CiberLATAMbywhalemate
Intelligence reportJul 8, 202616 min read

Situación Nacional de Ciberseguridad - Junio 2026 - Argentina

Argentina closed June with 2,470 weekly attacks per organization, rising ransomware, and two local extortion cases.

Situación Nacional de Ciberseguridad - Junio 2026 - ArgentinawhalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are completed automatically with facts and verified sources from the period. They are the recurring month-to-month reading; the later analysis develops the cases without repeating this summary.

SECURITY TRIBUNE / WHALEMATE Verified Signal Monthly Dashboard June 2026 · Argentina VERIFIED FACTS 89 74 confirmed RECORDED ATTACKS 27 incidents, breaches, or leaks RANSOMWARE/EXTORTION 16 tracked criminal signal CVEs MENTIONED 9 CVE-2026-20253 / CVE-2026-20262 VERIFIED SOURCES 44 deduplicated URLs SIGNAL AREAS 5 0 ST obs.
Verified Signal Monthly Dashboard — Fixed period summary for Argentina.
MONTHLY FIXED MODULE Distribution by threat axis June 2026 · Argentina Vulnerabilities 38 Incidents 27 Ransomware 16 Fraud 2 Regulation 2
Distribution by threat axis — Heuristic classification of verified facts by threat type.
MONTHLY FIXED MODULE Sector breakdown of signal June 2026 · Argentina Technology 38 Public sector / OIV 29 Telecom 7 Education 4 Healthcare 3 Finance 2 Energy 2 Retail / consumer 2
Sector breakdown of signal — Heuristic classification of verified facts by affected or mentioned sector.
FIXED MONTHLY MODULE Critical Infrastructure in Argentina Verified signal on public agencies, utilities, and critical sectors Public sector / government 29 Energy / utilities 1 Telecom / connectivity 6 Classified incidents 7
Critical Infrastructure in Argentina — Verified signal on public agencies, utilities, and critical sectors

June cyber risk report for Argentina

June brought two clear signals for Argentina. On one side, the country logged an average of 2,470 weekly cyberattacks per organization, according to Check Point Research cited by local media, up 9% year over year. On the other, ransomware kept up steady pressure and, in Argentina’s case, grew 48% year over year, with education and government among the hardest hit sectors. The month’s picture was concrete, with named victims, visible targets and extortion campaigns that had local impact.

Extortion was the loudest front. LockBit 5.0 claimed an attack on Sanatorio Delta, a private healthcare institution, and threatened to leak sensitive patient data. At the end of the month, Incransom added GDN AR, the chain that operates the gdnargentina.com domain, to its leak site and demanded negotiations under threat of publishing allegedly stolen information. Both cases place Argentina within the usual operating range of the most active ransomware groups and reinforce healthcare and retail as high-pressure targets.

The month was also shaped by major patching announcements from leading vendors. Microsoft released fixes in June for around 200 vulnerabilities, with between 33 and nearly 40 classified as critical depending on the source, and at least six zero-days in different reports. Android, meanwhile, issued a bulletin covering 124 vulnerabilities, including at least one zero-day under active exploitation. For Argentine environments with hybrid estates, Windows workstations, Android mobile devices and exposed services, the volume of flaws patched in June raised the cost of delayed patch management.

Regulation also shifted the baseline. Disposition 1/2026 from the National Cybersecurity Center, released in May and analyzed in June, requires the National Public Sector to have contingency and operational continuity plans, alternate data processing centers, defined RTO and RPO values, and periodic recovery tests. This is not a cosmetic measure. It creates a concrete technical obligation around resilience and continuity for public agencies, with a preparedness standard closer to an operational audit framework than to a simple documentary recommendation.

At the same time, the Gov.eth case closed a chapter already linked to leaks, unauthorized access and attacks on government agencies and media outlets in Argentina and other countries. The arrest in Madrid of Matheo Enzo Torres Palacios, sought by Argentine courts, confirms the transnational scope of some of these cases and leaves an uncomfortable fact for the country, namely millions of records and sensitive data that may have been exposed at different points in the investigation. June was, in short, a month of simultaneous exposure in scale, extortion and regulatory maturation.

June 2026, ArgentinaOrder CNC3 JunAndroid 124 CVE1 JunMicrosoft 200failures9 JunGov.eth Arrest25 JunIncransom GDN AR29 JunSanatoriumDelta18 Jun
June 2026 in Argentina: key monthly milestones — Condensed timeline of verified regulation, vulnerabilities, and local incidents during the period.

