CiberLATAMbywhalemate
Intelligence report

Argentina Cybersecurity Situation, August 2026

Ransomware led August in Argentina, with Oldelval, health care, and transport at the center, while BCRA and ENACOM reforms advanced.

Sep 1, 202618 min read
Argentina Cybersecurity Situation, August 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are filled automatically with the verified facts dated within the period. Each one states its basis and counting criterion so the figures reconcile across modules. They are the recurring month-to-month reading; the later analysis expands on the cases without repeating this summary.

Indicator window: 86 dated facts in August 2026 · 1 from earlier months (comparative frame, not this month’s volume). Facts from earlier months are used only as a comparative frame in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Verified Signal Monthly Dashboard August 2026 · Argentina Top threat: Ransomware (34 of 84 incidents). Coverage: 86 dated incidents in August 2026 · 1 in prior mont… VERIFIED INCIDENTS 84 period base: all counts is measured from the bottom on this total RANSOMWARE / EXTORTION 34 3 encrypted assets confirmed · 3 exfiltration unencrypted (simple extortion) UNCLASSIFIED INCIDENTS 16 breaches or outages without declared threat type FRAUD / PHISHING 2 documented fraud campaigns documented REGULATIONS 15 rules, resolutions, or penalties UNIQUE CVEs 10 CVE-2026-18556 / CVE-2026-18577
Verified Signal Monthly Dashboard — Base: 84 verified incidents dated in the period for Argentina.
MONTHLY FIXED MODULE Threat Axis Distribution August 2026 · Argentina Each incident counts in only one axis, so the total is exactly 84. "Unclassified incidents" is the remainder. Ransomware 34 Incidents 16 Regulation 15 Unclassified 11 Vulnerabilities 6 Fraud 2
Threat Axis Distribution — Each incident is assigned to a single axis based on its classification; the total reconciles to the 84 incidents in the period.
MONTHLY FIXED MODULE Sectoral Distribution of Signals August 2026 · Argentina Base: 84 incidents in the period · total 103 because 18 incidents are classified in more than one sector. Public Sector / OIV 34 Other / unidentified sector… 28 Telecom 15 Healthcare 10 Technology 8 Finance 5 Retail / Consumer 2 Energy 1
Sectoral Distribution of Signals — Heuristic classification by victim sector. One incident may affect more than one sector, so the total can exceed the base.
MONTHLY FIXED MODULE Critical Infrastructure in Argentina August 2026 · Argentina 4 of 84 events in the period involve critical infrastructure. One event may appear in more than one category. Public sector / government 31 Explicit critical infrastructure 5 Telecom / connectivity 7
Critical Infrastructure in Argentina — Verified signal on public agencies, utilities, and critical sectors

Executive monthly summary for Argentina

Argentina ended August 2026 with ransomware as the leading threat, 34 of 84 verified incidents in the period, in a snapshot where attacks or claims against critical infrastructure, healthcare, transportation, and technology companies coexisted with a very active regulatory front. The most visible case was Oldelval, whose administrative systems were affected without impacting crude oil pumping, but it offered a clear view of the exposure facing energy infrastructure.

The month’s second layer was marked by victims claimed on leak sites and by campaigns centered on extortion, although in most cases the material does not allow a determination of whether there was encryption, exfiltration, or only publication on a portal. That distinction matters. August left more names than operational confirmations, and several episodes have to be read as threat intelligence indications, not fully validated incidents.

At the same time, the local regulatory front moved forcefully. Mendoza advanced its provincial cybersecurity law, ENACOM extended RAMATEL, and the BCRA rolled out changes to transfer-based collections and fraud risk management. At the national level, debates on data protection, cyberbullying, and control of critical technologies also remained active, reinforcing a denser state agenda than the previous month.

The risk reading for Argentina in August is high. Not because of a single large-scale intrusion, but because of the combination of persistent ransomware, exposure of sensitive sectors, digital fraud that remains elevated, and a regulatory layer trying to catch up in a space where extortion, social engineering, and pressure on essential systems are already operating.

Argentina, August 2026, verified milestonesOldelvalcyberattackCiberPlaneta 10CVEsMendoza mediasanctionBCRA CCT inforceQilin healthENACOM RAMATELThe month alternated between operational containment, extortion claims, and regulatory reforms.

Verified events timeline, Argentina, August 2026 — Selected month highlights with confirmed impact or high operational relevance, ordered by date.

