Mining, Metals, and Natural Resources, Aug 2026
Ransomware led August in Latin American hydrocarbons and mining, with Oldelval and Ecopetrol as key cases and no critical CVEs reported.
Key findings
- Ransomware was the dominant threat in the month, with 26 of 60 verified incidents, displacing the vague classification that dominated July.
- Oldelval and Ecopetrol concentrated the vertical's most sensitive signal, one tied to continuity of oil transport and the other to cloud exfiltration and encryption blocking.
- Most ransomware cases did not allow precise determination of whether encryption occurred, only a leak site or exfiltration, which makes taxonomy separation necessary.
- Regulatory disclosure gained weight: Oldelval reported to the CNV, and Ecopetrol documented its incident to the SEC and Colombian authorities.
- No critical CVEs were recorded in the analyzed material, so the month's risk was explained more by identity, cloud, and extortion than by published flaws.
- Argentina and Colombia were the countries with the highest density of relevant events for the sector, while Brazil contributed pressure telemetry and Venezuela the aftermath of prior incidents.
- Operational continuity held in the most visible cases, but data exposure, disputed attribution, and extortion pressure consolidated a high-risk period.
Monthly reference modules
These modules are completed automatically with the verified dated facts within the period. Each one states its basis and counting criteria so the figures reconcile across modules. They are the recurring month-by-month reading, and the analysis that follows develops the cases without repeating this summary.
Indicator window: 64 dated facts in August 2026 · 7 from prior months (comparative frame, not month volume) · 1 without confirmed date (excluded from the indicators). Facts from prior months are used only as a comparative frame in the analysis, never as volume for this period.
Executive summary for the month
August 2026 sent a clear signal across mining, metallurgy, and natural resources in Latin America, ransomware again dominated attention, with 26 of 60 verified incidents in the period. In Argentina, Oldelval and in Colombia, Ecopetrol framed the region's monthly picture. Direct operational impact remained limited in several cases, but data exposure, extortion pressure, and the need to disclose incidents to regulators carried more weight.
The month's picture does not point to a single systemic crisis, but to a pattern of intrusion with different effects depending on the asset and the response capacity. Oldelval reported an attack on administrative systems that did not interrupt crude transport and was filed as a material event with the CNV. Ecopetrol, by contrast, acknowledged unauthorized access to cloud environments, the download of data tied to thousands of accounts, and an attempted encryption that internal controls blocked. In both cases, the public narrative was shaped by unconfirmed attributions, leak sites, and regulatory disclosures.
Ransomware was the leading threat, but the month's material requires a careful distinction between its variants. There were 3 cases with confirmed asset encryption, 6 where only the victim appeared on a leak site, and 17 in which the type could not be determined from the available information. That ambiguity is not minor. In oil and gas and natural resource assets, the same group can alternate between extortion, exfiltration, and public exposure of victims without the operational damage being visible right away.
The Oldelval case deserves separate treatment because it combines critical infrastructure, disclosure to the capital markets, and open attribution to The Gentlemen under a RaaS model. The company said the attack was limited to administrative systems and that the transport chain kept operating. Different reports added that the strongest theory pointed to foreign attackers and that systems were restored, but authorship remained unconfirmed independently. That combination of a real attack, contained impact, and disputed attribution is representative of the month.
Ecopetrol showed a different angle, closer to data extortion than industrial disruption. The Colombian oil company said it detected an unauthorized download linked to about 3,300 user accounts and to cloud-stored data from around 15 group companies. It also said it managed to block the encryption phase and revoke access. Coverage linked the episode to The Gentlemen, although the company did not publicly validate the actor. In risk terms, August made clear that the corporate perimeter and cloud environments remain effective footholds for ransomware operators targeting the energy sector.
Regional outlook for the month
August’s regional signal was high, not because of the sheer volume of scandals, but because of the mix of sensitive sectors, extortion pressure, and two benchmark cases in hydrocarbons. At least five sectors posted documented incidents across the region, with oil, energy, and natural resources at the center, plus secondary signs of fraud, phishing, illicit cryptocurrency mining, and regulation. The month’s qualitative risk is high because some incidents were more severe than average, even though there was no broad operational collapse.
