CiberLATAMbywhalemate
Intelligence report

Argentina Cybersecurity Situation, September 2026

Ransomware led September in Argentina, with 66 verified incidents, 33 extortion cases, and new BCRA measures.

Oct 1, 202616 min read
Argentina Cybersecurity Situation, September 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are automatically populated with verified, dated facts from within the period. Each one states its source base and counting criterion so the figures can be reconciled across modules. They are the recurring month-to-month readout, and the analysis that follows expands the cases without repeating this summary.

Indicator window: 66 dated facts in September 2026 · 2 without confirmed date (excluded from the indicators). Facts from earlier months are used only as a comparative frame in the analysis, never as part of this period’s volume.

CIBERLATAM / WHALEMATE Verified Signal Monthly Dashboard September 2026 · Argentina Top threat: Ransomware (33 of 66 incidents). Coverage: 66 dated incidents in September 2026 · 2 undated… VERIFIED INCIDENTS 66 period base: all counts measured from the bottom on this total RANSOMWARE / EXTORTION 33 3 data exfiltration, no encryption (simple extortion) · 4 only mentioned on leak site · 26 UNCLASSIFIED INCIDENTS 10 breaches or outages with no threat type declared FRAUD / PHISHING 0 documented fraud campaigns documented REGULATION 7 standards, resolutions, or sanctions UNIQUE CVEs 8 CVE-2024-1708 / CVE-2026-20316
Verified Signal Monthly Dashboard — Base: 66 verified incidents dated in the period for Argentina.
MONTHLY FIXED MODULE Threat axis distribution September 2026 · Argentina Each event is counted in only one axis, so the total is exactly 66. "Unclassified incidents" is the remainder. Ransomware 33 Incidents 10 Unclassified 10 Regulation 7 Vulnerabilities 6
Threat axis distribution — Each event is assigned to a single axis based on its classification; the total reconciles to the 66 events in the period.
MONTHLY FIXED MODULE Sectoral Distribution of Alerts September 2026 · Argentina Base: 66 incidents in the period · total 96 because 24 incidents are classified in more than one sector. Public sector / OIV 41 Other / no sector identi… 17 Education 12 Technology 7 Telecom 6 Healthcare 5 Energy 5 Retail / Consumer 3
Sectoral Distribution of Alerts — Heuristic classification by victim sector. One incident may affect more than one sector, so the total can exceed the base.
MONTHLY FIXED MODULE Critical Infrastructure in Argentina September 2026 · Argentina 18 of 66 events in the period involve critical infrastructure. One event may appear in more than one category. Public sector / government 41 Telecom / connectivity 6
Critical Infrastructure in Argentina — Verified signal on public agencies, utilities, and critical sectors

Monthly executive summary for Argentina

September ended in Argentina with elevated operational pressure in cybersecurity, driven by ransomware and extortion, alongside a regulatory agenda that moved on financial fraud, cybercrime, and protection of critical infrastructure. Verified material for the period recorded 66 incidents, with 33 ransomware or extortion cases as the main focus and 10 unclassified incidents, a mix that leaves the risk reading at a high level because of volume, sector diversity, and the presence of cases involving exfiltration or a leak site.

The most consistent signal of the month was extortion activity by groups targeting Argentine organizations in government, education, health care, services, and retail. Confirmed listings appeared on leak sites for the Ministry of Education, the Jujuy Judicial Branch, Grupo Hospifar, Vitar Group, Diarco, and other entities, although in many cases the source did not allow a precise determination of whether encryption, exfiltration, or only a leak site mention was involved. That distinction matters, because the month’s ransomware universe was broad, but not uniform in its technical impact.

At the same time, the national government moved several pieces forward. The BCRA consolidated its fraud risk score framework for instant transfers, and the Ministry of Justice published [Resolution 483/2026](https://www.argentina.gob.ar/normativa/nacional/norma-430504/texto), which created PRONACIB for cybercrime investigation and digital evidence. Added to that was the submission to Congress of a national security bill that includes cybersecurity and critical infrastructure, a sign that the public agenda has shifted from diagnosis to institutional architecture.

