CiberLATAMbywhalemate

Oldelval and Qilin drive Argentina ransomware

Oldelval reported a ransomware incident, blamed on The Gentlemen, while Qilin added victims in the same period.

Whalemate Labs · AI-assisted researchAug 12, 20262 min read

Oldelval informed the CNV of a cyber incident in its administrative systems that it classified as RaaS ransomware and said was claimed by The Gentlemen. The company said the attack was contained, crude oil transport was not disrupted, and administrative systems were restored.

Oldelval informed Argentina’s CNV of a cyber incident in its administrative systems that it classified as RaaS ransomware and said was claimed by The Gentlemen. The company said the attack was contained, crude oil transport was not disrupted, and administrative systems were restored.

Pressure on energy and public agencies

Oldelval’s case fits into a run of ransomware activity that also included Qilin. In the same time window, Security Arsenal reported that the group posted 11 new victims between Aug. 4 and 6, 2026, across multiple countries and sectors, including energy.

As additional context, a ransomware monitoring feed reported 114 victims published on monitored data leak sites in the last 48 hours. That count included several claims attributed to Qilin and The Gentlemen, although it serves as context for sustained activity and not as confirmation of a specific Argentine case.

What is known so far

Available coverage points to pressure on agencies and the energy sector from ransomware, rather than to a confirmed APT or state-linked campaign. In Oldelval’s case, the attribution cited in the source was to The Gentlemen, and the company said the incident was already under control.

A ransomware map referencing Argentina is also circulating, but the material provided does not allow for more detail on victims or a local pattern beyond the episode reported by Oldelval. Based on the verified elements available, the clearest picture is one of sustained ransomware activity alongside an incident already reported by the company to the CNV.

Sources

View all