The prolific ransomware crew Qilin added an unusual name to its dark web leak site on July 24: Ejercito Argentino, the army of Argentina. Extortion gangs list thousands of companies a year, but national armed forces almost never appear among them, which makes this entry worth a closer look than the average leak-site post.
It is important to be clear about what this is. A leak-site listing is an unverified claim written by the attackers to pressure a target into paying. It is not a confirmed breach. The Argentine army has not publicly acknowledged an intrusion, and the entry IntelFusions recorded carries no ransom figure, no stated volume of stolen data, and no described proof sample. Listings on these sites are sometimes exaggerated, recycled from an earlier incident, built on data taken from a contractor rather than the named body itself, or occasionally fabricated outright.
Why a military listing stands out
Qilin is not new to the public sector, but it has stuck to civilian government. Across more than 2,000 Qilin listings IntelFusions has recorded since January 2024, the group's government-adjacent victims have been bodies like Ukraine's Ministry of Foreign Affairs, the Ministry of Health of Palau, Catawba County in North Carolina, Cleveland Municipal Court and the Municipio de Chihuahua in Mexico. This is the first national armed force in that entire set.
Widen the lens to every crew IntelFusions tracks and military listings remain scarce. The closest precedent is INC Ransom, which listed the Ejercito del Peru in March 2024, another South American army. KillSec listed the Royal Saudi Air Force in April 2025, and FunkSec posted a Bangladesh Navy domain in January 2025. Ordinary criminal ransomware affiliates usually avoid defence ministries because the law enforcement and intelligence response is disproportionate to the likely payout, so when a military does surface it is often the result of opportunistic access rather than deliberate targeting.
Part of a busy four days
The army entry did not arrive alone. Qilin posted 27 listings between July 22 and July 25, a tempo of roughly four a day that is consistent with the group's recent output of about 120 claims in the past month. The run spanned Germany, Canada, Mexico, Peru, Brazil, Malaysia, the Philippines, the United Kingdom, Turkey, Pakistan, Ireland, Nigeria, India and the United States.
Education took a notable share, with Kean University, Highline Community College and California's Salida Union School District all added. One entry is listed only as "Stryker" under US healthcare; the leak site gives a bare name, which is not enough to establish which company of that name is meant. The pattern is otherwise familiar for Qilin, whose affiliates work through mid-sized manufacturers, clinics, logistics firms and professional-services outfits, much as they did when the crew swept up US churches, schools and small businesses a week earlier.
For Argentina the listing lands in an already active year: IntelFusions has recorded 62 leak-site claims against Argentine organizations in the past 12 months, spread across 17 different groups. More context is on the Argentina country profile.
Who Qilin is
Qilin, also tracked as Agenda, has run a ransomware-as-a-service operation since 2022, with a core team maintaining the encryptor and leak infrastructure while affiliates carry out intrusions for a cut. It is known for targeting VMware ESXi virtualisation hosts, and it was behind the 2024 attack that disrupted blood-testing services for London hospitals. Its history and tooling are on the IntelFusions Qilin profile.
What you should do
If your organization appears on a leak site, treat it as a real incident until you can prove otherwise: preserve logs, hunt for unauthorised access, and involve law enforcement rather than negotiating alone. Public-sector and defence bodies should extend that check to suppliers and contractors, since shared file transfer and remote-access accounts are a common route into an otherwise hardened network. The baseline controls that blunt Qilin affiliates are unglamorous and effective: multi-factor authentication on email, VPN and every remote-access path; prompt patching of internet-facing systems; hardened and separately credentialed ESXi management interfaces; offline, tested backups so recovery does not depend on paying; and monitoring for large outbound transfers that betray exfiltration before encryption starts.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.