes an automod issue with having to provide links for “citations” the above arguments I know from the past you can and will find for yourself as well as counter arguments if you feel they need talking through as will certain others. So the Squid threads might get interesting again 😉

mark January 7, 2026 11:56 AM

To someone who claims to know a thing or two… no, you don’t. In the US, and elsewhere, I’ve seen reports of the electrical grid, water, etc, online, so it’s “convenient” for employees to deal with issues off-hours.

Ah, perfect example: a few years ago, some stupid 16 yr old was tried and convicted in the UK for cracking into the rail system, throwing switches, and causing an accident, with injuries (there may have been a death invovled).

Rontea January 7, 2026 1:06 PM

This fascination with the idea of a single, all-powerful button—press it and your enemies disappear—is a recurring fantasy in the world of cyber and physical security. It’s rooted in a desire for absolute control and simplicity in an inherently complex system. Real-world operations, like disabling power grids or launching cyberattacks, are anything but push-button affairs; they require layers of planning, intelligence, and risk assessment. The danger is that the belief in an easy kill-switch encourages reckless thinking, normalizes disproportionate responses, and erodes the important safeguards that prevent catastrophic mistakes. Security is never that simple, and imagining otherwise is an invitation to disaster.

someone who knows a thing or two January 7, 2026 1:20 PM

mark,

Why don’t you read what others write?
We are not talking about “script kiddies”, we are talking about state sponsored attacks.
There it’s already irrelevant whether your SCADA is online or offline. Determined attacker reach his goal, no “gap”, air or energy or whatever doesn’t help you.

I was personally helping resolving the “Industroyer” incidnent in Ukraine. In real world, not in science fiction as you write.

Leave a comment

Blog moderation policy

Login

Allowed HTML <a href="URL"> • <em> <cite> <i> • <strong> <b> • <sub> <sup> • <ul> <ol> <li> • <blockquote> <pre> Markdown Extra syntax via https://michelf.ca/projects/php-markdown/extra/

Sidebar photo of Bruce Schneier by Joe MacInnis.