Critical vulnerabilities with active exploitation also appeared, including CVE-2026-76461 in Cisco AsyncOS, CVE-2026-85706 in a commits API, and CVE-2026-59310 in VMware vCenter. The month also left a clear signal of sophistication in fraud and AI abuse, both in campaigns involving voice cloning and deepfakes and in the local case of the teenager from Quilmes, which showed the use of generative models as support for violent planning.

National snapshot for the month in Argentina

Argentina showed a high risk surface in September, with digital extortion dominating, rising regulatory pressure, and an institutional response that began to bring order to the field. The qualitative risk level is high because the material combines more than thirty ransomware incidents, AI-supported fraud campaigns, critical vulnerabilities in widely used products, and seven documented regulatory moves in the country.

The picture does not describe a single crisis, but several layers unfolding at once. On the criminal side, leak site listings and reports from specialized monitors suggest a particularly heavy second half of the month, although that concentration cannot be treated as official telemetry or an exhaustive count. On the institutional side, the BCRA, the Ministry of Justice, and the Executive Branch pushed measures on fraud, cybercrime, and national security aimed at a tougher framework for the financial system and the protection of essential services.

At the regional level, Argentina moved within a broader Latin American pattern of greater use of AI for fraud, multi-country ransomware campaigns, and regulation still expanding. That context helps explain pressure on sensitive sectors such as government, education, health care, and finance, but it does not replace local evidence. This month, Argentina’s signal was less noisy in classic fraud and more intense in extortion, critical infrastructure, and rulemaking.

Argentina, September 2026Monthly highlights in ransomware, regulation, and critical vulnerabilitiesSep 3BCRA scorefraudSep 11 Quilmesand AISep 18N0n,EducationSep 23 PRONACIBofficialSep 25JusticecybercrimeSources thismonth: BCRA,Infobae,OfficialBulletin,nationalgovernment andleak sitemonitors.
Argentina, September 2026: month highlights — Timeline of the most visible events of the period, focused on ransomware, regulation, and critical vulnerabilities.

Argentina period indicators

Indicator September 2026 Previous month Change
Verified events in the period 66 84 -18
Indicator time window 66 events dated in September 2026 · 2 with unconfirmed date (excluded from the indicators) 84 events dated in August 2026 N/A
Undetermined incidents (breaches or outages) 10 16 -6
Cases with ransomware or extortion as the primary focus 33 34 -1
Exfiltration without encryption (simple extortion) 3 N/A N/A
Leak site mention only 4 N/A N/A
Classification could not be determined from the material 26 N/A N/A
Documented fraud or phishing cases 0 2 -2
Documented regulatory moves 7 15 -8
Critical CVEs mentioned 8 10 -2
Sectors with at least one documented event 8 8 unchanged
Dominant threat of the month Ransomware (33 of 66 events) Ransomware (34 of 84 events) N/A
Events with direct source confirmation 39% N/A N/A

The indicators are based on the total number of verified events in the period, and the time window excludes the two events without a confirmed date. In ransomware, the breakdown matters because the material does not allow all cases to be standardized: only three were clearly exfiltration without encryption, four were leak site mentions only, and 26 could not be classified precisely. That makes it impossible to read the month as a uniform wave of operational encryption, although it does confirm a broad extortion surge.

Threat theme distributionVerified events for the period, base 66Ransomware 33Majority of the monthRegulation 7Secondary focusFraud 0Not documented
Argentina, September 2026: breakdown by theme — Summary distribution of the month’s leading themes based on verified events.

Relevant Incidents in Argentina

Argentina Ministry of Education, N0n claim and attributed leak

The month’s loudest case was the N0n group’s claim against Argentina’s Ministry of Education, which appeared on several leak monitors and extortion sites. Public evidence points more to an extortion claim with a leak than to a closed incident, but the source does not allow a firm assessment of the real damage or whether encryption was confirmed.

Available information mentions exposure of the full network security configuration, connection logs, and systems tied to education services, along with references to a supposed Monero miner. Since there was no public confirmation from the agency, the case should be read as a criminal group claim, not as a fully corroborated incident from the victim.

Jujuy Judiciary, Emperador attribution

The Judiciary of the Province of Jujuy was another persistent name in the leak-site ecosystem, this time attributed to the Emperador group. The available documentation refers to leaked data and exfiltration from judicial infrastructure, with mentions of administrative credentials and databases, although there is no public technical report independently describing the initial access or operational impact.