Latin America continued to present a very broad attack surface, but the period’s material focuses attention on three countries. Argentina contributed the Oldelval case, one of the most sensitive because of the infrastructure involved and the disclosure to the CNV. Colombia added the Ecopetrol incident and the later reference to a ministry hit by ransomware, which helps frame the regional environment, even though it is not part of the mining and energy core. Chile and Peru appeared in the press because copper supply disruptions were tied to weather and accidents, not cyber incidents, which serves as operational context for the sector, not as attack volume.
The sector-by-sector view matters because the month was not limited to one type of asset. There was oil transport infrastructure, energy groups with corporate cloud environments, illicit cryptocurrency mining as background telemetry in Brazil, and a methodological reference in mining cybersecurity centered on RBVM. At the same time, SLB’s contract with PDVSA, driven by years of neglect and a previous cyberattack, again showed that the aftermath of older incidents continues to shape commercial and operational decisions in the regional extractive industry.
The absence of critical CVEs in the material analyzed should not be read as technical calm. It only means that no critical vulnerabilities were mentioned in the coverage collected for this axis and this month. August’s risk came more from credentials, remote access, cloud, permission abuse, and extortion campaigns than from the public exploitation of specific flaws. For industrial defense teams, that shifts the focus. Identity hardening, segmentation, and exfiltration monitoring matter more than chasing a list of CVEs that was not present in the material.
Period indicators
The table below reproduces the indicators calculated for August 2026 on mining, metallurgy, and natural resources in Latin America, with their exact basis and the comparison against the previous month provided by the prior report.
| Indicator | August 2026 | Previous month | Change |
|---|---|---|---|
| Verified facts in the period | 60 | 57 | +3 |
| Time window for the indicators | 64 facts dated August 2026 · 7 from prior months (comparative frame, not month volume) · 1 with unconfirmed date (excluded from the indicators) | Same | N/A |
| Unclassified incidents (breaches or outages) | 26 | 8 | +18 |
| Cases with ransomware or extortion as the primary focus | 26 | 7 | +19 |
| Ransomware breakdown, confirmed asset encryption | 3 | No comparable data | N/A |
| Ransomware breakdown, mention on leak site only | 6 | No comparable data | N/A |
| Ransomware breakdown, classification not determinable from the material | 17 | No comparable data | N/A |
| Documented fraud or phishing cases | 1 | 4 | -3 |
| Documented regulatory developments | 1 | 0 | +1 |
| Critical CVEs mentioned | 0 | No comparable data | N/A |
| Sectors with at least one documented fact | 5 | 6 | -1 |
| Dominant threat of the month | Ransomware (26 of 60 facts) | Unclassified (23 of 57 facts) | Shift in focus |
| Facts with direct source confirmation | 68% | No comparable data | N/A |
| Aggregate telemetry figures excluded from volume | 4 (aggregate attempts or blocks, not incidents with confirmed impact) | No comparable data | N/A |
The calculation base excludes the 4 telemetry figures and the fact with an unconfirmed date. It also does not include the 7 facts from prior months, which are used only as a comparative frame. The clearest shift in the month was the expansion of ransomware and unclassified incidents, along with a relative decline in phishing and a single regulatory move, concentrated in the Oldelval case.
Relevant Incidents
This section brings together the cases with the highest analytical value for mining, metallurgy, and natural resources, especially those that affected energy infrastructure, crude transport, enterprise cloud environments, and regulatory communications. What they had in common was public visibility, not the operational scale of each incident.
Oldelval, attack on administrative systems and disclosure to the CNV
Oldelval was the most visible case of the month in Argentina and one of the most sensitive for the natural resources sector. The company told the CNV that it had suffered a cyberattack or information security incident that affected administrative systems. It said the episode was contained and that crude transport was not interrupted. Public debate focused both on the company’s role and on the regulatory framing of the disclosure.
Coverage agreed that the impact was limited to the administrative layer. MásEnergía, Diario Neuquino, The Rio Times, Infobae, and Defonline all said transport operations stayed active and the affected systems were restored. At the same time, People of Internet pointed out that the duty to report came from the capital markets regime, not from a specific sectoral cybersecurity law. That makes the case an example of governance, not just technical response.
