CiberLATAMbywhalemate

Oldelval and Qilin drive Argentina ransomware

Oldelval reported a ransomware incident, blamed on The Gentlemen, while Qilin added victims in the same period.

Whalemate Labs · AI-assisted researchPublished:Updated 2 min read

Oldelval informed the CNV of a cyber incident in its administrative systems that it classified as RaaS ransomware and said was claimed by The Gentlemen. The company said the attack was contained, crude oil transport was not disrupted, and administrative systems were restored.

Oldelval told Argentina’s securities regulator, the CNV, about a cyber incident in its administrative systems that it classified as ransomware RaaS and that The Gentlemen claimed. The company said the attack was contained, crude oil transport was not interrupted, and administrative systems were restored.

What else happened during the same period?

During the same window, Security Arsenal reported that Qilin posted 11 new victims between Aug. 4 and Aug. 6, 2026, across multiple countries and sectors, including energy.

What do monitoring data show about recent activity?

A ransomware monitoring feed reported 114 victims published on monitored data leak sites in the past 48 hours.

That total included several claims attributed to Qilin and The Gentlemen, although the figure serves as context for sustained activity and not as verification of a specific Argentine case.

How is the Oldelval case interpreted in that context?

The available coverage points to pressure on public bodies and the energy sector from ransomware, rather than to a confirmed APT or state-backed campaign.

In Oldelval’s case, the attribution cited in the source was to The Gentlemen, and the company said the incident was already under control.

A ransomware map referencing Argentina is also circulating, but the material provided does not support adding more details about victims or a local pattern beyond the episode reported by Oldelval.

Based on the verified elements available, the clearest reading is sustained ransomware activity alongside an incident already reported by the company to the CNV.

Sources

View all