EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/hacktivism/2022-guacamaya-leaks
152/430

File EL-0279CriticalOngoingHacktivism / Government Surveillance Leak

Guacamaya Leaks

Also filed as Guacamaya Hacktivist Operation · Latin American Military Leaks

Codename Operación Guacamaya

The Guacamaya hacktivist collective systematically breached dozens of government and military agencies across Latin America, leaking millions of internal emails and documents exposing corruption, surveillance programs, and environmental exploitation.

  • #hacktivism
  • #latin-america
  • #military
  • #government-leaks
  • #environment
Notoriety8/10
Event
1 Sept 2022
Disclosed
22 Sept 2022
Target
Multiple Latin American Governments
Actor
Guacamaya
Scale
Terabytes
Status
Ongoing

01Summary

Beginning in September 2022, the Guacamaya collective launched an unprecedented wave of breaches targeting military, police, and government institutions across Latin America. Initial breaches targeted the Mexican Ministry of Defense (SEDENA), leaking 10 terabytes of data including emails revealing surveillance of journalists and activists. Subsequent operations targeted the Chilean Army, Colombian Ministry of Defense, Peruvian military, and multiple Central American governments. Notable leaks include the Chilean 'Hurricane' case documenting military spying on Indigenous Mapuche communities, and the 'Mina Perdida' leak exposing mining company collusion with government officials.

02Background

Guacamaya emerged as a prominent hacktivist voice in Latin America, specifically focused on exposing military corruption, environmental crimes by mining corporations, and government surveillance of civilian populations across the region.

03Key revelations

  1. 01Mexican military surveillance of journalists and activists
  2. 02Chilean military intelligence operations against Mapuche communities
  3. 03Mining industry collusion with government officials across Latin America
  4. 04Systemic corruption in multiple Latin American defense ministries

04Technical analysis

The collective gained initial access through compromised credentials and exploiting unpatched vulnerabilities in government email servers. Data was exfiltrated over extended periods before public disclosure.

Attack vector
Compromised credentials / Exploited vulnerabilities
Attack method
Data exfiltration and public disclosure
Initial access
Credential compromise / Vulnerability exploitation
Lateral movement
Network pivoting
Exfiltration
Bulk data extraction

05Threat actor

Guacamaya is a decentralized hacktivist collective operating across Latin America, focused on exposing government secrecy, military corruption, and environmental crimes through targeted data breaches and coordinated public disclosures.

Aliases

  • Guacamaya Hacktivist Collective

Attribution sources

  • Guacamaya leak site

06Victims and impact

Additional victims

  • Mining corporations
  • Police forces

Countries affected

  • Mexico
  • Chile
  • Colombia
  • Peru
  • El Salvador
  • Guatemala
  • Honduras
  • Nicaragua
  • Paraguay

07Data exposed

Data types

  • Government Emails
  • Intelligence Reports
  • Military Communications
  • Corporate Communications

Notable documents

  • SEDENA email archive
  • Chilean Army Hurricane files
  • Peruvian military intelligence documents

08Timeline

  1. 2022-09-01First public disclosure of Guacamaya leaks targeting SEDENA (Mexico).
  2. 2023-04-01Chilean Army breach disclosed; Hurricane files published.
  3. 2023-11-01Colombian Ministry of Defense breach disclosed.
  4. 2024-02-01Peruvian military intelligence documents leaked.

09Reaction and fallout

Public reaction

Significant political fallout across Latin America; millions of citizens gained unprecedented access to internal government operations.

Political impact

Triggered political crises in multiple countries; investigations launched into military surveillance and corruption.

Geopolitical consequences

Strained diplomatic relations between affected countries over cross-border espionage revelations.

10Legal

Ongoing investigations in multiple jurisdictions.

11Aftermath

Policy changes

  • Some countries initiated transparency reforms and independent investigations.

12Significance and legacy

Significance

The largest coordinated hacktivist operation ever conducted in Latin America, targeting 9 countries and exposing government opacity across an entire region.

Legacy

Demonstrated the power of regional hacktivist collaboration in exposing systemic corruption and surveillance across multiple jurisdictions simultaneously.

13Disclosure and media

Authentication
Guacamaya leak site and media partner verification

Publishing organisations

  • Guacamaya leak site
  • Distintos Latitudes
  • Forbidden Stories

14Field notes

  1. 01Guacamaya's operations spanned at least 9 Latin American countries over 2+ years.
  2. 02The group's name means 'macaw' in Spanish, referencing the bird's regional significance.

15Resolution

Ongoing; Guacamaya continues to leak documents periodically.

16Sources

References

  1. [1]Distintos Latitudes reporting
  2. [2]Forbidden Stories - Guacamaya project
  3. [3]Media coverage across Latin America
Fact sheetEL-0279

Dates

Event
1 Sept 2022
Started
1 Sept 2022
Discovered
1 Sept 2022
Disclosed
22 Sept 2022
Ongoing
Yes

Target

Organisation
Military and Government Agencies of Mexico, Chile, Colombia, Peru, and others
Type
Government Agency
Sector
Defense / Government
Country
Multiple
Gov. level
Federal

Actor

Name
Guacamaya
Type
Hacktivist Group
Motivation
Exposing government secrecy, military corruption, and environmental destruction across Latin America.
Attribution
Medium
Status
Active
Arrested
No
Convicted
No

Data

Volume
Terabytes
Sensitivity
Top Secret
Published
Yes
Sold (dark web)
No

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.