← Back to Cyber Tours
2,052 Domains Scanned
31,684 Payment Records Exposed
5,313 Student PII Records
805 Bank Branches (GPS)
131 Government Domains (V1)
42 GAESA Subsidiaries
13,800+ Unique Emails Leaked
307 MB Total Evidence

About This Investigation

Two-phase OSINT assessment of Cuban government infrastructure. V1 (January 2026) documented 131 .gob.cu domains across 20 categories — presidency, ministries, military, state media, infrastructure, judiciary, and state enterprises. V2 (March 2026) expanded to 2,052 domains via certificate transparency and DNS enumeration, uncovering the GAESA military conglomerate's digital footprint, a catastrophic single-point-of-failure software vendor (Guajiritos S.R.L.), and unauthenticated APIs exposing tens of thousands of payment records with customer PII. All data obtained passively through Tor multi-node rotation — no exploitation, no authentication required.

GAESA: The Military Runs the Internet Too

GAESA (Grupo de Administración Empresarial S.A.) is the Cuban military's business conglomerate, controlling an estimated 40% of the national economy and 95% of foreign currency transactions. Of 42 subsidiaries probed, 34 have zero DNS records — total digital opacity. But the 20% that are online share a single software vendor, a single SSL certificate, and a single set of unauthenticated APIs. One company — Guajiritos S.R.L. — builds and operates all tourism IT for 20+ GAESA companies. A compromise of Guajiritos means a compromise of Cuba's entire tourism booking infrastructure, military marinas, medical tourism, and rental car fleet.

GAESA Tourism Network

7 companies, 1 SSL certificate, shared everything

CompanyDomainRole
Havanatur S.A.*.havanatursa.comMain booking platform (12 API subdomains)
Grupo Cubanacan*.grupocubanacan.comTourism group
Marinas Gaviota S.A.*.marinasgaviotasa.comMilitary marina / nautical tourism
Cubanacan S.A.*.cubanacansa.comTourism operator
Okaturs*.okaturs.comTourism operator
CIS La Pradera*.cislapradera.comMedical tourism / International Health Center
Ofertas Travel*.ofertastravel.comTourism operator

Critical Findings

Data exposed without authentication across Cuban government and military infrastructure

FindingSourceImpact
31,684 payment records with customer PIIGAESA tourism APIs13,800+ emails, 27,500+ phone numbers
Full rental car fleet inventoryHavanatur API156 vehicles, pricing, availability
805 bank branches with GPS coordinatesBanco Central APIComplete financial infrastructure map
Triple exchange rate system exposedBanco Central APIOfficial, informal, and crypto rates
5,313 student records with national IDsUCLV GitLabFull PII: names, CI numbers, enrollment data
Laravel APP_KEY + DB credentialsUCLV GitLab commitsRemote code execution capability
Bcrypt password hashesUCLV GitLabCredential theft risk
OpenID Connect password grantUCLV auth systemDirect password authentication endpoint
ETECSA employee PII in SSL certCertificate transparencyInternal organizational data leak
WordPress user enumeration (14 accounts)Health, education, media .gob.cuGravatar hashes, login targets
MINFAR military HQ GPS coordinatesPublic metadataAvenida Independencia, La Habana 10400
12 Google Analytics IDs mappedGovernment websitesCross-site tracking and relationship mapping

Credentials & Secrets

Exposed credentials, password hashes, API keys, and PII across both assessments

🔑
V2 Exposed Credentials Report
Laravel APP_KEY (RCE), root DB passwords, bcrypt hashes, OpenID password grant
View
🔑
V1 All Credentials
Compiled credentials from 131 government domains
View
🔐
WordPress Password Hashes
All harvested WP hashes across .gob.cu domains
View
🔐
Gravatar Hashes
Email hashes from WordPress user enumeration
View
📧
Master Email List
64 government email addresses extracted
View
👤
All Usernames
14 enumerated accounts across government CMS platforms
View
📞
Phone Numbers
Government phone numbers extracted from infrastructure
View
👤
Social Media Handles
Government social media accounts identified
View
🔧
Config Leaks
Exposed server configurations and debug endpoints
Browse
🔥
Cuba Pwned
OSINT social posts and visual evidence
Browse

V1 — Government Infrastructure Collection

131 domains across 20 categories — January 2026

🏛
01 — Presidency
Executive branch, Communist Party (PCC)
Browse
🏛
02 — Ministries
Government ministries infrastructure
Browse
🛡
03 — Military & Security
MINFAR, MININT, Aduana (Customs)
Browse
📺
04 — State Media
Granma, Cubadebate, Radio Rebelde, Juventud Rebelde
Browse
05 — Infrastructure
ETECSA, utilities, telecom
Browse
06 — Judiciary
Courts, prosecutors
Browse
🏛
07 — Other Government
Banks, health, education, state enterprises
Browse
📄
08 — HTML Source
Offline HTML copies of government sites
Browse
🔒
09 — SSL Certificates
16 certificates collected and analyzed
Browse
🔌
10 — APIs
Discovered API endpoints
Browse
🔎
11 — Tracking IDs
12 Google Analytics IDs mapped
Browse
💻
12 — Tech Stacks
CMS, frameworks, server fingerprints
Browse
🚨
13 — Critical Findings
High-severity exposures
Browse
🤖
14 — AI Findings
AI-assisted analysis results
Browse
🗃
15 — Raw Dumps
Raw data extraction
Browse
🗃
16 — Raw Exports
Exported scan data
Browse
🔑
17 — Credentials Exposed
Discovered credentials and secrets
Browse
🔧
18 — Config Leaks
Exposed configuration files
Browse
📊
19 — Tracking Summary
Cross-site tracking relationship map
Browse
📄
20 — Reports
Master OSINT reports
Browse

V2 — GAESA & Deep Infrastructure

2,052 domains — military conglomerate, university GitLab, banking APIs — March 2026

📄
V2 Findings Report
838-line master report — GAESA, Guajiritos, payment records, student PII, credentials
View
🔑
Exposed Credentials
Database credentials, APP_KEYs, and secrets from V2 assessment
Browse
🗃
GAESA Tourism Dumps
Payment records, fleet data from military tourism network
Browse
🗃
Havanatur API Dumps
Booking system, rental fleet, customer data
Browse
🗃
Guajiritos Infrastructure
Single-vendor tourism IT — shared codebase evidence
Browse
🏦
Banco Central Dumps
805 bank branches, GPS coordinates, exchange rates
Browse
🎓
UCLV GitLab
5,313 student records, Laravel credentials, bcrypt hashes
Browse
🛡
MINFAR Data
Military infrastructure data
Browse
🎓
University Scans
Higher education infrastructure assessment
Browse
🚌
WeTransp Data
Transport infrastructure dumps
Browse
Donate