🔴 [LATEST] IRAN DEPLOYS 2 CYBER FRONTS: HANDALA TARGETS ISRAEL, CYBERAV3NGERS TARGETS US    ◆    🔴 [LATEST] PARAGUAY'S MITIC SERVER DOWN FOR 24 HOURS, THEGARUDAEYE IN SPOTLIGHT    ◆    🔴 [LATEST] THEHATMAN SELLS 3.6 MILLION AZURE EMPLOYEE RECORDS FROM FORTUNE 500 COMPANIES    ◆    🔴 [LATEST] 24 HOURS OF DIGITAL BLACKOUT: THEGARUDAEYE SILENCES PARAGUAY'S CULTURE MINISTRY PORTAL IN THE NAME OF PALESTINE    ◆    🔴 [LATEST] WHERE HAS DRAGONFORCE MALAYSIA GONE? THE SILENCE OF SOUTHEAST ASIA'S PREMIER HACKTIVISTS

~/ddosarticle

ddos

Paraguay’s MITIC Server Down for 24 Hours, TheGarudaEye in Spotlight

> By Clara | Aug 19, 2026 | 7 min read

The online services of Paraguay’s Ministerio de Tecnologías de la Información y Comunicación (MITIC), the ministry overseeing the country’s information and communication technology policy, reportedly experienced an access disruption lasting roughly 24 full hours. The ministry’s official domain, mitic.gov.py, was recorded as inaccessible throughout that period, a duration considerably longer than most government service disruptions, which typically resolve within minutes to a few hours.

Paraguay’s MITIC Server Down for 24 Hours, TheGarudaEye in Spotlight - CyberAsia Threat Intel Evidence

The hacktivist group TheGarudaEye has now come under the spotlight after openly publishing details of the incident through its own communication channels. The publication included screenshots, verification links from third-party services, and a political narrative used as the backdrop for the action. This kind of publication pattern is now common among hacktivist groups, which do not merely carry out technical disruptions but also build communication campaigns to reinforce their ideological messaging while boosting their own visibility.

> TABLE_OF_CONTENTS [toggle]

Timeline of the Disruption

According to material published by TheGarudaEye, the disruption to MITIC’s service reportedly began on August 13, 2026, at 09:19 a.m. Paraguay time. The group listed a duration of 86,400 seconds, equivalent to 24 hours, as the claimed length of the outage. This specific duration figure, stated upfront, is one of the elements that makes the incident stand out compared to the shorter, minutes-long disruptions more commonly seen in similar actions.

Paraguay’s MITIC Server Down for 24 Hours, TheGarudaEye in Spotlight - CyberAsia Threat Intel Evidence

As part of its publication, TheGarudaEye included two external verification links from third-party site-availability monitoring services, check-host.net and check-host.cc. Both services are commonly used within the cybersecurity community to check a domain’s online status from multiple server locations worldwide. The group also shared a screenshot showing a “Server Error” page when the mitic.gov.py domain was accessed via a browser, along with a note indicating that the infrastructure’s web application protection system runs on OPNsense.

Paraguay’s MITIC Server Down for 24 Hours, TheGarudaEye in Spotlight - CyberAsia Threat Intel Evidence

The Technical Side of the Disruption

The combination of elements published — a duration specified from the outset, the use of third-party verification tools to demonstrate a domain’s offline status, and a “Live Attack” label inviting the audience to monitor in real time — is consistent with the pattern of a distributed denial-of-service (DDoS) attack. In this type of attack, perpetrators flood a target server with an overwhelming volume of traffic until the system runs out of capacity to respond to legitimate user requests, making the service appear inaccessible from the user’s side.

As of this report, neither MITIC nor Paraguay’s national cybersecurity authority has issued an official statement confirming the exact technical cause of the disruption. The absence of an official confirmation means details such as the volume of attack traffic, the technical vector used, and the state of MITIC’s defensive infrastructure at the time of the incident remain unable to be independently verified.

Paraguay’s MITIC Server Down for 24 Hours, TheGarudaEye in Spotlight - CyberAsia Threat Intel Evidence

Who Is Affected

MITIC is Paraguay’s primary authority for shaping national digital policy, governing telecommunications infrastructure, and coordinating the government’s digital transformation efforts. A disruption to the ministry’s online services of this kind risks hampering public access to official information, electronic administrative services, and inter-agency communication channels that rely on the domain.

Attention on TheGarudaEye has also grown due to the fact that the MITIC incident does not appear to be an isolated action. The material the group published also featured a broader “target list,” presented as a modified version of a “Board of Peace” graphic that had previously circulated in the media, with markers on countries the group claims have become targets of its operations because of their involvement in that forum.

The “Board of Peace” issue itself refers to an international forum that emerged after a number of heads of state and senior officials gathered to discuss a post-conflict governance framework for Gaza, with dozens of countries recorded as attending or expressing support for the forum. For TheGarudaEye, a country’s involvement in this forum is used as grounds for making it a target of cyber operations, framed as a form of protest against what the group views as support for policies it considers harmful to Palestinians.

