CSIDB logo
Threat actor

Guacamaya

Attribution profile

Type
Activist
Location
Ecuador
Known incidents
13 incidents
First seen
2022-08-01
Last seen
2022-09-20
Updated
2026-07-30 20:19
Aliases
4 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Guacamaya is an environmental hacktivist collective that takes its name from a species of bird and operates through the Enlace Hacktivista website where it publishes leaked materials. The group has collaborated with transparency platforms such as DDoSecrets and journalism organizations like Forbidden Stories to disseminate the data it obtains. It describes itself as a collective of hackers who seek to participate in resistance movements where there is dignified rage and a joyful desire for radical revolution.

The collective primarily targets mining companies, oil corporations and government agencies responsible for environmental oversight in Central and South America, specifically naming entities in Colombia, Guatemala, Ecuador, Chile, Brazil and Venezuela. According to its own statements, Guacamaya aims to expose environmental devastation caused by foreign and domestic firms, to halt exploitation, mining and pollution, and to oppose what it describes as a desire for dominance by those entities. Its motivations are framed as hacktivist resistance rather than financial gain or espionage.

Guacamaya’s tactics involve obtaining internal emails and files from target networks and then publishing the data publicly, accompanied by statements that explain their grievances. The group has released videos detailing how it accessed systems and extracted emails, and it has given interviews to outlets such as Forbidden Stories to explain its motivations. Prior to the August 2022 release of two terabytes of mining company emails, Guacamaya leaked 4.2 terabytes from mining subsidiaries of a Swiss investment group, a leak that fed a global reporting project involving sixty‑five journalists that revealed pollution, government manipulation and surveillance of journalists.

Attribution to Guacamaya is based on the group’s self‑identification and its public communications; no state sponsorship or criminal consortium affiliation is mentioned in the source material. The collective’s notable operations include the August 2022 leak of over two terabytes of data from five mining companies and two environmental agencies across Central and South America, and the earlier 4.2‑terabyte disclosure linked to the Swiss‑linked mining subsidiaries that contributed to an international investigative series. These actions illustrate the group’s focus on documenting and publicizing alleged environmental harm through the acquisition and release of internal corporate and governmental communications.

Incidents

Attributed incidents are available to members.

13 incidents
CSIDB