National monthly overview in Argentina

Argentina’s monthly risk was high, as the verified volume was concentrated in ransomware, administrative incidents, and extortion campaigns affecting energy, health care, transport, and technology, while digital fraud remained a structural threat. The month did not produce a single catastrophic event, but it did show sustained pressure on organizations with operational or symbolic value.

Oldelval was again the most useful case for reading the country’s situation. The company reported a cyberattack that affected administrative systems, activated response protocols, and kept crude oil transport running without interruption. That sends a dual signal: on one side, segmentation between IT and OT contained the damage; on the other, the episode showed that critical energy infrastructure remains in the crosshairs and that the reporting framework still relies on stock exchange rules rather than a comprehensive cybersecurity law.

The rest of the month reinforced that same idea from other angles. In health care, claims surfaced against Sanatorio Modelo de Caseros and Instituto Ferrero de Neurología y Sueño. In transport, Flecha Bus was added along with other cases on leak sites, and in industry and technology, names such as Neumáticos Corral and Tecno Accion also appeared. Not all were confirmed in the same way, but they do show the ongoing activity of groups that combine public pressure, data leaks, and negotiation.

In the regional context, Argentina was not alone. The activity of The Gentlemen kept growing in South America, Qilin maintained a broad presence, and DragonForce again appeared with victims in the region. That matters because Argentina’s exposure is explained not only by domestic factors, but also by the country’s place in Latin American ransomware campaigns that use leak sites, opportunistic perimeter exploitation, and extortion as a business model.

Period indicators in Argentina

Indicator August 2026 July 2026 Change
Verified facts in the period 84 87 -3
Time window for the indicators 86 facts dated in August 2026 · 1 from prior months (comparison frame, not monthly volume)
Unclassified incidents (breaches or outages) 16 16 unchanged
Cases with ransomware or extortion as the primary focus 34 33 +1
Ransomware breakdown, confirmed asset encryption 3
Ransomware breakdown, exfiltration without encryption (pure extortion) 3
Ransomware breakdown, mention only on leak site 3
Ransomware breakdown, classification could not be determined from the material 25
Documented fraud or phishing cases 2 9 -7
Documented regulatory moves 15 15 unchanged
Critical CVEs mentioned 10 13 -3
Sectors with at least one documented fact 8 8 unchanged
Dominant threat of the month Ransomware (34 of 84 facts) Ransomware (33 of 87 facts) unchanged
Facts with direct source confirmation 56%
Aggregated telemetry figures excluded from volume 2 (aggregated attempts or blocks, not incidents with confirmed impact)
Ransomware and extortion, Argentina, August 202634 items, broken down by type of verifiable impactCifrado confirmado3Exfiltración simple3Leak site3No determinable25Most of the category did not allow technical impact to be defined precisely.
Qualitative distribution of ransomware in Argentina, August 2026 — Breakdown of the ransomware axis by the verifiable impact shown in this month’s material.
Module Reading
Base for all indicators 84 verified facts in the period
Comparison frame 1 fact from prior months, for contrast only
Taxonomy rule ransomware and extortion are not merged if the material makes impact distinguishable
Telemetry aggregated figures for attempts or blocks are not counted as incidents

Narrative breakdown of the verified signal

Axis August reading
Ransomware and extortion dominant axis, with visible campaigns on leak sites and some cases with confirmed impact
Fraud and phishing lower volume than in July, but still persistent against banking, wallets and credentials
Regulation and compliance strong regulatory activity at BCRA, ENACOM, Mendoza and in the personal data debate
Vulnerabilities 10 critical CVEs mentioned in the material, without exhausting the regional exposure

Relevant incidents in Argentina

Oldelval, cyberattack on the main crude oil network

Oldelval was the month’s most sensitive incident because it affected critical energy infrastructure and because it showed, clearly, how an attack can hit administrative systems without stopping industrial operations. The company told the CNV that it suffered a cyberattack, activated its response protocol, and restored the compromised platforms without interrupting crude oil transport.

Available reporting agrees that the impact was limited to the administrative layer and that SCADA systems were not reached. That segmentation matters, but it does not erase the risk signal. The episode also sparked an attribution debate, since several reports pointed to The Gentlemen as a hypothesis, while other sources described ransomware as a service, or even different rivals. The material does not support a single, definitive attribution.

