Six different ransomware crews put eight Argentine organisations on their leak sites in the week to 20 September. The number is not what makes the week unusual. It is that no single crew is driving it.
Argentina normally draws about one leak-site claim a week in IntelFusions' incident tracking. Eight is the highest weekly total we have recorded for the country since that tracking began in January 2024, ahead of two weeks of seven in July. Our coverage of leak sites has widened over those two years, so treat the long comparison as indicative rather than exact. The shape of this particular week stands on its own.
Six crews, not one spree
Qilin accounted for three of the eight: Ceres Tolvas, which our data records as an agriculture and food business, the technology firm Techwise, and Vitar Group. The other five came from five separate operations. INC Ransom listed the retailer Diarco. The Gentlemen listed the bookshop chain Libreria Santa Fe. DragonForce and Audit Team each posted a bare Argentine domain rather than a company name. A crew calling itself N0n listed Argentina's Ministry of Education. Two of the six, N0n and Audit Team, only surfaced this year, which is a reminder that the roster turning up in any given country is not fixed.
These are claims, not confirmed breaches
Every figure here comes from posts the gangs wrote about themselves, on infrastructure they control. We have seen no public confirmation from any of the organisations named, and a listing is an assertion about an intrusion rather than evidence of one. The gangs also have an obvious interest in the assertion being believed, since the whole mechanism runs on pressure. The sites themselves sit on .onion addresses, which we do not link.
A ministry among the names
The entry worth watching is Argentina's Ministry of Education, posted by N0n on 18 September. Our record of it carries only a victim name, a sector and a date, which is normal for this crew and tells you nothing about scope. Government listings still matter more than the rest, because they are what a national response gets organised around, and Argentina's coordination point for that is CERT.ar, inside the national cybersecurity centre. Argentine public bodies have been named before: Qilin listed the country's army in July.
Treat a listing as a prompt, not a verdict
For an organisation that finds its own name on one of these sites, the useful response is to preserve logs before anything is overwritten, check remote access and administrator accounts, and report to CERT.ar rather than negotiate on the gang's clock. For everyone else in the same sectors, a week like this is a cheap prompt to confirm that external access points are patched and monitored.
One week at eight against a median of one is a spike, not yet a trend. Argentina's two previous peaks, in early and late July, were each followed inside a month by weeks of one or two claims. The test is whether this holds into a second week. We watched a similar run of claims against Chile in August, and the useful signal was never the count on the day; it was what the count did next.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.