Based on the material it released, the countries the group claims to have targeted for joining or being affiliated with the “Board of Peace” forum include Albania, Argentina, Armenia, Azerbaijan, Bahrain, Belarus, Bulgaria, Egypt, Hungary, Indonesia, Israel, Jordan, Kazakhstan, Kosovo, Kuwait, Mongolia, Morocco, and Pakistan. It should be noted that this list comes entirely from the group’s own publication, so the actual scale of operations against each country cannot be independently verified without official confirmation from the respective countries’ authorities.

Who Is TheGarudaEye

TheGarudaEye positions itself as a hacktivist collective with a political orientation aligned with the Palestinian cause. In the message accompanying evidence of the disruption, the group linked its action to the narrative surrounding the “Board of Peace,” an international forum that has recently drawn significant attention over reconstruction and post-conflict governance in Gaza, along with a list of countries the group claims have expressed support for or involvement in the forum.

In the same message, the group also raised concerns about how funds intended for Gaza were being directed, while voicing concerns over efforts it believes threaten the continuity of Palestinian ethnic identity. This narrative was then used as the ideological justification for the group to target Paraguay, given that the country appears on the list it released as one of the parties considered affiliated with the international forum.

Paraguay’s MITIC Server Down for 24 Hours, TheGarudaEye in Spotlight - CyberAsia Threat Intel Evidence

The action was also marked by a number of promotional hashtags, including #OpParaguay, #OpBoP, #TheGarudaEye, #FreePalestine, and #WeAreRevolution. The group also expressed thanks to its “alliance” and supporters, while directing its audience to a private community channel to follow further developments of the operation — a pattern commonly used by hacktivist groups to expand their follower base while sustaining campaign momentum after an incident.

The name TheGarudaEye has not yet been widely recorded in established global cyber threat databases. As a result, its track record, level of technical capability, and any potential links to other, better-known hacktivist groups remain difficult to independently verify at this stage.

Broader Potential Impact

A 24-hour disruption to a ministry’s official domain carries a number of potential consequences. From a reputational standpoint, an incident like this could erode public confidence in the resilience of government digital infrastructure, particularly if it recurs or extends to other strategic institutions in the future. Operationally, if the domain also hosts subdomains or derivative services such as licensing portals, complaint systems, or public information services, the impact of the disruption could extend further than what is visible on the surface.

There is also a non-technical dimension that is no less important. Open publications of this kind also function as a form of psychological pressure and political propaganda, where the success of a campaign is measured not only by the technical damage caused but also by how widely the group’s narrative spreads through media coverage and public discussion. Given indications of a campaign targeting multiple countries at once, the potential for escalation against other government institutions in South America, as well as other countries on the group’s target list, warrants continued attention.

Paraguay’s MITIC Server Down for 24 Hours, TheGarudaEye in Spotlight - CyberAsia Threat Intel Evidence

No Official Response Yet

As of now, neither MITIC nor Paraguay’s national cybersecurity agency has issued an official statement regarding the incident, including the exact cause of the disruption, the status of service recovery, or the technical steps that have been or will be taken to strengthen the system’s defenses going forward. The absence of an official statement in the early aftermath of an incident is common, as technical teams typically prioritize service recovery and internal investigation before issuing public statements.

For government institutions in general, this incident serves as a reminder of the importance of strengthening defenses against volumetric attacks, including the adoption of cloud-based DDoS mitigation services, adequate load-balancing configurations, real-time traffic monitoring, and the preparation of public communication contingency plans for when online services experience disruptions. Cross-agency collaboration between national cybersecurity authorities and technology infrastructure providers is also a key factor in accelerating recovery time while minimizing the impact on public services.

Conclusion

The spotlight now on TheGarudaEye underscores that government institutions in various countries, including in South America, remain targets of hacktivist campaigns that combine political motives with technical action. With the reported disruption lasting a full 24 hours, along with indications of involvement in a broader target list spanning several other countries, this case warrants continued monitoring.

CyberAsia will update this report should official confirmation become available from Paraguayan authorities, or should further clarity emerge regarding the full scale of the campaign carried out by TheGarudaEye.

Disclaimer: CyberAsia is an independent Cyber Threat Intelligence (CTI) research organization. The information provided in this report is derived from public intelligence gathering, dark web monitoring, and threat actor claims. It is published strictly for educational purposes, defensive analysis, and public awareness. CyberAsia does not endorse, verify, or facilitate any cyberattacks or illegal activities.

> INTELLIGENCE_NOTICE

The report above detailing Paraguay’s MITIC Server Down for 24 Hours, TheGarudaEye in Spotlight is part of the CyberAsia public archive. For organizations requiring real-time Indicators of Compromise (IoCs), YARA rules, and extended mitigation strategies for ddos threats, please refer to our Secure Drop or contact the research desk.

> ABOUT_AUTHOR: Clara

Senior Threat Intelligence Analyst and former Cyber Policy Consultant focusing on geopolitical cyber warfare and data privacy.

> related_intel --suggest