Sanatorio Modelo de Caseros, appearance on Qilin leak sites

In August, Sanatorio Modelo de Caseros appeared in leak site records and threat intelligence platforms as a claimed victim of Qilin, with discovery dates concentrated on 26 August. The material indicates a public claim and possible exfiltration, but the organization did not publicly confirm the incident or the allegedly leaked content.

The operational readout is limited but clear, healthcare remained an attractive target for ransomware extortion. In this case, the source does not let us say with confidence whether systems were encrypted, data was exfiltrated without encryption, or the case only appeared on a leak portal. For that reason, the incident should be treated as an independently unverified claim.

Instituto Ferrero de Neurología y Sueño, extortion threat involving sensitive data

Instituto Ferrero de Neurología y Sueño was mentioned by Dexpose as a target of the Kazu group, which allegedly threatened to disclose sensitive data unless negotiations were opened. Available information points to an extortion campaign focused on the healthcare sector, but it does not publicly confirm the technical scope of the incident.

Here, nuance matters more than the headline. The material does not establish encryption, and it also does not define exfiltration with precision, so the case falls into the category of undetermined classification. Even so, it adds to the list of Argentine clinics, hospitals, and medical centers exposed to groups that use public pressure as a collection tactic.

Flecha Bus, CoinbaseCartel claim over transportation

Flecha Bus appeared in a 24-hour campaign attributed to CoinbaseCartel, where the group published multiple victims and placed the Argentine company within the transportation sector. According to the material, the actor claimed to have compromised sensitive data and threatened to release it if there was no negotiation.

There is no official confirmation from the company or Argentine authorities about the incident. The best read, then, is an extortion claim in a sector that had already shown exposure in August. The case expands the risk perimeter beyond energy and healthcare, and reinforces the idea that transportation came under pressure from opportunistic campaigns.

AMCA and the BLACKWATER claim

The Asociación Mutual de Conductores de Automotores, AMCA, appeared in August in threat intelligence notices and leak sites linked to BLACKWATER. Available material refers to a supposed data breach and system lockout, but it offers no independent validation or confirmed scope of damage.

The incident adds to the map because it places a financial services and insurance organization on the radar of ransomware groups. It also shows the persistence of claims first published by monitoring sites and only later, if at all, confirmed by the victim. In this case, that confirmation has not appeared.

Criba, DragonForce claim involving data from several countries

Criba was listed by DragonForce on its extortion portal, with reference to financial and customer documentation that would cover Argentina, Uruguay, and other countries. Coverage makes clear that the publication is limited to indexing the existence of the leak and the group’s public description.

There was no public validation of the stolen content. Even so, the case matters for two reasons. First, it shows that ransomware groups with strong regional activity continue to use Argentina as an exposure point. Second, it links the country to sensitive datasets that could feed fraud or new waves of social engineering.

Active threats and campaigns in Argentina

Ransomware and extortion, Oldelval as a confirmed case and multiple claims

In August, 34 cases centered on ransomware or extortion, and the material clearly separates three levels of impact. Only three incidents show confirmed asset encryption, another three describe exfiltration without encryption, three more are limited to mention on a leak site, and 25 do not allow the exact classification to be determined.

Oldelval falls into the first group because it confirmed a cyberattack with system recovery, although there was no public confirmation of encryption or exfiltration. The rest of the month was dominated by leak-site campaigns targeting health care, transportation, and technology. That set should not be read as 34 confirmed damage incidents, but as 34 events in which ransomware or extortion was the narrative or operational focus.

Fraud and phishing, lower volume than in July but the same operating vector

Only 2 fraud or phishing cases were documented during the period, compared with 9 in July. The drop does not mean structural relief, because digital fraud remained highly present in the Argentine ecosystem and in the regulatory and legal signals surrounding banking, wallets, and payment methods.

The month’s material again shows the same operating pattern, identity spoofing, WhatsApp messages, fake calls, counterfeit sites, and scams using institutional branding. What is new is not the method, but its continued effectiveness and the burden it is beginning to place on claims, litigation, and stricter authentication mechanisms.

APT and vulnerability exploitation, Argentina as a secondary target in external campaigns

There was no clearly defined local APT campaign during the period based on a primary Argentine source, but there was a relevant technical signal. SCWorld reported that APT groups linked to Russia are exploiting CVE-2026-73570 against government agencies, universities, and state institutions in Brazil and Argentina.

That mention does not make the case a confirmed Argentine incident, but it does place it on the threat radar for the public sector, education, and state infrastructure. The broader context for the month suggests that Argentina remains a target of opportunistic exploitation and regional campaigns, rather than a single isolated sophisticated operation.

