CiberLATAMbywhalemate
Intelligence reportAug 1, 202618 min read

Argentina: cybersecurity landscape, July 2026

July saw ransomware dominate, 15 regulatory moves, 13 critical CVEs, and heavy pressure on finance

Argentina: cybersecurity landscape, July 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are automatically completed with the verified dated facts within the period. Each one states its basis and counting criterion, so the figures reconcile across modules. They are the recurring reading month to month, the later analysis develops the cases without repeating this summary.

Indicator window: 87 dated facts in July 2026 · 4 from previous months (comparative frame, not monthly volume). Facts from previous months are used only as a comparative frame in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Monthly verified signal dashboard July 2026 · Argentina Leading threat: Ransomware (33 of 87 incidents). Coverage: 87 dated incidents in July 2026 · 4 prior months… VERIFIED INCIDENTS 87 period base: all counts all lower values are measured against this total RANSOMWARE / EXTORTION 33 11 unencrypted exfiltration (simple extortion) · 4 only leak site mention · 18 UNCLASSIFIED INCIDENTS 16 breaches or outages with no threat type declared FRAUD / PHISHING 9 documented fraud campaigns REGULATION 15 rules, resolutions or penalties UNIQUE CVEs 13 CVE-2026-0257 / CVE-2026-16723
Monthly verified signal dashboard — Base: 87 verified dated incidents for Argentina.
MONTHLY FIXED MODULE Threat-axis distribution July 2026 · Argentina Each event is counted on only one axis, so the total is exactly 87. "Unclassified incidents" is the remainder. Ransomware 33 Incidents 16 Regulation 15 Vulnerabilities 11 Fraud 9 Unclassified 3
Threat-axis distribution — Each event is assigned to one axis based on its classification; the total reconciles to the 87 events in the period.
FIXED MONTHLY MODULE Sectoral distribution of signals July 2026 · Argentina Base: 87 incidents in the period · total 113 because 23 incidents were classified in more than one sector. Public sector / OIV 49 Other / no sector ident… 22 Technology 15 Telecom 13 Finance 8 Retail / consumer 3 Education 2 Healthcare 1
Sectoral distribution of signals — Heuristic sector classification by victim. One incident may affect more than one sector, so the total can exceed the base.
MONTHLY FIXED MODULE Critical Infrastructure in Argentina July 2026 · Argentina 10 of 87 events in the period involve critical infrastructure. One event may appear in more than one category. Public sector / government 49 Energy / utilities 1 Telecom / connectivity 8
Critical Infrastructure in Argentina — Verified signal on public agencies, utilities, and critical sectors

Executive monthly summary for Argentina

July sent a clear signal in Argentina. The month was dominated by ransomware and cyber extortion, with 33 incidents out of 87 verified, while documented fraud and phishing cases totaled 9. At the same time, the country recorded 15 regulatory moves and 13 critical CVEs mentioned in the material analyzed. The pattern does not point to a single crisis front, but to several at once: provincial government under pressure, the financial system forced to tighten controls, and a compliance agenda that accelerated with new bills and resolutions.

The most visible public-sector case was the defacement attack on the Mendoza Senate website, which took place on July 24. The homepage was altered with an image of Claudio "Chiqui" Tapia and a message against Argentina, with attribution signed by "B133DR00T". That episode unfolded alongside legislative progress on Mendoza's Cybersecurity Law, which continued through committees in the provincial Senate and led to new coverage, parallel data protection proposals, and references to a provincial cybersecurity system. The sequence does not prove a causal link between the bill and the attack, but it does expose a climate of public exposure and accelerated institutional response.

In ransomware, the month was marked more by claims and leak-site listings than by technical confirmation of encryption. The Gentlemen claimed Mercado Libre Argentina and later Oldelval, while Qilin listed the Argentine Army and other Argentine organizations in monitoring sources. In several of those cases, the source makes clear there is no public confirmation of intrusion or that the real scope cannot be determined. That does not reduce the operational importance of the threat, because the extortion pattern is already putting pressure on reputation, negotiations, and legal response, but it does require a sharp distinction between confirmed exfiltration, a listing on a leak portal alone, and possible system encryption, when the material does not allow that difference to be established.

The financial sector was the other major front of the month. There were sanctions in Córdoba for security failures in the face of digital scams, court rulings against banks over losses tied to virtual fraud, public warnings from the BCRA about new scam methods, and a police operation that dismantled a fake home banking and phishing ring. Added to that was the adoption of artificial intelligence tools by banks and fintech firms for fraud detection, a sign of a more mature defensive response, but still one that remains reactive in the face of a fraud ecosystem that is becoming more professionalized.