Here too, the distinction between what was claimed and what was proven matters. The material supports the conclusion that data was published or threatened with publication, but it is not enough to confirm encryption or to specify which part of the court system was affected. That leaves the case in the month’s most uncertain category.

Grupo Hospifar, Titan signal in the health sector

Grupo Hospifar S.R.L. appeared on Titan’s radar and was classified in the health sector. In this case, public evidence is also limited, and the best reading available is a posting on a leak site, with the leak status still uncertain according to some aggregators.

The analytical value of the case is not in technical confirmation, but in the sector pattern. Health was again among the month’s targets, in line with a quarter in which extortion groups continue to focus on organizations with high operational sensitivity and low tolerance for disruption.

Vitar Group, Diarco, and other leak-site mentions

Vitar Group, Diarco, Techwise, Ceres Tolvas, Librería Santa Fe, Contreras Hermanos and other Argentine organizations were mentioned by different groups in trackers and leak sites. In several cases, the available source only allows for a leak-site posting or intrusion claim, without enough information to determine encryption, exfiltration, or the real effect on operations.

That mosaic is not minor. In terms of public exposure, September left a broad sector spread, with companies in retail, technology, manufacturing, health, and services sharing the same extortion narrative. The editorial takeaway is cautious, the volume of claims was high, but independent evidence of technical impact was much lower.

Active Threats and Campaigns in Argentina

Ransomware and Extortion in Argentina

Ransomware and extortion dominated the month, with 33 incidents out of 66. The available material points to three distinct layers, but in most cases it did not go far enough to move from allegation to forensic verification. There were three episodes involving exfiltration without encryption, four that appeared only as mentions on leak sites, and 26 cases that could not be classified more precisely with the sources available.

In practice, that means the month was shaped more by public pressure from threat groups than by technical confirmation of encryption or prolonged system outages. Most entries came from leak site monitors, breach aggregators, and third-party reports, with a low level of direct confirmation by audit standards.

Fraud and Phishing in Argentina

No fraud or phishing cases were documented as formal incidents in the period’s indicators, although warnings, behavioral shifts, and analysis of AI-driven banking fraud were widespread. The BCRA warned about fake investment campaigns, while local media detailed scams involving voice cloning, fake advisors, and audiovisual manipulation.

The month’s turning point was not the emergence of a major documented phishing case, but the consolidation of a more industrialized fraud ecosystem. Coverage pointed to recurring identity impersonation tactics, deepfakes, and messages designed to create operational urgency, but that did not translate into a counted case within the formal incident indicator.

APT, Espionage, and Hacktivism in Argentina

APT and espionage activity appeared on two fronts. On one hand, ESET and other analyses reported FamousSparrow activity using a new backdoor against Argentine government entities. On the other, the SparroWocky case reinforced the view that public agencies in the region, including Argentina, remain exposed to campaigns built around persistence and abuse of legitimate services.

The material did not show a wave of hacktivism comparable in volume to ransomware. The pressure here was more technical than narrative, with the focus on backdoors, persistence, and exploitation of edge infrastructure or administrative systems.

Critical vulnerabilities affecting Argentina

The critical vulnerabilities cited this month combine active exploitation, zero-days, and flaws already added to CISA’s KEV catalog. Not all are tied to confirmed local incidents, but the material presents them as part of the risk surface that could affect Argentine organizations.

CVE Software Exploitation Source
CVE-2026-76461 Cisco AsyncOS for Email Security Appliance Active exploitation, advisory published by Cisco and added to KEV MUG Argentina
CVE-2026-85706 Commit API Unauthenticated path traversal, added to KEV MUG Argentina
CVE-2026-75650 Magento Zero-day exploited before patch, in KEV MUG Argentina
CVE-2026-59310 VMware vCenter Syslog server Active exploitation, critical severity Gustavo Sied
CVE-2026-50751 Check Point Security Gateway Vector associated through campaign analysis by N0n SecurityArsenal
CVE-2026-20316 Cisco Secure FMC Vulnerability used as part of TTPs linked to initial access SecurityArsenal
CVE-2026-48027 Nx Console Supply chain and development tooling risk SecurityArsenal
CVE-2024-1708 ConnectWise ScreenConnect Path traversal with remote code execution SecurityArsenal

The table combines vulnerabilities with different levels of connection to Argentina because that is how the source presents them. Some are confirmed by local technical sources, such as MUG Argentina and Gustavo Sied, while others appear in campaign analysis that affected organizations in the country or across the region. In September, the clearest signal was that the edge, management consoles, and internet-exposed products remain a sensitive target for extortion groups.

