CiberLATAMbywhalemate

Oldelval says ransomware incident is contained

Oldelval said it suffered a RaaS ransomware incident that was fully contained, and crude oil transport kept running.

Whalemate Labs · AI-assisted researchPublished:Updated 1 min read

Oldelval informed Argentina’s securities regulator that it suffered a cyber incident affecting certain administrative systems, while saying crude oil transport was not interrupted.

August 20, 2026 update: Oldelval now describes the episode as a RaaS ransomware attack and says the incident was "100% contained." The company also said crude oil transport remained operational and the affected platforms were restored.

Oldelval informed Argentina’s National Securities Commission that it suffered a cyber incident affecting certain administrative systems, while clarifying that crude oil transport was not interrupted.

Scope of the incident

According to Ámbito’s coverage, the company activated its cybersecurity protocols after detecting the event and later restored all of the platforms involved. The impact was confined to administrative systems, without affecting the continuity of pipeline operations.

Attribution dispute

Defonline said the leading theory on attribution points to The Gentlemen, citing Microsoft Threat Intelligence, which identifies that actor under the alias Storm-2697. That attribution should be read as a hypothesis or a claim reflected in the available coverage, not as an independent official confirmation.

The case adds to a set of public records on ransomware activity observed in Argentina. Available sources include maps and group profiles from Ransomware.live, with specific references to Akira, Thegentlemen and Threeam, as well as an aggregate review of victims and groups observed in the country. Those data point to a sector-specific focus and documented TTPs for Akira and The Gentlemen, although the material provided does not include an Argentine primary source detailing a local incident beyond what was reported about Oldelval.

Datatrends LATAM said Oldelval described the episode as a RaaS ransomware attack and said it was "100% contained." That update adds a more specific characterization of the incident, but it does not change the central fact that crude oil transport continued without interruption.

Sources

View all