National snapshot for the month in Argentina

Argentina’s risk level in July was high. Not because of a single confirmed large breach, but because of the density of verified incidents, the range of affected sectors, and the coexistence of extortion, fraud, public exposure of government websites, regulatory changes, and critical vulnerabilities. The material points to a country where the operational and legal cost of a cyber incident no longer stays confined to the technical team. It also affects public administration, financial oversight, litigation, and administrative sanctions.

The dominant trend was ransomware, but its main form was extortion centered on public pressure or leaks, not necessarily confirmed encryption. That matters because it changes the operational read. In several cases, the value of the attack lies in posting a claim, selectively exposing data, or threatening a leak, while the affected organization has not yet made an official statement. From a response standpoint, that requires stronger monitoring of leak sites, legal response, and crisis communications, in addition to classic technical containment.

The regulatory front also moved more actively than in previous months. Mendoza accounted for much of the local agenda with a Cybersecurity Law proposal that includes a strategic committee, an operational authority, a provincial SOC, an asset inventory, risk management, tiered sanctions, and reporting obligations. At the national level, Resolution 725/2026 expanded the powers of federal forces for prevention in digital environments, and the BCRA continued to solidify a more traceable oversight framework for the financial system. The picture is one of a more active, more demanding regulatory environment with higher expectations for rapid incident response.

In the regional context, the pressure is not only Argentine. July’s material also shows a Latin American push to strengthen regulation around privacy, child protection, deepfakes, and digital fraud. For Argentina, that dynamic matters because it raises compliance standards and because several of the criminal vectors appearing in the country, especially social engineering and AI-assisted identity fraud, are already part of a broader regional wave.

Sectors with documented indicatorsFinanceGovernmentEnergyLogisticsCommerceTelecomhigh pressureactive agendaclaims and riskfraud and extortionbrand and paymentsbroad attack surface
Sectors with documented indicators in Argentina — Presence of verified incidents by sector, with possible overlap across categories.

Argentina period indicators

Indicator Value Base / window
Verified events in the period 87 Base for all indicators, dated July 2026
Time window for the indicators 87 events dated July 2026 Additional comparison frame, 4 events from prior months, not monthly volume
Unclassified incidents (breaches or outages) 16 Events in the period
Cases with ransomware or extortion as the primary focus 33 Events in the period
Exfiltration without encryption (simple extortion) 11 Breakdown within ransomware/extortion
Leak site only mention 4 Breakdown within ransomware/extortion
Unclear classification based on available material 18 Breakdown within ransomware/extortion
Documented fraud or phishing cases 9 Events in the period
Documented regulatory moves 15 Events in the period
Critical CVEs mentioned 13 Events in the period
Sectors with at least one documented event 8 One event may affect more than one sector
Dominant threat of the month Ransomware 33 of 87 events
Events with direct source confirmation 59% Direct confirmation out of total verified

Relevant incidents in Argentina

Mendoza Senate defacement, public dispute over cybersecurity

On July 24, the official website of the Mendoza Senate was defaced, with its homepage replaced by an image of Chiqui Tapia, along with the phrase "Senado de Mendoza, hackeado" and a message against Argentina. TN reported that the group calling itself "B133DR00T" claimed responsibility for the action, and authorities opened an investigation to determine the origin of the attack and how the systems were breached. Hostin classified the episode as a defacement attack and said no leakage of sensitive data had been reported at the time of coverage.

The significance of the case goes beyond the visual impact. It came during legislative treatment of the provincial Cybersecurity Law bill, and several media outlets linked it to the introduction of the initiative. In the coverage reviewed, that connection appears conjectural, so the incident should not be read as proven retaliation. Even so, it exposes a vulnerable public surface, an institutional response still taking shape, and a narrative of state "hardening" that became central immediately after the attack.

AFA, unauthorized access to institutional email

On July 9, the Argentine Football Association acknowledged unauthorized access to an institutional account linked to AFA Medios. From that mailbox, emails were sent to journalists criticizing the refereeing of the match against Egypt in the 2026 World Cup. The organization clarified that the messages were not issued by its communications team and said it was investigating the scope of the incident.

Later coverage expanded the technical and threat context, but the official version remained limited to that improper access to an account. In other words, the verified fact does not confirm a broader intrusion or a generalized data leak. Even so, the case shows how a single compromised account can become a vector for reputational damage and disinformation, especially when tied to a high-profile public event.

