Qilin puts Argentine Army on leak site
Qilin added the Argentine Army to its leak site and tied it to a claimed July 24 attack. Signs of credential theft also emerged.
Qilin added the "Argentine Army" to its leak site on July 24, 2026. IntelFusions says the listing is unverified and appears meant to pressure the alleged target, not confirm a breach. At the same time, Dexpose said the group publicly claimed an attack on the official Argentine Army domain, argentina.gob.ar/defensa/ejercito, while Ransomware.live flagged infostealer activity on associated accounts and more than 200,000 compromised users.
Qilin added the "Argentine Army" to its leak site on July 24, 2026. IntelFusions says the entry is an unverified leak-site listing, used to pressure the alleged target rather than confirm a breach.
What is known about the case
Dexpose reported that on July 24, 2026, Qilin publicly claimed an attack against the Argentine Army’s official domain, argentina.gob.ar/defensa/ejercito, and threatened to expose sensitive military data. That post lines up in time with the listing seen on the leak site.
Ransomware.live, meanwhile, shows a specific "Ejército Argentino" record attributed to Qilin, discovered the same day. The record references the Army’s official domain and points to infostealer activity on associated accounts, which supports the view that at least credential compromise occurred, even if the main intrusion has not been verified.
The same source estimates that the Qilin-linked entry corresponds to an attack dated July 24, 2026, and lists more than 200,000 compromised users in related infostealer activity. That scale suggests a high risk of credential reuse and a possible access vector for ransomware operators.
Qilin activity context
IntelFusions recorded 27 listings from Qilin between July 22 and 25 on its leak site, part of a broader pace of about 120 claims over the past month. Against that backdrop, the Argentine Army case falls within a period of elevated global activity for the group.
The same publication describes Qilin, also known as Agenda, as a ransomware-as-a-service operation active since 2022. Its model combines a core team that maintains the encryptor and leak-site infrastructure, while affiliates carry out intrusions in exchange for a share of the ransom.
IntelFusions adds that Qilin is known for targeting VMware ESXi virtualization servers and links it to the 2024 incident that disrupted blood test services in London hospitals. That history helps frame the kind of environment the group tends to exploit.
The situation in Argentina
Over the past 12 months, IntelFusions recorded 62 ransomware leak-site claims against Argentine organizations, spread across 17 different groups. That figure suggests the real number of victims in the country may be higher than what appears in narrower panels such as Pulse.
Ransomware.live also lists between 169 and 174 victims attributed to Argentina on its interactive map, far above the 10 recent victims visible in the Pulse panel. For the local ecosystem, that indicates activity against Argentine organizations has been broader in both time and group diversity than some partial datasets show.
RansomLook, meanwhile, records more than 32,000 ransomware posts since 2022 and places Qilin among the most active groups, with 14.9% of posts in its recent sample and an increase of more than 200% over the past week. The Argentine Army case lands within that global spike in activity.
Sources
- Ransomware Wing — víctimas, grupos y patronespulse.kalir.io· Pulse
- La llegada de los “cárteles” a la ciberseguridadinversorlatam.com· Inversor Latam
- Qilin ransomware lists Argentina's army on its leak siteintelfusions.com· IntelFusions
- Victim: Ejército Argentinoransomware.live· Ransomware.live
- Ransomware.live 👀 — Map ARransomware.live· Ransomware.live
- RansomLook — Open ransomware intelligenceransomlook.io· RansomLook
- Qilin Ransomware Group Targets Ejército Argentinodexpose.io· Dexpose



