How a Lifetime of Fighting Surveillance States Became a Methodology

▶ Watch (01:52)

Kubecka’s grandfather was a DIA agent running Voice of America’s Latin American operations. He brought classified work home. She read it. What stuck was an OSS sabotage manual: instructions for civilians under occupation — use light oil in factory machinery, poke holes in filters, stuff flammable material into fireproof rooms. Disruption, low risk.

In 2006 she did forensic analysis on the Panama Papers law firm. In 2016 a Bulgarian official killed her OSINT workshop’s livestream mid-session. Puerto Rico spent 50 years under US military rule; FBI hop-tracking covered 80% of the island. The manual was analog. The toolkit is digital.

Venezuela’s Spyware Citizen App and How It Disappeared People

▶ Watch (09:23)

Venezuela’s “citizen app” was state spyware. The VenApp (and its older variant Patricia) was marketed as a pothole-reporting tool. VenApp APK spyware capabilities revealed (10:31): APK analysis found it could switch on camera and microphone, block the device from sleeping, harvest contacts, and inject pro-Maduro political rally events into the user’s calendar. After protests followed the July 2024 election, Kubecka received detainee lists with nearly 3,000 names. Families searching for the missing went to the prison administration website — and got arrested too. Prison website Google ID geolocating families (13:02): the site ran Google ID and Analytics JavaScript that geolocated visitors to street level, smartphone data included.

Google’s Infrastructure as a Sanctioned Government Surveillance Tool

▶ Watch (13:17)

The Venezuelan prison administration website was run by a director sanctioned in six countries, including the EU. Families searching for disappeared relatives were the target. Google ID and Analytics on that site geolocated visitors down to street level, and people were then picked up themselves.

“code does not lie. Anyone can look at a website and see the JavaScript that is running on that website.” — Chris Kubecka

Kubecka reported this to Google as a sanctions violation, not a security bug. Google’s PR team denied it. She filed a GDPR complaint in the Netherlands. Nearly a year later, after spinning up a technical review of the submitted code, the Dutch authority confirmed what the JavaScript showed:

“the continued use of Google Analytics and Tag Manager on government Venezuelan servers where they’re not supposed to be is leading to additional loss of life.” — Chris Kubecka

▶ Watch (16:00)

Maduro claimed North Macedonia had DDoS’d the CNE election website, forcing officials to withhold results. Code review and traffic forensics found no such attack. What the logs did show was the cartel thread: the PSVD, a Panama-based party with cartel ties that backs Maduro. Its legal representative denied any connection to VenApp. That denial collapsed when Kubecka hit Panamanian government document servers and pulled the woman’s own CV, confirming Panama government CVs exposing cartel ties (18:15). Russian drones had been in Caracas since mid-August, and Russian phone-checkpoint equipment, identical to what runs in occupied Ukraine, was operating inside Venezuela.

AI-Powered Counter-Operations Against the Dictatorship

▶ Watch (20:15)

Kubecka built two custom GPT tools to fight back. Zero Day GPT generates exploits targeting Venezuelan government infrastructure. Pirate GPT tracks IoT-controlled drug submarines the Venezuelan Navy runs via Starlink, and has already hacked some of them. Both the Android and Apple versions of the VenApp spyware are down – though Maduro announced a new version, and Kubecka is watching the app stores.

When a major outlet published her Google Tag Manager findings in English and Spanish, Google sent letters to the organization. The editor pulled both versions and the journalist resigned. Kubecka reposted it on the one-year anniversary.

Hacking for Democracy — Active Operations and a Call to Action

▶ Watch (24:02)

Kubecka’s team surveilled security-camera feeds and IoT systems to help Venezuela’s opposition leader escape first to the Dutch embassy, then to Spain. Kidnappers targeting candidates’ families made a simpler mistake: they sent ransom emails without stripping Gmail tracking pixels (25:33), which gave away their location and got the victims smuggled across the Colombian border.

“maybe we should start using technology for the good because boy, the bad people keep using it for all the wrong stuff.” — Chris Kubecka

Her closing argument: once you map a dictatorship’s propaganda sites, you can spin up thousands of counter-sites with real corruption data in ten minutes, using the same automation they use.

“every single weapon that they can use against you us in this room we are a cyber army” — Chris Kubecka

Q&A

How did people not notice that the VenApp was spying on them? Venezuela’s massive brain drain left government employees earning $30/month with no forensic specialists or logging infrastructure to catch it. ▶ 31:02

How do you keep yourself safe given the real-world threats you face? She holds registered journalist status in the Netherlands, talks publicly about the threats, and insulates herself — acknowledging those protections are limited. ▶ 32:27

How can volunteers verify they are helping you and not a spoofed or AI-deepfaked version of you? She uses code words and tiered trust levels, and expects to shift toward in-person verification as AI-generated fakes make digital-only authentication unworkable. ▶ 35:46

Starlink is mentioned repeatedly — are these groups using it for internal lateral communication or simply because no other ISP is available? They use Starlink purely because no other ISP is available, and Starlink continues operating in sanctioned regions like Myanmar and Venezuela despite the prohibitions. ▶ 38:11

What is your opinion on election applications — should they be built by governments or private parties, and what model works? She favors the Dutch model: open-source vote-tabulation software anyone can inspect, after 2016 showed a foreign company had been writing the counting code and Russia subsequently hacked it. ▶ 39:49

Notable Quotes

code does not lie. Anyone can look at a website and see the JavaScript that is running on that website. Chris Kubecka · ▶ 13:17

every single weapon that they can use against you us in this room we are a cyber army Chris Kubecka · ▶ 28:48

the continued use of Google Analytics and Tag Manager on government Venezuelan servers where they’re not supposed to be is leading to additional loss of life. Chris Kubecka · ▶ 15:11

maybe we should start using technology for the good because boy, the bad people keep using it for all the wrong stuff. Chris Kubecka · ▶ 26:07

I can’t hack the future yet. One day, Chris Kubecka · ▶ 45:25

Key Takeaways

  • Audit every JavaScript tag on government-adjacent sites — sanctioned regimes weaponize analytics to geolocate dissidents and their families.
  • Mirror the adversary’s information infrastructure at scale: map their disinformation sites, then deploy thousands of counter-sites exposing corruption in minutes.
  • Operational security in high-risk environments requires in-person verification and code words — AI deepfakes make digital-only trust unworkable.

About the Speaker

Chris Kubecka

Chris Kubecka is an esteemed cybersecurity expert with over two decades of experience in digital defense. Her career began with a strong technical foundation, advancing into leadership roles requiring tactical acumen and strategic foresight. Her current roles include: CEO of HypaSec, Netherlands Nation-State incident response; Senior Cyber Security Advisor at Elemental Concept, UK; Chief Hacktress for Unit6 Tech, UK; Senior Advisor for The Hacking Games. Chris has led complex cybersecurity initiatives and advised on critical digital defense strategies. Her expertise spans cyber warfare, digital intelligence, aviation, oil & gas, nuclear, space, and cybersecurity frameworks. A thought leader, Chris is a respected author and speaker, contributing to international conferences, policy discussions, and academic forums. She has developed international policies, cyber peace treaties, and systems protecting critical infrastructure.