Critical vulnerabilities affecting Argentina

CVE Software Exploitation Source
CVE-2026-73570 Zimbra Collaboration Suite Active exploitation mentioned by SCWorld, with campaigns targeting government agencies and universities in Brazil and Argentina SCWorld
CVE-2026-69836 Microsoft Entra ID Active exploitation confirmed in a CiberPlaneta bulletin CiberPlaneta
CVE-2026-68820 Windows Ancillary Function Driver for WinSock (AFD) Active exploitation confirmed by INCIBE-CERT INCIBE-CERT via Moncloa
CVE-2026-18556 N-able N-central Active exploitation included in CISA's KEV SecurityOnline.info
CVE-2026-18577 N-able N-central Active exploitation and use as an initial intrusion vector SecurityOnline.info, Telefónica Tech
CVE-2026-63077 JetBrains TeamCity Active exploitation included in CISA's KEV SecurityOnline.info
CVE-2026-9198 IBM Langflow Active exploitation included in CISA's KEV SecurityOnline.info
CVE-2026-8037 Progress LoadMaster Active exploitation included in CISA's KEV SecurityOnline.info
CVE-2026-72529 TrueConf Server Active exploitation confirmed in a CiberPlaneta bulletin CiberPlaneta
CVE-2026-72530 TrueConf Server Active exploitation confirmed in a CiberPlaneta bulletin CiberPlaneta

The list does not exhaust the country’s vulnerable surface, or the region’s. It includes only the critical vulnerabilities mentioned in this month’s material, and several appear in a regional or global context, not necessarily with confirmed exploitation inside Argentina.

Regulation and compliance in Argentina

Argentina saw a particularly active month on the regulatory front, with concrete steps in cybersecurity, personal data, telecommunications, and financial fraud. The common thread was an effort to bring critical sectors under tighter, more specific rules, although in several cases the framework is still in transition or has not yet become a comprehensive national law.

The most advanced case at the subnational level was Mendoza. The province advanced and then gave half approval to its cybersecurity bill, which creates a Provincial System, a SOC, a CSIRT, and a framework for sanctions, audits, and incident notification. The initiative also adds a Provincial Cybersecurity Strategy and obligations for state technology providers.

At the national level, the BCRA kept expanding its regulatory framework. The Cobro con Transferencia mechanism for loan installments took effect, with explicit conditions for consent, advance notice, and limits on debit attempts. In addition, the Central Bank issued new rules on fraud risk management in payment methods, with phased implementation and full effectiveness scheduled for September 2027.

ENACOM, for its part, extended the rollout of the new RAMATEL until December 1, 2026, and kept a transitional regime for telecommunications equipment approval. That shift is significant. It affects infrastructure, providers, and adaptation timelines, and it adds to the debate over which systems or networks should be considered critical information infrastructure.

The personal data front also remained active. Marval analyzed a new bill that broadens extraterritorial scope, while Congress received proposals on digital violence, cyberbullying, and the protection of children and adolescents. The underlying message is that the country is adding layers of regulation, but still through separate pieces rather than a unified framework.

Most affected sectors in Argentina

The energy sector was the most exposed in August, not because it had the most cases, but because of Oldelval’s systemic importance. The operator of the country’s main oil pipeline turned an administrative incident into a signal of national risk, and that made the episode weigh more than any other individual event in the month. Containment was effective, but the exposure was clear.

Healthcare was the other major focus. Clinics, neurology centers, and private hospitals appeared in ransomware or extortion claims, often with information that had not yet been independently verified. That suggests the sector remains attractive to groups that monetize operational urgency and the sensitivity of clinical data.

Transport and logistics also stayed on the radar. Flecha Bus and other cases, along with Oldelval’s own visibility as an oil logistics network, show that the month had a broader sector map than simple financial fraud. The value of operational assets, the cost of disruption, and the potential for extortion remain decisive factors.

Technology and professional services round out the picture, with Criba, Tecno Accion, and other references appearing on leak sites or intelligence platforms. At the same time, consumer finance and banking kept the background noise going through fraud, complaints, and new collection mechanisms. The public sector, though less visible in confirmed incidents, did appear in regulatory debate and in exposure to leaks and phishing.

Compared with July, the total number of verified incidents fell from 87 to 84, but ransomware accounted for a larger share, rising from 33 to 34 cases. The clearest signal is not a numerical spike, but the same pattern persisting, extortion targeting critical sectors and specific names appearing on leak sites.