Regulation and compliance in Argentina

Argentina closed September with an intense wave of regulatory activity, especially in financial fraud, cybercrime, and critical infrastructure protection. Resolution 483/2026 created PRONACIB, a national program to investigate cybercrime and digital evidence, and the Executive Branch sent a national security bill to Congress that adds cybersecurity functions and public and private critical infrastructure.

Rule or decision Agency Scope Status in September 2026
Resolution 483/2026 Ministry of Justice Creates PRONACIB and sets functions on cybercrime and digital evidence Enacted on September 23, published on the 25th
National Security Bill Executive Branch and Congress Adds cybersecurity and critical infrastructure to the national security system Introduced in Congress on September 17 and began committee debate on the 30th
Communication A 8473 BCRA Fraud risk score for instant transfers In force, with staggered implementation deadlines
Provision No. 1/2026 CNC Support for National Public Sector agencies on cybersecurity Support sessions held in September
Mendoza provincial framework Provincial legislature Prevention, management, and response to cybersecurity incidents Final approval reported in the material
Majority digital bill Congress/legislative sphere Minimum age, privacy by default, and recommender limits Introduced in September

The BCRA remained the most active player in anti-fraud regulation. Through Communication A 8473, it consolidated a fraud risk score that feeds onboarding, monitoring, and review of instant transfers. The Central Bank also warned about fake investment campaigns and reinforced the idea that public information can help profile risk by person.

At the same time, PRONACIB marked a shift in criminal policy, with a focus on digital evidence, virtual assets, and artificial intelligence applied to investigations. Together, these measures point to a state that is not only seeking to tighten controls, but also to formalize capabilities for incident response and better-supported investigations.

Sectors most affected in Argentina

The sectors most exposed in September were government and defense, education, health, services, technology, and commerce, with industry and finance also appearing. The sector data is not exclusive, since one incident can affect more than one sector, but the distribution does show where pressure was concentrated during the month.

Government and education were at the center of attention because of Argentina's Ministry of Education and the Jujuy Judiciary. Health appeared through Grupo Hospifar and the regional track record that continues to attract extortion groups. Services and technology also showed up in several leak site listings, reinforcing a broad and opportunistic attack pattern.

Finance did not lead the incident count, but it was the sector with the highest density of regulation and warnings. The BCRA, digital wallets, and banks concentrated much of the anti-fraud measures and operational guidance issued during the month. Commerce and retail, with names such as Diarco and Librería Santa Fe, rounded out a sector map that left virtually no vertical with relevant digital data or operations untouched.

September closed with fewer verified incidents than the previous month, but ransomware remained persistent and documented regulatory and fraud activity dropped sharply. Compared with August, verified incidents fell from 84 to 66, unclassified incidents went from 16 to 10, ransomware or extortion cases slipped only slightly from 34 to 33, and fraud or phishing incidents stayed at zero, down from two the month before.

The lower volume does not mean structural relief. In terms of severity, September still showed pressure on sensitive sectors and, in addition, added a more defined regulatory front than August. The month's seven regulatory moves are still far fewer than the fifteen in the prior period, but they point to more concrete institutional action. The most useful reading is that the criminal ecosystem stayed active while the state refined its control and investigative tools.

The quality of confirmation also deserves attention. Only 39% of incidents had direct source confirmation, which means part of the ransomware picture should be treated as public exposure signal rather than a confirmed breach. Next month, case traceability, the release of technical evidence, and the official response from affected organizations will be the difference between a list of claims and a real map of intrusion.