Threats and incidents in Argentina

Sanatorio Delta and LockBit 5.0's claim

On June 18, LockBit 5.0 named Sanatorio Delta as a victim on its leak site. The company, a private health care institution in Argentina, was tied to a ransomware campaign in the group’s classic format, extortion, a threat to publish data, and pressure to force payment. The technical report cited by Dexpose adds that the group warned of a possible leak of sensitive patient data if the organization did not meet its demands.

This should not be read as just another incident in a long list of leak site claims. In health care, response time is critical, and loss of availability often has a direct operational impact. An attack like this can affect appointments, medical records, lab systems, admissions, billing, and internal communications. The public threat to expose medical data also adds a second layer of harm, reputational damage, which in health care has long-term commercial and regulatory effects.

For Argentina, the case comes amid broad pressure on the sector. The 48% year-over-year ransomware figure, and the specific mention of education and government as the hardest-hit sectors, do not exclude health care, which has historically ranked among the highest-value targets from an operational standpoint. Sanatorio Delta’s appearance on a leak site reinforces that Argentina is not seeing only ecosystem noise, but active campaigns with concrete local victims.

GDN AR, Dorinka, and Incransom's extortion attempt

On June 29, Incransom posted a notice on its leak site targeting GDN AR, also identified as Dorinka, the Argentina-based supermarket chain that operates the gdnargentina.com domain. The group said it had carried out a cyberattack and threatened to leak sensitive data it allegedly stole if the company did not begin negotiations.

The difference between this case and the health care one is the sector, but the logic is the same. Retail concentrates personal data, transaction information, access credentials for internal platforms, and, in many cases, sensitive logistics dependencies. Public extortion with a leak threat can affect both operational continuity and the relationship with consumers and suppliers. In distributed chains, the impact also tends to spread across store environments, warehouses, and third-party systems.

Incransom’s claim lines up with signals in threat intelligence channels and on social networks mentioning the chain as a possible victim in Argentina. Although the available material does not support going beyond the group’s public claim, it does point to a clear trend, Argentine retail remained in the crosshairs of extortion campaigns run by groups specialized in monetizing data and reputational pressure.

Gov.eth, the Madrid arrest, and the transnational dimension of the case

June also ended with the arrest in Madrid of Matheo Enzo Torres Palacios, identified by Argentine authorities as Gov.eth. The investigation was led by Argentina’s federal judiciary and the Argentine Federal Police, with support from Spain’s National Police. Local coverage links him to attacks carried out between 2024 and 2026 against government agencies, private companies, and media outlets in Argentina, Uruguay, Mexico, Spain, and the United States.

The case matters for two reasons. First, it pushes aside the idea of an isolated attacker and shows an operation with regional reach and varied targets. Second, several reports say the group or the actors linked to Gov.eth may have obtained access to data on millions of people in Argentina. Even when presented in news coverage and social media posts, that figure underscores the potential scale of the accumulated damage.

The investigation also ties into the debate over the exposure of Argentine public agencies, including RENAPER and DNRPA, as well as media organizations and private entities. In June, alerts were already circulating about a possible RENAPER data leak and about a possible sale of bank databases from a local institution. The arrest in Madrid does not erase that history, but it does confirm that some cases do not end with a post or a database dumped in a forum, they can move into international police cooperation.

RENAPER under public alert and the problem of data exposure

On June 3, VECERT Analyzer issued a public alert about a suspected hacker who was allegedly offering an API with access to personal data of Argentine citizens stored in RENAPER. The alert itself, according to Criptonoticias, described the case as unconfirmed, although it said there was visible evidence of attacker activity.

That mix of caution and visible evidence is typical of episodes in which the available information still does not allow the full scope to be verified, but still demands a response. The material attributes the suspected actor’s commercial activity to an offering of access to millions of personal and private records, with data on families, addresses, phone numbers, and identity. It is not possible to say more than what has been verified, but it is clear that interest in Argentina’s identity registry remains strong among threat actors looking to monetize high-value data.

The relevance of the case is not only its possible source, but what it reveals about the resale of identities, access credentials, and databases in underground markets. In a country with heavy use of document verification, digital banking, remote services, and online government platforms, any exposure of this kind multiplies the risk of later fraud, account takeover, and social engineering campaigns.

Not Chile, the 2026 World Cup, and the fraud surface already emerging in Argentina

An analysis released in June on cybersecurity tied to the FIFA World Cup 2026 said that in markets such as Argentina, Uruguay, and Paraguay, the most common attacks during these events include cloned pages selling fake tickets, illegal streaming that spreads malware, malicious apps, phishing, and online betting fraud.