Attribution was less stable than the incident itself. The Gentlemen claimed responsibility in public channels, and several reports treated it as RaaS, but the company did not confirm authorship or the intrusion vector. One aggregator blog went so far as to attribute the incident to incransom, which adds noise to attribution rather than certainty. Nivel4 added a useful technical angle by identifying The Gentlemen as a RaaS actor tracked by Microsoft Threat Intelligence under Storm-2697.
Operationally, the case points to a contained intrusion, with impact limited to the administrative layer and no compromise of the pipeline’s physical continuity. That does not make it minor. In critical infrastructure, disruption that is prevented also has intelligence value, because it shows that controls, segmentation, and recovery procedures worked. The counterweight is that public exposure, leak site pressure, and the need for regulatory transparency are now part of the incident’s cost.
Ecopetrol, cloud exfiltration and blocked encryption
Ecopetrol delivered the other major case of the month and, unlike Oldelval, the focus was on unauthorized access, exfiltration, and an attempted encryption that the company said it blocked. The oil company said the incident involved data hosted in the cloud for around 15 companies in the group, about 3,300 user accounts, and the revocation of compromised access. It also said oil production was not interrupted.
The company went further in its response than many regional actors and detailed specific measures before Colombia’s Attorney General’s Office. DataEnforce said the company blocked the encryption stage, while ITSitio Colombia explained that the filing with the SEC referred to unauthorized access to cloud storage environments. Taken together, the reporting suggests a campaign with an exfiltration and extortion component, but no visible operational impact on production.
Coverage also recorded a claim by The Gentlemen about the supposed extraction of 327,095 files and around one terabyte of data, a figure Ecopetrol did not confirm. That point matters: the public narrative split between the company’s confirmation of unauthorized downloading and the actor’s self-reported volume of stolen data. In this kind of incident, the attacker group’s number usually has pressure value, not evidentiary value.
For the sector, the case leaves three lessons. First, the corporate cloud of conglomerates with multiple subsidiaries can become the most exposed entry or extraction path. Second, revoking access and blocking encryption remain relevant defenses once intrusion has already occurred. Third, legal and regulatory response becomes part of the incident. Production was not interrupted, but the data exposure surface and potential financial impact remain open.
Colombia’s Ministry of Justice, ransomware and service continuity
Although it is outside the mining and energy axis, the Colombian Ministry of Justice case serves as contextual signal for the month. On August 3, the ministry confirmed a ransomware attack that compromised part of its infrastructure and affected the availability of several services. Coverage linked the event to a security problem that emerged days earlier at an oil company, reinforcing the idea of impact chains among contractors, public agencies, and critical operators.
The analytical relevance is not the sector, but the pattern. An administrative environment compromised in an organization tied to the energy ecosystem ends up creating additional pressure on public services. For natural resources operators, cases like this underscore that the supplier and contractor chain cannot be treated as a theoretical boundary. A poorly managed contract can end in an incident with broader reach than expected.
SLB and PDVSA, access to oil data after a prior cyberattack
At the end of August, Reuters and other outlets reported that SLB obtained access to Venezuelan oil data through a contract with PDVSA, in the context of years of neglect and a recent cyberattack on those systems. The report did not describe a new incident, but it showed how earlier attacks continue to shape database reorganization and the handling of sensitive information in the sector.
In regional terms, the case is a reminder that the consequences of a cyberattack do not end when the press releases stop. The need to modernize databases, clean up inventories, and rebuild access often emerges months later, with significant operational and geopolitical weight. In this case, there is no evidence of a new compromise, but there is evidence of an environment still carrying security aftereffects.
Threats and Active Campaigns
Offensive activity this month centered on ransomware and extortion, with only one reference to fraud or phishing and not enough material to support an APT narrative in the mining and energy space. The impact varied more than the actor’s name.
Ransomware and extortion
Ransomware was the dominant threat of the period, accounting for 26 of 60 verified incidents. Within that set, only 3 cases showed confirmed asset encryption, 6 were limited to a mention on a leak site, and 17 did not allow a precise determination of whether there was encryption, only exfiltration, or a claim with no visible impact. That breakdown matters because it keeps all ransomware from being read as the same phenomenon.
