CiberLATAMbywhalemate

Argentina's AMCA listed by BLACKWATER

Breachsense flagged amca.org.ar as a BLACKWATER victim on Aug. 17, 2026. Security Arsenal also cited it among two new leak-site victims.

Whalemate Labs · AI-assisted researchPublished:3 min read

Breachsense listed amca.org.ar as a victim of the BLACKWATER ransomware group and dated the incident discovery to Aug. 17, 2026. Security Arsenal also said the actor posted two new victims on its leak site, including an organization in Argentina, while technical analysis ties these campaigns to VPN access and remote tools.

Breachsense listed amca.org.ar as a victim of the BLACKWATER ransomware group and dated the incident discovery to Aug. 17, 2026. At the same time, Security Arsenal said the actor had posted two new victims on its leak site, including an organization in Argentina. In AMCA's case, the listing describes it as an Argentine mutual association focused on auto insurance coordination, roadside assistance, and financial benefits for drivers.

What is known about AMCA?

Breachsense identifies AMCA as an Argentine mutual association tied to services for drivers, not just as a generic professional services entity. The record also notes 34 accounts with the @amca.org.ar domain exposed in earlier external breaches, along with 64 credentials linked specifically to amca.org.ar, a volume that raises the risk of ransomware compromise or credential-based intrusions.

Security Arsenal, for its part, described www.amca.org.ar as part of a broader pattern of opportunistic targeting of professional services in Latin America. That characterization was attributed by the source, but no independent official confirmation was included in the material provided.

What techniques connect these campaigns to the perimeter?

Security Arsenal attributed to BLACKWATER a possible focus on organizations with perimeter VPNs and unpatched remote access tools, with Latin America mentioned in that context. In the same vein, for THEGENTLEMEN it described an operational pattern built around perimeter intrusion, rapid exfiltration, leak threats, and negotiation under pressure.

The report on THEGENTLEMEN also identified specific TTPs, including VPN and perimeter abuse, RMM abuse, lateral movement with PsExec and WMI, shadow copy destruction, and pre-encryption staging. Barracuda added that the ransomware uses XChaCha20 encryption with Curve25519 and spreads in Active Directory environments through WMI, PowerShell, PsExec, and Group Policy objects, reinforcing the technical picture of attacks designed to move quickly inside the network before encryption begins.

Why does this matter for Latin American organizations?

The material points to a consistent risk for entities that rely on remote access and exposed perimeters. In AMCA's case, the accumulation of previously documented leaked credentials in Breachsense adds to the attack profile Security Arsenal associates with BLACKWATER. For THEGENTLEMEN, the use of legitimate administrative tools and shadow copy destruction shows a campaign aimed at speeding up intrusion and making recovery harder.

Together, these elements leave two concrete signals in the region, victims published on leak sites and a set of TTPs built around VPN, RMM, and lateral movement with native Windows tools, especially in Active Directory environments.

Sources

View all