There was no confirmed local incident in the material for Argentina tied to the tournament, but there was a useful operational warning. Major sporting events are often used as cover by opportunistic campaigns that mix urgency, branding, and scarcity to trick users. In Argentina, where digital payment services and online ticket buying are already well established, security and fraud teams should treat these patterns as predictable threats rather than seasonal surprises.

Monthly sequenceAccess or alertExfiltrationLeak siteNegotiationRENAPERData, identitiesLockBit, IncransomPublic threat
From alert to extortion in Argentina — Operational sequence observed in June, from data exposure to public pressure.

Ransomware and extortion in Argentina

The clearest data point this month underscores the continued pressure on Argentine organizations. According to Check Point Research, cited by ITSitio and 100seguro.com.ar, the country averaged 2,470 weekly cyberattacks per organization in 2026, up 9% year over year. Ransomware rose 48% year over year in the same period and reached its highest expansion level recorded in 2026 in May. Education and government were among the hardest hit sectors, and coverage also points to telecommunications.

That statistical picture matches what happened in June at the case level. LockBit 5.0 targeted a health institution. Incransom went after a supermarket chain. Added to that is the Ransomware.live map, which by mid-June counted 158 victims associated with Argentina. This is not an official count of national incidents, but it is a useful gauge of the public visibility of Argentine victims within the global extortion ecosystem.

The pattern has two parts. First, constant pressure on organizations with exposed attack surfaces, reused credentials, or insufficient segmentation. Second, the monetization of data leaks as a coercion tool. Groups no longer rely only on encryption. The threat of publication has become the main negotiation mechanism and, in many cases, the vector that gives the incident more visibility than the system hijacking itself.

Against that backdrop, Argentina's position as one of the Latin American countries with the highest average weekly attack rate per organization, behind Colombia, Brazil and Mexico, fits a digital economy with relatively high exposure. That does not mean the country leads in offensive maturity or total damage, but it does mean it sits squarely in the zone where the frequency of attempts and campaigns requires continuous defense, not episodic response.

The affected sectors also help explain the priorities. Education usually has low tolerance for disruption, limited resources and heavy reliance on shared systems. Government manages large volumes of data and services that must stay available. Health care, although it does not appear in the sector statistics cited as one of the hardest hit, showed a concrete vulnerability in June with Sanatorio Delta. Retail and supermarkets are attractive as well because they combine customer volume, payments, loyalty programs, logistics and personal data.

The technical debate over ransomware in Argentina cannot be reduced to victim counts. The most active groups are aligned with RaaS models, which lower entry barriers and speed up opportunistic campaigns. At the same time, the extortion space has become more aggressive. When an Argentine organization appears on a group's site, the reputational damage can arrive even before the full scope of the incident is confirmed. That asymmetry requires legal, communications and continuity playbooks to be ready, not just forensic containment.

Period indicators2,47015820012448%Weekly attacksAR victimsMicrosoftAndroidRansomware
Quantified signals for June 2026 in Argentina — Comparison of verifiable indicators for the period, with a focus on attack frequency and ransomware victims.

Critical vulnerabilities with impact in Argentina

June was dominated by pressure to patch at scale across major ecosystems. Although not all flaws directly affected Argentine assets, their operational impact on local companies and agencies is clear because of the widespread use of Windows, Android, Cisco SD-WAN, and collaboration and email products. The issue is not just the volume, but the mix of severity, likely exploitation, and available zero-days.

CVE Software Exploitation Source
CVE-2026-49160 Windows, HTTP/2, denial of service Listed among the most likely to be exploited; described as a DoS via HTTP/2 Bomb technique Infosertecla, Infosertecla
CVE-2026-50507 Windows BitLocker Listed among the most likely to be exploited; risk with physical access to the system Infosertecla
CVE-2026-45586 Windows Collaborative Translation Framework Listed among the most likely to be exploited; elevation of privileges to System Infosertecla
CVE-2026-20262 Cisco Catalyst SD-WAN vManage Arbitrary file write, exploitable by an authenticated user, with compromise indicator searches Cisco
CVE-2026-20253 Splunk Enterprise Critical unauthenticated remote code execution Cronup
CVE-2026-47291 Windows HTTP.sys Remote code execution, CVSS 9.8, fast patching recommended Splashtop
CVE-2026-48567 Azure HorizonDB Privilege escalation, CVSS 10.0, highlighted as the highest in June Splashtop
CVE-2026-41089 Windows Netlogon Described in a distribution piece as a critical flaw actively exploited Instagram

Microsoft's June patch cycle is the largest in the material. Donweb.news and Infosertecla report 200 vulnerabilities fixed, while other coverage puts the total at 198, 206, and 604 when including Microsoft-owned and third-party issues. The difference in counts reflects different methodologies, but it does not change the main signal, June was a month of mass updating and urgent prioritization for administrators.