Oldelval fell into the group of cases with contained impact and a public ransomware classification, although the company did not confirm attribution. Ecopetrol, by contrast, is the clearest case of extortion with blocked encryption attempts. Also included is the incident attributed to a French multinational in Chile, reported by BioBioChile as a ransomware campaign with possible exfiltration and payment pressure, although the source does not allow attribution or technical scope to be closed out. In every case, public pressure on the victim was part of the attack.
The month also left a relevant undercurrent for the extractive sector. The Gentlemen, a group described as RaaS in several reports and technical analyses, appeared linked to hydrocarbon victims in Argentina and Colombia. That overlap does not prove a campaign focused exclusively on the vertical, but it does show an affinity for assets where operational continuity, corporate reputation, and regulatory compliance all matter at once.
Exfiltration without encryption deserves separate treatment because it is the attack mode that most closely resembles silent theft. In Ecopetrol, the value of the incident lay as much in the unauthorized download as in the failed encryption attempt. In Oldelval, the public pressure came from a group’s claim, but the company said there was no interruption to transport. In both cases, identity control and rapid system restoration mattered more than malware detection itself.
Fraud and phishing
Only one incident from the month was documented under fraud or phishing. The available source says phishing remains effective in Latin America and that, in manufacturing, a high share of companies reported attacks, but that material is perception telemetry, not an incident from the mining and energy axis. For that reason, it should be read as context, not evidence of a specific campaign against mining or natural resources.
The relevance for the vertical is indirect but real. Natural resource operators depend on email, engineering, maintenance, and contractor chains where phishing still works as an entry point. August did not show an emblematic case of this kind in the axis, but the regional data suggests identity hygiene remains a pressure point for sector companies.
APT and Persistent Intrusion
There was not enough material to sustain an APT campaign identified as such in the vertical during August. What did appear was operational persistence in the form of intrusions with disputed attribution, such as Oldelval and Ecopetrol, and a reference to foreign origin in the Argentine case. That persistence is not the same as a classic APT, but it does point to an environment in which the attacker tries to maintain access, exfiltrate data, or monetize with low friction.
Critical Vulnerabilities
No critical CVEs were recorded in the material analyzed for August 2026. That does not mean there were no critical vulnerabilities exploited in the region, only that none appeared in the sources collected for this report. As a result, the table remains empty, and technical analysis should focus on compromised access, credential abuse, and cloud exposure, not on a list of published flaws.
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| No critical CVEs were recorded in the material analyzed | N/A | N/A | N/A |
Regulation and compliance
August brought a clear regulatory shift and a compliance precedent that matters more for how it was handled than for the amount involved. Oldelval reported the incident as a material event to the CNV, and People of Internet underscored that the transparency obligation came from the securities regime, not from any specific cybersecurity rule for critical infrastructure. That distinction matters because it defines who must report and under what framework.
The CNV thus emerges as a disclosure vector, not just a financial regulator. The company said the incident affected administrative systems, crude transport continued without interruption, and the systems were restored. In this case, the public information chain ran through capital markets before reaching a sectoral cybersecurity authority. For other natural resource operators, that sequence sets a governance precedent.
Ecopetrol also showed broader compliance, although of a different kind. The company reported the incident in filings with the SEC, disclosed access revocations, complaints filed with the Fiscalía, and work with specialized firms and national authorities. The regulatory signal is that cloud incidents with account and data impact are no longer handled only as a technical issue, but as legal, market, and corporate governance exposure.
Taken together, the month confirms that cybersecurity compliance in natural resources is shifting toward two fronts. On one side, disclosure to markets and oversight bodies. On the other, access traceability, forensic response, and the ability to demonstrate that critical operations did not stop. Anyone unable to document both will be at a disadvantage with regulators, customers, and insurers.
Countries and most affected subsegments
The countries with the highest density of relevant developments on this axis were Argentina and Colombia, followed by operational signals in Peru, Chile, Brazil and Venezuela. Their weight is not explained by the raw number of comparable incidents, but by the sensitivity of the assets affected and the quality of the evidence available in each country.
Argentina
Argentina was dominated by the Oldelval case, which shaped the country picture in August. Oldelval is the main oil transport network tied to Vaca Muerta, with around 75% of the field's crude flowing through its pipelines, according to business coverage. The incident was reported to the CNV, affected administrative systems and did not interrupt crude transport.