The opposite trend appeared in documented fraud or phishing, which dropped sharply from 9 to 2 cases. That should not be read as the problem disappearing. The month was full of context around digital fraud, court rulings, complaints against banks, and new authentication rules, so the decline reflects the makeup of the archive more than a structural easing in the financial front.

The number of critical CVEs mentioned fell from 13 to 10. That also should not be overread. August material continued to show active exploitation of high-profile vulnerabilities, just in fewer verified mentions within the corpus analyzed. The more useful trend is different, the technical attack surface remains broad and ransomware groups are exploiting it quickly.

The variable that merits the closest watch in September is the consolidation of campaigns that publicly pressure health care, transportation, and energy infrastructure. Oldelval showed that the country can contain operational impact, but not that the risk has declined. Add the spread of leak sites with Argentine victims and the continued regulatory agenda, and the next month starts with several open monitoring lines.

Security recommendations for teams in Argentina

  1. Review segmentation between administrative networks, industrial systems, and support layers, with a focus on critical infrastructure. Oldelval showed that containment depends on keeping IT from dragging OT down with it.
  2. Speed up response capabilities for claims on leak sites. In healthcare, transportation, and technology, the first signal is often public before it is internal.
  3. Strengthen authentication and access controls in banking, wallets, and collections processes. Fraud and phishing declined in document volume, but not in their ability to cause harm.
  4. Prepare incident notification and traceability procedures, because the local regulatory framework continues to expand and technical security alone is no longer enough.
  5. Apply urgent patches to products that show active exploitation, especially those in KEV or those mentioned as an initial vector.
  6. Review log retention, restoration, and protection of privileged credentials. In campaigns such as The Gentlemen or Qilin, the pace of operations leaves little room to react.
  7. For sectors handling sensitive data, assume extortion may combine real leakage, mention on a leak site, and threat intelligence noise. It is advisable to prepare responses for all three scenarios.

Frequently Asked Questions

What connects Oldelval, health care, and transportation in August?

All three sectors were exposed to ransomware pressure or extortion, but with different effects. Oldelval suffered a confirmed cyberattack with no operational shutdown, health care concentrated several claims on leak sites, and transportation appeared with Flecha Bus. The Relevant Incidents section and the Active Threats and Campaigns section show that overlap.

Did digital fraud in Argentina really fall, or did it just change shape?

The number of documented cases in the month’s material fell from 9 in July to 2 in August, but the problem did not disappear. The context of banking, wallets, complaints, and new BCRA rules shows continuity. The difference is between documented volume and structural persistence, which appears in Trends and Regulation.

What is the difference between a victim on a leak site and a confirmed incident?

A victim on a leak site is a public claim by the attacker or a monitoring portal, while a confirmed incident means validation by the organization, the regulator, or the primary source. In August there were several claimed cases without independent confirmation, such as Sanatorio Modelo de Caseros, Flecha Bus, or AMCA.

What does it mean that 10 critical CVEs were mentioned, and not more?

It means that ten critical vulnerabilities appeared in the month’s analyzed material, not that only ten exist in the region or in the country. The figure does not capture the full technical universe. The Critical Vulnerabilities with Impact in Argentina table explains which ones were actually mentioned in August.

Which sectors should review the full report first?

Energy, health care, transportation, technology, financial services, and the public sector. The month showed a mix of confirmed incidents, extortion claims, and regulatory changes that directly affect those industries. The Incidents, Regulation, and Most Affected Sectors sections cover the details.

Material limitations

This report was built exclusively from the material provided for Argentina in August 2026 and from one comparative fact from July 2026. The indicators reproduce exactly the declared base, 84 verified events from the period, and the time window of 86 events dated in August 2026 plus 1 from prior months used only as a comparative frame.

A zero indicator, or a figure lower than the previous month, does not mean the phenomenon is absent from the region. In particular for CVEs, the count reflects only what was recorded in the material analyzed, not the full set of critical vulnerabilities exploited in Argentina or the Southern Cone.

Aggregated telemetry figures were also excluded, because they are attempts, blocks or automated scans and not incidents with confirmed impact. If they are mentioned, they should be read as technical background noise, not as intrusion volume.

Finally, sources not available in the authorized list were excluded, and publications outside that universe were not used. In the case of social media, only those already integrated into the material as corroborated leads or as secondary evidence allowed by the working file were taken, always without turning them into an independent monthly volume.

Sources