Argentina on the ransomware map
Qilin claimed an attack on the Argentine Army as threat intel platforms add more victims in Argentina and widen the sector map.
Qilin claimed an attack against the Argentine Army on July 24, 2026, according to Dexpose, while other threat intelligence platforms continue to add victims in the country and expand the sector map.
Argentina on the ransomware radar
Qilin claimed an attack against the Argentine Army on July 24, 2026, according to Dexpose. The intelligence platform also says the case draws attention to military and government targets in Argentina, in a context where several OSINT tools had already been showing sustained activity in the country.
Ransomware.live shows the same claim against the Argentine Army. In that mobile view, the group says it exfiltrated data and encrypted systems, although the page does not tie that claim to an official statement from the Argentine government. That lack of institutional confirmation leaves a gap between the public visibility of the threat and formal validation of the victim.
What the maps show
Ransomware.live maps for Argentina show between 169 and 174 historically claimed victims by different ransomware groups. The platform does not specify in those views which of those victims are specifically Argentine organizations, and it does not publish a full list of names or affected sectors.
Even with that limitation, the threat intelligence ecosystem places the country in a significant spot on the regional map. The available sources link groups including Conti, ALPHV, LockBit, BlackByte, CL0P, Qilin, Akira and The Gentlemen, among others, although the material in this report does not provide a full breakdown of the tactics, techniques and procedures associated with each one.
Sectors hit
The La Sevillanita case broadens that picture. Breach House lists the Argentine company as a victim of Global Secret Group, with a leak of about 200 GB of data and the business classified under logistics and transportation.
That record adds another piece to the sector map of victims in Argentina, where the available material links activity to government, finance, business services, manufacturing and healthcare, as well as transportation and supply chains. The exact scope of each campaign still depends on what each platform is able to confirm and publish, which does not always match official confirmation from affected organizations.
Sources
- Ransomware Trackerderp.ca· Derp.ca
- Latin American Governments Targeted By Ransomwarerecordedfuture.com· Recorded Future
- Latin America sees sharp rise in ransomware, hacktivist attacks in 2025 amid expanding fraud and phishing threatsindustrialcyber.co· Industrial Cyber
- LATAM Financial Sector Threat Landscape 2025digiamericas.org· DigiAmericas
- Ransomware Map – Argentinaransomware.live· Ransomware.live
- Ransomware Map – Argentina (mobile view)mobile.ransomware.live· Ransomware.live
- INTERPOL Working Group highlights cyber threats across the Americasinterpol.int· INTERPOL
- Ransomware Criminals Attack Argentine Telecoms Giant, Demand Payout in Moneroredcanary.com· Red Canary
- Qilin Ransomware Group Targets Ejército Argentinodexpose.io· Dexpose
- La Sevillanita — GLOBAL SECRET GROUP Ransomware Attackbreach.house· Breach House