What stood out most in Argentina was not only the attack, but the way it was exposed. The case passed through the securities regulator and was picked up by specialized defense, energy and business outlets. Attribution also remained open between The Gentlemen and other theories, including a single reference to incransom. For a critical infrastructure operator, that level of informational noise is already part of the damage.
Colombia
Colombia was marked by Ecopetrol, a state-owned company whose incident involved corporate cloud, unauthorized download and a blocked encryption attempt. The company confirmed there was no interruption to production, but the exposure of data from thousands of accounts and about 15 related companies makes it one of the month's most relevant events for natural resources in the region.
The country also added the reference to the Ministry of Justice as a ransomware case, which helps frame the broader exposure environment. It is not a mining or energy asset, but it is a reminder that critical operators do not work in isolation. Vendor management, credentials and shared access continue to be a cross-cutting failure point.
Chile
Chile appeared on two different levels. On one side, a journalistic investigation into the French company hit by ransomware and with a subsidiary in Quilicura showed possible exfiltration and extortion pressure. On the other, Bloomberg reported copper supply problems caused by storms and by the shutdown of a mine in Peru, with mention of Chilean mining and logistics operations affected by weather. None of those events amounts to a confirmed Chilean mining cyberincident in the material, but both help illustrate the sector's operational fragility.
Peru
Peru was relevant because of Las Bambas, where MMG resumed operations on August 21 after a shutdown tied to a workplace accident. The report is useful because it narrows the impact on copper supply and avoids a mistaken reading of a cyberincident. There is no evidence in the material of a cyberattack on the mine, only an operational disruption unrelated to cybersecurity.
Brazil
Brazil produced two types of signal. Fortinet telemetry, cited by local media, reported nearly 250 billion cyberattacks between January and July and 69,000 cryptomining occurrences in the country during that period. That figure is telemetry, not a confirmed impact incident, but it shows sustained pressure on Brazil's technology infrastructure.
In addition, a specialized note said cryptomining attempts in Brazil surpassed the full total for the previous year. For the natural resources axis, that matters because illicit cryptocurrency mining competes for computing capacity, power and operational visibility, even if it does not by itself imply an intrusion with confirmed damage to the extractive sector.
Venezuela
Venezuela was shaped by the PDVSA case and the contract with SLB. Reuters and other outlets said the US company gained access to field data to organize and modernize outdated databases after years of neglect and a recent cyberattack. There is no newly documented incident here, but there is a structural consequence of system deterioration and the need to regain control over critical information.
Trends and signals to watch
The month’s main trend is the jump in ransomware and uncategorized incidents compared with July. The comparative report shows 26 cases with ransomware or extortion as the primary focus, up from 7 the previous month, and 26 uncategorized incidents, up from 8. That shift cannot be explained by more media noise alone. It points to a threat that is more visible, easier to monetize, and harder to classify accurately.
The second signal is the drop in documented phishing and the limited presence of fraud. Moving from 4 to 1 fraud or phishing case does not mean the vector disappeared, only that it lost prominence in this month’s material to extortion campaigns. For defensive security, that suggests operational attention should focus less on isolated email threats and more on persistent access, identities, and lateral movement.
The third signal is the growing role of regulatory disclosure as part of the incident. Oldelval showed that the relevant filing before the CNV can be the mechanism that shapes the public narrative. Ecopetrol did something similar with the SEC, the Fiscalía, and corporate communications. That means teams need to prepare not only technical containment, but also an evidence chain suitable for regulators and auditors.
The fourth signal is the rising importance of cloud. Ecopetrol was not hit through an exposed PLC or an isolated terminal, but through cloud storage environments and user accounts tied to several companies in the group. In mining, metallurgy, and natural resources, where risk narratives usually center on operational technology, August was a reminder that the corporate layer remains the most profitable target for attackers.
The fifth signal is that the absence of critical CVEs in the material does not improve the outlook. If the month was organized around credentials, access, exfiltration, and RaaS, defenders should read that as an identity, segmentation, and data visibility problem. No standout vulnerability explained everything. What did appear was enough offensive maturity to exploit what already exists inside networks.
Recommendations for security teams
For mining, metals, and natural resources security teams, the priority should be to strengthen identity controls and recovery capabilities, because August saw intrusions that advanced without the need for a publicly identified critical vulnerability. The most significant incidents relied on access, cloud environments, exfiltration, and extortion pressure.