Recommendations for security teams in Argentina

October’s priority should be to tighten controls where September showed the most pressure: immediate transfers, exposed edge services, admin consoles, and digital evidence workflows. The month provided enough material to show that risk is not concentrated in a single sector, but spread across government, education, healthcare, services, and finance.

First, strengthen monitoring for initial access and harden internet-facing assets. Campaigns involving critical CVEs, along with ransomware claims on leak sites, suggest reviewing VPNs, email appliances, admin panels, and any portal with weak authentication or no recent patching. The review should include privileged accounts, phishing-resistant MFA, and alerts for configuration changes.

Second, separate incident response from extortion response. If the organization is named on a leak site, it is not enough to look at the post. Teams need to preserve logs, identify remote access, freeze administrative accounts, verify exfiltration, assess exposed credentials, and coordinate legal and technical response at the same time. If the case involves personal data, the relevant compliance path also needs to be activated.

Third, review the posture against AI-driven fraud. This month’s material showed voice cloning, deepfakes, and adviser impersonation as active tactics. It is advisable to add out-of-band verification, a security phrase for sensitive processes, restrictions on changes to destination accounts, and internal training on signs of audiovisual manipulation.

Fourth, map third-party dependence in critical services. Discussions about critical infrastructure, national security systems, and digital continuity point to supply chain, hosting, cloud providers, and technology operators becoming part of the core risk. Teams should have an updated inventory, RTO and RPO by process, and a continuity plan that does not rely only on the vendor.

Frequently Asked Questions

What changed in Argentina between bank fraud and ransomware this month?

September saw much more pressure from ransomware and extortion than from formally documented fraud or phishing. Fraud showed up mainly in BCRA warnings and coverage of AI, while leak site claims and extortion drove the monthly volume. See also the Threats and Active Campaigns in Argentina and Regulation and Compliance in Argentina sections.

Which Argentine sectors were most exposed to ransomware and new regulation?

Government, education, health, services, technology, commerce, industry and finance each had at least one documented incident. Criminal pressure was most visible in government, education and health, while the heaviest regulatory activity was concentrated in finance and cybercrime. See also Most Affected Sectors in Argentina and Period Indicators in Argentina.

Which critical vulnerabilities should be linked to the month's local cases?

The most relevant were CVE-2026-76461, CVE-2026-85706, CVE-2026-75650 and CVE-2026-59310. Some appear in local technical sources, while others are tied to campaign analysis that affected Argentine or regional organizations. The right reading is to cross-reference them with the type of exposure, not assume automatic local impact. See Critical Vulnerabilities with Impact in Argentina.

Which Argentine regulatory measures carried the most operational weight?

The two most important were Resolution 483/2026, which created PRONACIB, and BCRA Communication A 8473, which established the fraud risk score for instant transfers. Added to that is the national security bill with responsibilities over cybersecurity and critical infrastructure. See Regulation and Compliance in Argentina.

What should a security team prioritize if it appears on a leak site?

Preserve logs, review remote access and privileged accounts, confirm whether exfiltration occurred, cut off compromised credentials, and coordinate technical, legal and compliance response. If the case involves ransomware, it is not advisable to negotiate without minimum forensic verification. See Recommendations for Security Teams in Argentina and Relevant Incidents in Argentina.

Material limitations

This report was built exclusively from the material provided for Argentina in September 2026. There was no internet access or additional external verification, and any facts without a confirmed date were left out. They were not included in the indicators, although they could be used as qualitative context if needed.

A zero value, especially for CVEs, means it did not appear in the material analyzed for the period, not that similar activity did not exist in the region or that exploited vulnerabilities did not occur outside this corpus. Likewise, a zero fraud or phishing indicator does not rule out attempts or incidents in the country, only that they were not documented in this month’s sources with the required classification.

The indicator time window is the one already stated above, 66 dated facts in September 2026, with 2 facts without a confirmed date excluded from the counts. Aggregated telemetry figures, blocked attempts, and vendor averages were also left out of the count because they are not incidents and should not be mixed with the period record.

The material also excluded consumer social media sources and promotional posts as primary evidence. When third-party notes, leak site monitors, or market analyses appeared, they were used only as contextual or attributed signals, never as sufficient confirmation if the material itself did not provide it. That is why several ransomware cases remain in the claim category or have undetermined classification.

Sources