Microsoft also fixed six zero-days, with at least one actively exploited before patching according to Donweb.news, and the highlighted flaws include Windows BitLocker, Collaborative Translation Framework, and Windows HTTP/2. The operational takeaway is clear, environments that did not apply the June cycle were exposed to a mix of privilege escalation, access to encrypted data, denial of service, and remote code execution.

Android added a second layer of exposure. The June bulletin fixed 124 vulnerabilities and, according to the material, included at least one zero-day under active exploitation. For corporate mobile fleets, managed device estates, and BYOD, this means Android patch hygiene can no longer sit outside the same prioritization loop as Windows or network appliances.

Cisco, for its part, issued a specific advisory on Catalyst SD-WAN, with CVE-2026-20262 as the key issue. The vulnerability in vManage, which can allow arbitrary file writes by an authenticated user, requires checking exposure, access, and possible compromise indicators. The advisory matters for two reasons, first because it involves critical network infrastructure, and second because the vendor itself included search and remediation steps, which suggests a particularly high level of attention.

Exposure hot spotsHealthGovernmentRetailIdentityPatchingContinuitySanatorio DeltaCNC 1/2026GDN ARRENAPERMicrosoft and AndroidRTO, RPO
Most visible risk surface in Argentina — Qualitative map of hot spots that dominated the month according to consolidated sources.

Regulation and compliance in Argentina

Disposición 1/2026 from the National Cybersecurity Center is the most significant regulatory move this month for the National Public Sector. According to analysis by VCISO Latam and reporting by Segu-Info, the rule requires contingency and operational continuity plans, alternate data processing centers, defined RTO and RPO targets, and periodic disaster recovery testing. Segu-Info also describes it as the first CNC rule aimed at imposing technical requirements for cyber continuity and resilience.

The broader takeaway is that the CNC is no longer just a point of reference. It is emerging as a technical regulator with the ability to set mandatory guidelines for the National Public Administration on continuity and information security. For government teams, that means reviewing not only whether plans exist, but whether they are tested, documented, and aligned with realistic recovery times.

From a compliance standpoint, the requirement for alternate CPDs and explicit RTO and RPO targets raises the evidentiary bar. A contingency document on its own is no longer enough. Organizations now have to show how long it would take to get back online, which processes they would prioritize, which services would come up first, and how they would verify the integrity of recovered data. The gap between having a backup and being able to restore it has become a regulatory issue, not just a technical one.

The material also points to a notable institutional signal. The CNC appeared in public outreach tied to June congresses and conferences, suggesting an agency with a growing presence in the local ecosystem. The sources do not provide enough detail to say more about its structure, powers, or future scope, but they do support the conclusion that in June it began to establish itself as a visible rule-setting actor in public resilience discussions.

Financial sector and digital fraud in Argentina

There is enough material to include the financial system in this month’s review, but not enough to build a full picture of confirmed incidents. The possible sale of BBVA Argentina banking databases, reported by El Estratégico and attributed to a threat that has not yet been fully verified, is the main exposure point in the segment. The report itself says BBVA Argentina’s core servers were placed under investigation and preventive audit after the cyberthreat.

The most sensitive element in the report is the volume attributed to the database in question, around 750,000 premium cardholders, although that figure is presented as the threat actor’s claim and cannot be taken as confirmed. What can be verified is that there was a public alert, the case prompted a preventive audit, and criminal interest in Argentine banking data remains active.

The RENAPER incident adds another layer, because the overlap between identity and finance is one of the most dangerous. When an identity database is combined with a banking database or reused credentials, the resulting fraud often escalates to identity theft, account opening, fund diversion, or the activation of unsolicited credit lines. In that sense, June did not show a systemic financial crisis, but it did reveal a chain of signals affecting the authentication foundations of the system.

The 2026 World Cup case should also be read from this angle. Fake ticket campaigns, fraudulent betting and malicious streaming are not only designed to trick end users, they also serve to steal payment credentials, cards and platform accounts. For banks, fintechs and acquirers, the period leading up to major events usually increases transactional fraud noise and brand phishing.

Regional outlook: Argentina in LATAM context

Argentina ended June among the Latin American countries with the highest average weekly cyberattacks per organization, behind Colombia, Brazil and Mexico according to ITSitio. The figure does not need embellishment. It does show that the country is facing an attack frequency comparable to the region’s largest digital economies, and that the pressure comes not only from local campaigns but also from a regional pattern of high criminal activity.