First, review the privileges of administrative and third-party accounts. The month left enough signs of permission abuse and compromised access to treat excessive privileges as an operational risk, not an issue of basic hygiene. Any contractor with unnecessary access to production, cloud, or support systems should be placed in immediate recertification.
Second, harden segmentation between administrative and operational environments. Oldelval showed that an attack can remain confined to administrative systems, but that does not make the problem less serious. Strict separation between transport, industrial control, ERP, and identity services remains one of the few barriers that can stop a corporate intrusion from becoming operational.
Third, test access revocation and exfiltration response. Ecopetrol stood out for its ability to block encryption and revoke compromised credentials. Those actions cannot be improvised in the middle of an incident. They should be rehearsed through drills that include cloud services, document repositories, service accounts, and third-party access.
Fourth, prepare a regulatory disclosure package before an event occurs. The Oldelval case shows that the wording of the report to the regulator, the timeline, and the technical evidence matter as much as containment. Legal, compliance, and security teams should agree on thresholds, templates, and communication owners before an incident happens.
Fifth, monitor leak sites and attribution channels with judgment. The month saw groups claiming attacks and contradictory versions about who was responsible. That makes it necessary to separate useful intelligence from attacker propaganda. Public attribution should only factor into operational decisions when there is independent corroboration, not when the group claims it.
Frequently Asked Questions
What do August’s Oldelval and Ecopetrol cases have in common that other incidents this month do not?
Both incidents combine critical infrastructure, public exposure and regulatory response, but with different impacts. Oldelval reported disruption to administrative systems without stopping crude transport, and Ecopetrol confirmed unauthorized access and encryption blocking. The comparison is developed in Relevant Incidents and Regulation and Compliance.
Why does the report insist on separating encryption, exfiltration and a leak site?
Because August showed three different impacts under the same ransomware label. There was confirmed encryption in a few cases, a single public mention on a leak site in others, and several situations where the material did not allow the typology to be closed. That distinction appears in Active Threats and Campaigns and in the Period Indicators.
What changes for a natural resources operator if there were no critical CVEs in the material?
The defensive focus changes. This month, the risk did not come from a published flaw but from access, credentials, cloud environments and extortion pressure. That means identity, segmentation and recovery should take priority over hunting for a specific vulnerability. The nuance appears in Critical Vulnerabilities and in Trends and Signals to Watch.
Which country was most exposed by the combination of cybersecurity and regulatory disclosure?
Argentina, because of the Oldelval case. The incident reached the CNV, was reported as material information and was tied to the continuity of oil transport. Colombia also had a major case with Ecopetrol, but there the focus was more on exfiltration and encryption blocking than on capital markets disclosure. See Countries and Subsegments Most Affected.
Does cryptomining telemetry in Brazil count as a sector incident?
No. These are automated attempts or blocks, not intrusions with confirmed impact, and therefore they are not counted in the month’s volume. They do, however, serve as contextual signals for pressure on technology infrastructure and resource consumption. The methodological clarification appears in Period Indicators and Material Limitations.
Material limitations
This report was built exclusively from the facts provided for August 2026 on mining, metallurgy, and natural resources in Latin America. The indicator window includes 64 dated facts from August 2026, 7 facts from earlier months used only as a comparative frame, and 1 undated fact that was excluded from the indicators.
A zero value in an indicator, especially the critical CVE count, means none were recorded in the material analyzed, not that they were absent in the region. The same logic applies to other categories that were not observed or appeared in low volume. An absence in the corpus does not equal a real absence of the phenomenon.
Aggregated telemetry figures, such as attempts, blocks, scans, and weekly vendor averages, were excluded from the incident total. If they are mentioned, it is only as context and with the clarification that they are automated attempts or blocks, not confirmed-impact intrusions. Consumer social media and sponsored or commercial content that was not enabled as a primary source for external claims were also excluded.
The available material gives priority to news sources, technical reports, and corporate or regulatory notices. That makes it possible to reconstruct the Oldelval and Ecopetrol cases with considerable clarity, but it leaves less certainty about attribution, exfiltration volumes, and fine-grained classification in several incidents. Where the source did not allow a fact to be closed out, the report says so explicitly rather than overinterpreting it.