Córdoba, administrative penalties for banks and digital wallets

The General Directorate for Consumer Protection and Commercial Fairness in Córdoba imposed fines totaling $386.204.804,30 on banks and virtual wallets, with entities including Banco Galicia, Banco Macro, Banco Santander, Banco Supervielle, Tarjeta Naranja and Prisma Medios de Pago among those affected. The sanction was based on failures in security measures and in responding to users affected by digital scams and other cybercrimes.

The case matters because it was not limited to a warning. There was a financial penalty, an ex officio investigation and a clear message about the responsibility of financial actors in the face of digital fraud. From a public policy perspective, the episode places user security within consumer protection and compliance, not just technical cybersecurity.

Commercial courts and partial restitution in bank fraud cases

Two court rulings added another layer to the month. In one, Infobae reported that an Argentine bank was ordered to reimburse part of the money lost in an online scam that emptied a customer’s account. In another, the National Commercial Court of Appeals increased compensation in favor of a retiree whose account was hacked and who was improperly listed in the BCRA’s debtors registry.

Both rulings show that financial damage from digital fraud is no longer handled only as a private issue between user and institution. Courts are incorporating duties of care, correction of records and compensation for moral harm, with direct consequences for incident handling, claims and transaction traceability.

Operation against a fake home banking gang

Toward the end of the month, federal and provincial forces dismantled a gang dedicated to virtual scams and the theft of banking data through phishing and fake home banking pages. The operation included 18 raids, 12 arrests and the seizure of phones, computers, counterfeit cards, cash and vehicles.

This is a significant case because it confirms that digital fraud in Argentina is not just a set of scattered campaigns. There are also criminal structures with logistics, capture infrastructure and the ability to persist. The context note matches warnings from the BCRA and several reports on identity theft, reinforcing the operational nature of this vector rather than a merely opportunistic one.

Threats and active campaigns in Argentina

Ransomware and simple extortion

The Gentlemen and Mercado Libre Argentina

The Gentlemen claimed to have attacked Mercado Libre Argentina and later added it to its leak portal. The available reporting did not confirm a successful intrusion or operational damage, so the strongest verifiable fact is the public threat and the mention on the extortion site. At this point, precision matters, the source does not support claims of asset encryption or proven exfiltration. What it does support is placing the case within a campaign of reputational pressure and forced negotiation.

The Gentlemen and Oldelval

Oldelval also appeared in follow-up material as a presumed victim of The Gentlemen. Some sources say internal data was exfiltrated, but others note there was no official notice and the real scope remained unknown. For this report, the classification remains undetermined in several passages, although the pressure on energy infrastructure is evident from the sector involved and the symbolic weight of the target.

Qilin and the Argentine Army

Qilin listed the Argentine Army on its leak portal and several trackers reproduced the entry. ShellCodeX made it explicit that this is an "unverified claim". Ransomware.live and Dexpose place the claim on July 24. Again, what is confirmed is the leak site mention and the public assertion, not a breach validated by the institution. The significance of the case is that a defense target entered the extortion circuit visible to ransomware operators and observers.

Gran Valle Negocios and La Sevillanita

During the month, claims also surfaced about Gran Valle Negocios and La Sevillanita on specialized trackers. In both cases, the available material refers to alleged exfiltration by the attacking group or to data published on leak sites, but with no public official confirmation. For Argentina, these two episodes broaden the map of pressure on logistics, services and construction, and reinforce a distributed extortion campaign across multiple sectors.

Fraud and phishing

Home banking, identity theft and WhatsApp

Digital fraud remained heavily concentrated on social engineering. Reports covered the new home banking lockout scam followed by fake calls, paid likes scams, identity theft on WhatsApp using profile photos of family members or contacts, and campaigns combining voice cloning, synthetic images and fake profiles. These are not isolated cases. They describe a criminal market that already works with recurring pretexts and a highly tuned emotional playbook.

The operational point is clear. In all of these cases, the first line of defense remains verification through official channels, cutting off contact and keeping a record of what happened, because the groups still rely on urgency, shame and fear. The BCRA recommendation to document dates, amounts, channels and transaction types matches that reality.

AFA, unauthorized emails and reputational deception

Although the AFA case was not a financial fraud, it followed the same logic of impersonation and trust abuse. The sender used an institutional account to send unauthorized content. From a campaign perspective, that type of event sits close to social engineering and corporate identity manipulation, a border that is becoming increasingly blurred between technical intrusion, communications fraud and reputational exploitation.

