The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →In a May 28, 2020 report, SecurityWeek said cybersecurity firm Check Point had linked the online identity VandaTheGod with “high certainty” to an unnamed individual in Uberlândia, Brazil. Check Point said it had passed its findings to law enforcement in October 2019, but the report did not name the person or establish that authorities brought a case or that a court made a finding.
What SecurityWeek reported
Eduard Kovacs’s May 28, 2020 article in SecurityWeek described Check Point’s attempt to identify the person behind the VandaTheGod alias. The report said the online identity appeared active from 2013 and remained active until May 2020.
According to SecurityWeek’s account of Zone-H records, an account linked to VandaTheGod listed more than 4,800 defaced domains between July 2019 and February 2020, spanning 40 countries. Those numbers describe records cited in the news report; they are not an independently audited count of successful intrusions or affected organizations. A defaced website is one whose displayed content has been altered, and that record alone does not establish the full extent of a compromise.
How the reported identification was made
SecurityWeek described an attribution based on traces across online accounts and websites, rather than a public legal record. The article said researchers examined a website registration associated with Uberlândia and screenshots of social-media profiles. One screenshot showed a Facebook account using the name “Vanda De Assis (VandaTheGod)”; another exposed initials that researchers used alongside the location to find a profile of a man who endorsed the Brazilian Cyber Army.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
Researchers also noted that a whisky photograph and a room-and-furniture setup appeared across profiles. Check Point characterized the resulting identification as high certainty. SecurityWeek’s article does not make the underlying account identities, screenshots, or investigative evidence independently assessable, and it does not provide a court-tested evidentiary record. The reported similarities and location clues should therefore be understood as the basis for Check Point’s attribution, not as a public judicial determination.
Reported activity mixed political messaging with alleged financial activity
The article described anti-corruption messages as the apparent motivation for some website defacements. It separately reported alleged activity involving corporate information and payment-card data, including leaks or offers to sell information. These reported behaviors do not by themselves verify the authenticity, completeness, or source of any data.
One specific claim was that the hacker offered to sell medical records belonging to one million New Zealand patients for $200. SecurityWeek reported an offer, not a confirmed transaction: its article does not verify that the records were authentic, that the seller possessed the full records, or that anyone bought them.
The report also noted claimed associations with the Brazilian Cyber Army and UGNazi. Those mentions are claims in the report, not proof of verified membership.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchRank #3
Timeline and what is—and is not—established
| When | What the report said |
|---|---|
| Since 2013 | The VandaTheGod identity appeared to have been active, according to SecurityWeek. |
| October 2019 | Check Point said it informed law enforcement of its findings. |
| July 2019–February 2020 | The Zone-H account cited by SecurityWeek listed more than 4,800 defaced domains across 40 countries. |
| May 2020 | SecurityWeek said the hacker remained active until this month. |
| May 28, 2020 | SecurityWeek published Eduard Kovacs’s report. |
Check Point’s quoted conclusion was: “Ultimately, we were able to connect the VandaTheGod identity with high certainty to a specific Brazilian individual from the city of Uberlândia, and relay our findings to law enforcement to enable them to take further action.” SecurityWeek did not identify the person or name an individual Check Point spokesperson as the source of the statement.
The report establishes what Check Point said it had concluded and shared with law enforcement. It does not establish a prosecution, conviction, or other legal outcome. It also does not independently verify every defacement, data claim, or alleged affiliation it recounts.
Quick Recap
Best Value
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

