CiberLATAMbywhalemate

Argentina on the ransomware map

Ransomware.live shows 160 to 177 victims linked to Argentina. Qilin also claimed an attack on the Argentine Army.

Whalemate Labs · AI-assisted researchPublished:Updated 2 min read

Qilin claimed an attack on the Argentine Army on July 24, 2026, according to Dexpose, while Ransomware.live shows 160 to 177 victims linked to Argentina on its country map. The platform lists Argentine organizations as victims without detailing the exact period or full sector breakdown.

Update, August 20, 2026: Ransomware.live now shows between 160 and 177 ransomware victims associated with Argentina on its country map. The figure updates the visible scope of activity tied to the country, but the platform still does not specify the exact time period or provide a full sector breakdown.

Argentina on the ransomware radar

Qilin claimed an attack on the Argentine Army on July 24, 2026, according to Dexpose. The threat intelligence platform also says the case marks a point of attention for Argentine military and government targets, in a context where different OSINT tools had already been showing sustained activity tied to the country.

Ransomware.live shows the same claim against the Argentine Army. In its mobile view, the group says it exfiltrated data and encrypted systems, although the page does not connect that assertion to any official statement from the Argentine government. That lack of institutional confirmation leaves a gap between the public visibility of the threat and formal validation of the victim.

What the maps show

Ransomware.live maps for Argentina show between 160 and 177 historical victims claimed by different ransomware groups. The platform itself does not specify in those views which of those victims correspond specifically to Argentine organizations, nor does it publish a complete list of names or affected sectors.

Even with that limitation, the threat intelligence ecosystem places the country in a relevant position on the regional map. Available sources link groups such as Conti, ALPHV, LockBit, BlackByte, CL0P, Qilin, Akira and The Gentlemen, among others, although the material in this report does not provide a full breakdown of the tactics, techniques and procedures associated with each one.

Which sectors have been hit

The La Sevillanita case adds to that picture. Breach House lists the Argentine company as a victim of Global Secret Group, with a leak of about 200 GB of data and a business classification in logistics and transportation.

That record adds another piece to the sector map of victims in Argentina, which in the available material appears linked to government, finance, business services, manufacturing and health, as well as transportation and supply chains. The exact scope of each campaign still depends on what each platform is able to confirm and publish, which does not always match official confirmation from the affected organizations.

Sources

View all