Ransomware data also puts Argentina in a sensitive position within LATAM. The 48% year-over-year increase, the mention of critical sectors and the presence of 158 victims on the Ransomware.live map suggest visible, sustained exposure. The regional comparison should not be used for comfort, but as a sign that the country shares the same extortion vectors as its more exposed neighbors.

June also brought a relevant data point on cooperation and cross-border reach. The arrest of Gov.eth in Madrid, in a case with ramifications in several countries, shows that some investigations are already operating on a regional and European scale. For Argentina, that means the response does not stop at its own borders. Investigation, digital evidence and coordination with foreign counterparts are part of the same defense.

Period indicators

Indicator Value Scope Source
Weekly cyberattacks per organization 2,470 Argentina, 2026 ITSitio, 100seguro
Year-over-year change in cyberattacks 9% Argentina ITSitio, 100seguro
Year-over-year ransomware growth 48% Argentina ITSitio, 100seguro
Victims linked to Argentina on Ransomware.live 158 Map consulted in mid-June Ransomware.live
Vulnerabilities patched by Microsoft in June about 200 Microsoft ecosystem Donweb.news, Infosertecla
Critical vulnerabilities in Microsoft’s cycle 33 to nearly 40 Microsoft ecosystem Donweb.news, Infosertecla
Zero-days patched by Microsoft 6 Microsoft ecosystem Donweb.news
Vulnerabilities patched in Android 124 Android Infobae, AOSP
Complaint date against Sanatorio Delta 18/06/2026 Argentina Dexpose
Complaint date against GDN AR 29/06/2026 Argentina Dexpose
Gov.eth arrest date June 2026 Madrid, Argentine case Perfil, La Opinión Austral

Reading for security teams in Argentina

June left one immediate priority, patch management. Microsoft, Android, and Cisco delivered enough fixes in June to overwhelm teams working within limited maintenance windows. The practical takeaway is not to patch everything at once, but to have a serious prioritization mechanism based on likely exploitation, external exposure, asset criticality, and operational dependency. Without that mechanism, June showed how risk can pile up in just days.

The second issue is continuity. Disposición 1/2026 of the CNC moves the resilience discussion into measurable territory. For the public sector, and by extension for providers and other critical third parties, the question is no longer whether a plan exists, but how long it actually takes to restore service, where the alternate data center is, and what is tested on a regular basis. Continuity has to be validated with drills, not folders.

The third front is extortion prevention. Sanatorio Delta and GDN AR show that the impact of ransomware in Argentina is not limited to encryption. Public victim disclosures and the threat of data leaks are central to the criminal business model. That requires specific playbooks for communications, evidence preservation, coordination with insurers, lawyers, and the crisis room. It also means monitoring leak sites and threat intelligence channels with rapid response criteria.

The fourth point is identity and master data protection. RENAPER, alerts about banking databases, and the Gov.eth case point to data reuse as a source of secondary fraud. The initial attack may not end in a visible outage, but it can trigger a chain of impersonation, account openings, document fraud, or highly credible social engineering campaigns. Fraud, IAM, SOC, and legal teams should be working from the same dashboard.

The fifth is sector-specific pressure. Healthcare, government, education, retail, and financial services face different levels of pressure, but share the same common denominator, data exposure, availability dependency, and low tolerance for error. In that mix, asset inventory, privilege segregation, strong MFA, and monitoring for anomalous access stop being generic best practices and become survival controls.

Material limitations

There were no verifiable internal observations accumulated for the period, so this report is built entirely on in-depth research and consolidated external sources. That supports the figures, dates, campaigns and regulatory decisions cited in June, but it does not allow for a national incident rate or a forensic count of actual events that occurred in the country.

Several items from the month come from press reports, social media posts or third-party alerts that, in some cases, include unconfirmed statuses or threat actor claims. When that happens, the report distinguishes between confirmed fact, public alert and attribution made by the source itself. In particular, the RENAPER, BBVA Argentina and some references to Gov.eth actions include elements that cannot be elevated to full operational certainty with the available material.

It was also not possible to build a robust financial sector section with fully confirmed incidents, beyond the alert about a possible sale of banking data and the overlap with identity exposure. Likewise, the material does not provide a complete view of Argentina's private sector beyond the cases in health, retail and public administration. The absence of internal local observations makes it impossible to measure real severity by industry or compare June with previous months within the country.

Even with those limitations, the month shows a clear pattern, Argentina dealt with a high frequency of attacks, ransomware growth, public extortion claims, pressure on credentials and identities, and a new layer of regulatory demands on operational continuity in the state. June's picture does not depend on a single incident, but on the overlap of all of them.

Sources