Argentina on the ransomware map
Ransomware.live shows 160 to 177 victims linked to Argentina. Qilin also claimed an attack on the Argentine Army.
Qilin claimed an attack on the Argentine Army on July 24, 2026, according to Dexpose, while Ransomware.live shows 160 to 177 victims linked to Argentina on its country map. The platform lists Argentine organizations as victims without detailing the exact period or full sector breakdown.
Update, August 20, 2026: Ransomware.live now shows between 160 and 177 ransomware victims associated with Argentina on its country map. The figure updates the visible scope of activity tied to the country, but the platform still does not specify the exact time period or provide a full sector breakdown.
Argentina on the ransomware radar
Qilin claimed an attack on the Argentine Army on July 24, 2026, according to Dexpose. The threat intelligence platform also says the case marks a point of attention for Argentine military and government targets, in a context where different OSINT tools had already been showing sustained activity tied to the country.
Ransomware.live shows the same claim against the Argentine Army. In its mobile view, the group says it exfiltrated data and encrypted systems, although the page does not connect that assertion to any official statement from the Argentine government. That lack of institutional confirmation leaves a gap between the public visibility of the threat and formal validation of the victim.
What the maps show
Ransomware.live maps for Argentina show between 160 and 177 historical victims claimed by different ransomware groups. The platform itself does not specify in those views which of those victims correspond specifically to Argentine organizations, nor does it publish a complete list of names or affected sectors.
Even with that limitation, the threat intelligence ecosystem places the country in a relevant position on the regional map. Available sources link groups such as Conti, ALPHV, LockBit, BlackByte, CL0P, Qilin, Akira and The Gentlemen, among others, although the material in this report does not provide a full breakdown of the tactics, techniques and procedures associated with each one.
Which sectors have been hit
The La Sevillanita case adds to that picture. Breach House lists the Argentine company as a victim of Global Secret Group, with a leak of about 200 GB of data and a business classification in logistics and transportation.
That record adds another piece to the sector map of victims in Argentina, which in the available material appears linked to government, finance, business services, manufacturing and health, as well as transportation and supply chains. The exact scope of each campaign still depends on what each platform is able to confirm and publish, which does not always match official confirmation from the affected organizations.
Sources
- Ransomware Trackerderp.ca· Derp.ca
- Latin American Governments Targeted By Ransomwarerecordedfuture.com· Recorded Future
- LATAM Financial Sector Threat Landscape 2025digiamericas.org· DigiAmericas
- Ransomware Map – Argentinaransomware.live· Ransomware.live
- Ransomware Map – Argentina (mobile view)mobile.ransomware.live· Ransomware.live
- INTERPOL Working Group highlights cyber threats across the Americasinterpol.int· INTERPOL
- Ransomware Criminals Attack Argentine Telecoms Giant, Demand Payout in Moneroredcanary.com· Red Canary
- Qilin Ransomware Group Targets Ejército Argentinodexpose.io· Dexpose
- La Sevillanita — GLOBAL SECRET GROUP Ransomware Attackbreach.house· Breach House
- Ransomware: 4.699 ataques en el primer semestre de 2026 y foco sectorialmercado.com.ar· Mercado
- Ransomware Trends & Data Insights: April 2026areteir.com· Arete Incident Response
- Ransomware Trends & Data Insights: January 2026areteir.com· Arete Incident Response
- Seguro contra Ransomware para Empresas en LATAMnextguardinsurance.com· NextGuard Insurance
- Pulse — Underground Intel (actividad de ransomware y leaks, julio 2026)pulse.kalir.io· Kalir.io
- The State Of Ransomware 2026blackfog.com· BlackFog
- La operadora del oleoducto por el que circula el 75% del petróleo de Vaca Muerta sufrió un ciberataque a sus sistemasinfobae.com· Infobae
- Threat group profile: TheGentlemenransomware.live· Ransomware.live
- Latin America sees sharp rise in ransomware, hacktivist attacks in 2025 amid expanding fraud and phishing threatsindustrialcyber.co· Industrial Cyber