Criminal operations with AI

The July material shows a jump in offensive uses of AI. Several analyses cite deepfakes, synthetic identities and automation to expand fraud at scale. In Argentina, the most relevant data point is not only criminals adopting these tools, but also banks and fintechs adjusting their defenses with biometrics, behavioral analytics and checks against official databases. That confirms the conflict is already entrenched at the identity layer.

APT, hacktivism and public defacement

Defacement of the Mendoza Senate

The Mendoza Senate incident fits better as hacktivism or defacement than as a sophisticated espionage operation. The message was political, the visibility was public and the main effect was reputational. The investigation opened by authorities indicates that the entry vector was still under review. This case deserves monitoring because, even without confirmed leakage, it shows that exposed institutional sites remain an easy way to generate media impact.

Critical vulnerabilities affecting Argentina

CVE Software Exploitation Source
CVE-2026-56155 Microsoft ADFS Active exploitation confirmed by Microsoft Threat Intelligence Gustavo Sied, SIED.AR
CVE-2026-56164 Microsoft SharePoint Active exploitation confirmed by Microsoft Threat Intelligence Gustavo Sied, SIED.AR
CVE-2026-48282 Adobe ColdFusion Active exploitation, included by CISA in KEV CronUp, RadioCSIRT, Integrity360
CVE-2026-48908 JoomShaper SP Page Builder Active exploitation, included by CISA in KEV RadioCSIRT, Integrity360
CVE-2026-56290 Joomlack Page Builder Active exploitation, included by CISA in KEV RadioCSIRT, Integrity360
CVE-2026-55255 Langflow Active exploitation, included by CISA in KEV RadioCSIRT
CVE-2026-16812 Arista VeloCloud Active exploitation, CVSS 10.0 Codigo Vigia
CVE-2026-0257 Palo Alto Networks firewalls Active exploitation confirmed, used as initial access vector for Qilin Devel Group
CVE-2026-16723 FastJson Active zero-day exploitation Devel Group
CVE-2026-54420 LiteSpeed for cPanel Active exploitation, included in KEV Telconet CSIRT
CVE-2026-46817 Oracle E-Business Suite Active exploitation reported and later added to KEV Blog de Gustavo Sied
CVE-2026-39808 FortiSandbox Active exploitation, CVSS 9.1 Blog de Gustavo Sied
CVE-2026-25089 FortiSandbox Active exploitation, CVSS 9.1 Blog de Gustavo Sied

Regulation and Compliance in Argentina

July was a busy month for regulation. Most of the local signal centered on two fronts, tighter provincial state rules in Mendoza and stricter supervisory and response standards in the financial system. The pattern reflects a country that no longer treats cybersecurity as a single sector policy, but as a mix of public governance, compliance, operational continuity, and reporting obligations.

In Mendoza, the Cybersecurity Bill kept moving through Senate committees. The consolidated coverage of the legislative text points to a broad institutional design, with a Strategic Steering Committee, an Operational Authority, a provincial SOC, a government CSIRT, an inventory of critical assets, risk management, information classification, a sanctions regime, and scope over different branches of government and third-party technology providers that deliver critical services. The bill also includes a workstream on ethical hackers, or white hats, which suggests an effort to formalize technical collaboration rules.

The proposal also has a compliance dimension that goes beyond traditional cybersecurity. Bringing privacy by design into the text, requiring incident notification within 72 hours in the parallel Fuerza Patria draft, and naming data protection officers brings the local debate closer to more mature data governance practices. The province appears to be aiming for a regulatory framework that combines prevention, response, and accountability.

At the national level, Resolution 725/2026 from the Ministry of Security expanded the authority of federal forces against cybercrime and network threats, with special rules for interventions involving minors. It is a sensitive measure because it sets out what the government can do online and under which exceptions. In parallel, BCRA Communication B 13208/2026 strengthened formal information and authorization workflows within the financial ecosystem, and the Central Bank continued to push a stricter traceability model.

Disposition 8/2026 from Consumer Defense added another layer of public disclosure for final sanctions, with data available to the public. While it is not a cybersecurity rule in the strict sense, it affects the reputational exposure of providers sanctioned for fraud and security-related failures. In the same vein, sanctions in Córdoba make clear that digital fraud oversight already carries concrete administrative consequences.

Most affected sectors in Argentina

The financial sector was the month’s most consistent signal. Fraud, sanctions, court rulings, regulatory warnings and the adoption of stronger authentication measures all appeared. The pressure is coming not only from incidents, but also from regulatory expectations and litigation. A bank or wallet that fails to respond well to fraud faces operational loss, sanctions and reputational damage at the same time.