Sources
- Argentina's Oldelval Cyberattack Disclosure Shows Securities Law, Not Cyber Law, Is Doing the WorkPeople of Internet
- Ransomware a Oldelval: la gobernanza que le falta a Vaca MuertaDataTrends LATAM
- Ransomware Group incransom Hits: Oleoductos del ValleHookPhish
- Vaca Muerta en alerta por ciberataque a la red que transporta la mayor parte del crudoAlerta Digital (Argentina)
- Argentina's Main Oil Pipeline Was Hacked. The Oil Kept Moving.The Rio Times
- Defonline (Argentina)Defonline (Argentina)
- Ciberataque en Vaca Muerta: ¿Qué pasó con los oleoductos de Oldelval?MásEnergía / LM Neuquén
- Hackers atacaron a Oldelval, que opera el mayor oleoducto de la ArgentinaDiario Neuquino
- 📍CIBERATAQUE A LA INFRAESTRUCTURA CRITICA PETROLERA ARGENTINA📍 (Gabriel Iezzi)X
- 🚨 ACTUALIZACIÓN | Cyberataque a Oldelval (GordoGeos)X
- Oldelval Cyberattack Hits Argentina's Top Oil PipelineThe Rio Times
- La operadora del oleoducto por el que circula el 75% del petróleo de Vaca Muerta sufrió un ciberataque en sus sistemasInfobae
- Ciberseguridad en minería y las prioridades de un CIOMinería y Proyectos
- MMG confirms restart of operations at Las Bambas copper mine, PeruKitco
- IQSEC documenta 116 víctimas y 101 filtraciones de datos ...BNamericas
- Peru Mine Halt, Chilean Storms Add to Copper Supply StrugglesBloomberg
- Cierre de mina en Perú y tormentas en Chile agavan problemas de suministro de CobreBloomberg / La República
- "Tu vulnerabilidad es nuestra riqueza": el ataque de hackers que golpeó a empresa en ChileBioBioChile
- The Gentlemen ya ataca a empresas de ArgentinaPrensa Económica
- Relatório da Fortinet aponta que ataques cibernéticos no Brasil dobraram em 2026Gazeta Brasil
- Ecopetrol Data Leak: Hackers Claim 327095 FilesThe Rio Times
- Agente de IA explota falla de macOS en 4 horas e infiltra ...DiarioBitcoin
- Brasil registra quase 250 bilhões de ataques cibernéticos ...Correio Braziliense
- Confirman ciberataque a principal operador de oleoductoNivel4
- Empresas bajo amenaza: el secuestro digital crece 16,5% ...Ecuador Today Media
- Ransomware en Hidrocarburos: Protección de DatosIntexus
- Phishing en Latinoamérica: 73% de empresas atacadasHoy Donde Estamos
- Un contratista con permisos de administrador hundió a una petrolera — y días después atacaron a un ministerio enteroEl Heraldo de Puebla
- Ransomware Alert: OldelvalX (FalconFeedsio)
- Ataque de Ransomware a Ecopetrol, Julio 2026DataEnforce
- El 'ransomware' se dispara un 87 % a nivel global y ...Infobae (agencias)
- Los ataques de ransomware aumentan un 16% y apuntan a servicios empresariales, manufactura y tecnologíaCaracas Digital
- Operadora del oleoducto que lleva petróleo de Vaca Muerta sufrió un ciberataqueMás Río Negro
- 185 victims for ArgentinaRansomware.live
- Ransomware roundup: July 2026Comparitech
- SLB obtiene acceso a los codiciados datos sobre yacimientos petrolíferos de Venezuela a través de un contratoGBM Media
- EXCLUSIVE-SLB gains access to Venezuela's coveted oilfield data ...Devdiscourse
- EXCLUSIF - Selon certaines sources, SLB a obtenu l'accès aux précieuses données sur les gisements pétroliers du Venezuela grâce à un contratReuters / Boursorama
- Ciberataque a Ecopetrol: qué datos quedaron expuestosITSitio Colombia
- Ecopetrol Ransomware Attack, July 2026: The GentlemenDataEnforce
- PRESS DIGEST 2 AUG 2026: Hunt Oil in VEN; Vaca Muerta pipeline ...Energy Analytics Institute