The public sector was the second major focus. Mendoza brought defacement, debate over the law, discussion of data protection and the argument that critical services must be hardened. In addition, the federal resolution on prevention in digital environments and the CNC order on continuity in public data centers show that the state became central to resilience planning.

Energy and critical infrastructure also stood out clearly. Oldelval, Vaca Muerta and the Argentine Army appear in extortion material or strategic-risk material. In energy, the material does not always allow a confirmed impact, but the direction of the pressure is clear. For security teams, that means ransomware claims must be treated as part of operational risk, even when the incident has not been fully verified.

Telecommunications, logistics, e-commerce and media also appeared, although less often. The key point is that the 8 sectors with documented facts are not isolated compartments. One incident can affect more than one. Mercado Libre, for example, combines e-commerce and financial services; AFA combines institutional communications and public brand exposure; the Senate combines government, digital services and citizen trust.

There is no comparable baseline for most of the previous month’s indicators in the series provided, so it would be inaccurate to claim month-over-month increases or decreases. The useful exception is qualitative: July looks more weighted toward extortion, fraud, and regulation than toward technically confirmed incidents with a high level of detail. That does not mean lower risk. It means the risk showed up more clearly in public pressure, victim complaints, legal action, and regulatory response.

The most important signal for August is the persistence of the ransomware pattern without verified encryption, or with an undetermined scope. As leak sites keep posting lists of Argentine victims, it will be necessary to distinguish carefully between what is confirmed, what is a claim, and what is simple pressure. Confusing those three levels can lead to overestimating or underestimating the real incident.

Another signal to watch is the acceleration of AI-assisted identity fraud. Sumsub, BioCatch, and other coverage cited in the material show strong growth in social engineering and deepfakes in the region, with direct impact in Argentina. In the short term, this will drive more double verification, biometrics with liveness detection, behavioral analytics, and checks against official sources. The cost of friction will remain a key variable.

On regulation, Mendoza will remain the case to watch because of its regulatory ambition. The bill is still under review, but it has already pointed to a more complete cybersecurity governance model than other provincial texts. If it moves forward, it could become a reference for other districts. The implementation of Resolución 725/2026 and the measures from the BCRA will also need to be monitored, because their practical impact will depend on protocols, enforcement, and the response of operators.

Security recommendations for teams in Argentina

  1. Review internal classification between encryption, exfiltration, and simple mention on a leak site. With July’s data, that distinction changes the risk picture and the response entirely.
  2. Strengthen monitoring of brands and institutional domains. The Senate of Mendoza and AFA cases show the first warning sign can be reputational before technical.
  3. Increase readiness against identity fraud and impersonation through WhatsApp, fake calls, and online banking. The main vector this month remained social engineering, not complex malware.
  4. Require full operational traceability for financial incidents, with times, amounts, channels, and authorizations. That information is already appearing as a useful requirement in coverage of the BCRA and in later complaints.
  5. Review exposure to actively exploited CVEs, especially in perimeter appliances, publishing software, web frameworks, and collaboration suites. The month showed several actively exploited flaws in widely deployed products.
  6. Update crisis playbooks for ransomware claims. Even without immediate technical confirmation, publication on leak sites may require legal communications, third-party monitoring, and evidence preservation.
  7. In public and critical environments, move forward on asset inventories, RTO, RPO, recovery testing, and real system segmentation. July’s material again shows continuity and security can no longer be separated.

Material limitations

This report was prepared exclusively from the material provided for July 2026 and does not use the internet or external sources. The indicator window is the one stated above, 87 dated events in July 2026, plus 4 events from earlier months used only as a comparative frame and never as the month's volume.

An indicator at 0, when one exists, would mean it did not appear in the material reviewed for this period, not that the phenomenon did not occur in Argentina or the region. This applies especially to CVEs, where the absence of data in a table or indicator does not mean there were no critical vulnerabilities exploited in reality, but rather that the corpus for this month did not record them. In this report, 13 critical CVEs were mentioned, so that distinction applies as a general methodological principle.

Ransomware taxonomy was handled with a strict separation between exfiltration without encryption, mention only on a leak site, and indeterminate classification. When the source did not specify whether encryption occurred, the text made that explicit. Aggregated telemetry was also not counted as incidents, because the material did not provide figures of that kind for the period.

Consumer social media and sponsored posts or press release style publications that do not appear on the list of citable sources were excluded as evidence. If any item mentions X, Instagram, Threads, LinkedIn, or similar material, it was not used as evidence in the body of the report. Any statement that depended only on promotional material to present it as an established trend was also avoided.

Analytical infographic of the month

Sources