Sector register · Energy and critical infrastructure · Argentina
Fourteen incidents in six years, and seven of them never got a single published line
This is the register of known cyber incidents across Argentina's energy sector between 2020 and 2026, with a source for every row. It is built by crossing press coverage, filings to the Comisión Nacional de Valores (CNV, the securities regulator) and the sites where attackers publish their victims. It records what happened and what was said to have happened, in separate columns, because in several cases the two do not match.
The register
What happened to the sector, row by row
Fourteen incidents across energy and critical infrastructure, from June 2020 to August 2026. The confidence column says where each row comes from: high when the organization, a regulator or press with direct sources confirmed it; medium when the attacker's notice is all there is.
| Date | Organization | Subsector | Actor | How it surfaced | Confidence |
|---|---|---|---|---|---|
| 2020-06-07 | Edesur (Enel Argentina) | Power distribution | Snake / EKANS | Press | high |
| 2021-01-26 | Aguas Bonaerenses (ABSA) | Water and sanitation | Unattributed | Press | high |
| 2022-04-05 | Transportadora de Gas del Sur (TGS) | Gas transport | Unattributed | Press | high |
| 2023-02-14 | Grupo Albanesi | Generation and marketing | LockBit 3.0 | Leak site, then CNV | high |
| 2023-07-13 | BTU S.A. | Energy services | 8Base | Leak site | medium |
| 2024-06-13 | Amarilla Gas | LPG distribution | Play | Leak site | medium |
| 2024-12-18 | Comisión Nacional de Energía Atómica (CNEA) | Nuclear | Money Message | Press | high |
| 2025-01-04 | Hidrocarburos Argentinos (HASA) | Upstream | ElDorado | Leak site | medium |
| 2025-02-04 | 360 Energy | Solar generation | Akira | Leak site | medium |
| 2025-05-16 | Hidrocarburos Argentinos (HASA) | Upstream | BlackLock | Leak site | medium |
| 2025-05-27 | Yacimientos Carboníferos Río Turbio (YCRT) | Coal | Unattributed | Press | medium |
| 2025-11-26 | Electricidad Panamericana | Electrical services | Dire Wolf | Leak site | medium |
| 2025-12-14 | AySA | Water and sanitation | SafePay | Leak site | medium |
| 2026-07-23 | Oleoductos del Valle (Oldelval) | Crude transport | The Gentlemen | Leak site, then CNV | high |
→ the table scrolls sideways
- Ciudad de Buenos Aires · 9 Edesur, Transportadora de Gas del Sur, Grupo Albanesi, BTU S.A., Amarilla Gas, Comisión Nacional de Energía Atómica, Hidrocarburos Argentinos S.A., Hidrocarburos Argentinos S.A., AySA
- Buenos Aires · 3 Aguas Bonaerenses S.A., 360 Energy, Electricidad Panamericana
- Santa Cruz · 1 Yacimientos Carboníferos Río Turbio
- Río Negro · 1 Oleoductos del Valle
Hidrocarburos Argentinos appears twice, five months and two different groups apart. Neither appearance got any coverage. AySA and ABSA are not energy: they are included because they are essential services with operational technology and millions of users, which is the category that matters here. Transport and defense stay out, for now: EANA (the air-traffic control operator) and the state railway company ADIF surfaced on leak sites in 2026 without a single published line, and that boundary of the criterion is stated below.
The full data, with what each organization declared, what each attacker claimed and the sources behind every row: ciber-incidentes.json.
Finding
The sector finds out from the attacker, or not at all
Of the fourteen incidents, seven are known only because the group that attacked chose to publish its victim. No statement, no article, no obligation to say anything.
The Oldelval case measures the gap precisely. The group The Gentlemen posted the company on its site on July 23, 2026; the material-event filing to the CNV is stamped July 31, and the first press pieces are dated August 2. For eight days the information existed and circulated, on the attacker's side. Nobody had it on the other side: not the market, not the operators who ship through that same pipeline.
The detail that orders everything else is which channel it was. Oldelval reported to the CNV, the capital-markets regulator, because it issues debt there and a material event must be filed. No equivalent duty exists toward any energy regulator. A sector company that is not listed and gets no phone call owes nobody an account of having been compromised; seven rows of this register show that, indeed, it gives none.
That channel has a history nobody had looked at. The sweep of the CNV's public filings behind this update (30 energy issuers, some 44,000 filings since 2000) found exactly two incidents ever reported: Oldelval's, and an earlier one no timeline records, the "Cyber attack" material-event filing that the three issuers of the Albanesi group submitted on February 16, 2023, two days after LockBit published them. On the other side, TGS and Edesur were also issuers when they were attacked, and neither has a cyber material event anywhere in its filing history. The rule leaves the materiality call to each issuer; the aggregate result is a channel that exists and almost never gets used.
The consequence is that no operator learns from its neighbor's incident. The sector has no peer information-sharing mechanism of the kind other countries run for electricity and for oil and gas. Each company faces the same groups, one at a time, without knowing what worked for the previous one.
Finding
"Administrative systems only" does not mean what it seems to
It is the phrase that appears in nearly every disclosure in this register. Worth looking at which system it actually was, in the two cases where that is known.
At TGS the attack hit SPAC, the platform that processes requests, allocation and scheduling of gas volumes across the pipeline network. Nobody moves a valve from there. What gets decided from there is how much gas enters, whose it is, and where it goes. An oil pipeline has an equivalent layer for crude nomination and balance, and it serves the same purpose: it is what turns contracts into scheduled physical flow.
That layer is administrative on the org chart and operational in practice. When it goes down, the pipe stays full and the gas keeps moving, but scheduling falls back to phone and spreadsheet, balances are reconstructed afterwards, and imbalance penalties end up in dispute. The distinction between information technology and operational technology, which structures the whole practice of industrial security, lets the system that decides dispatch fall straight through the middle.
The 2020 Edesur incident points at the other side of the problem. The ransomware was Snake, also known as EKANS, which ships with a list of industrial processes it terminates before encrypting, operator-interface programs and process historians included. There is no public evidence that this capability was exercised at Edesur, and this register does not claim it was. What can be said is that the family carries it by design, and that it reached an Argentine power distributor in June 2020.
Finding
The sector's most-cited incident is its worst documented
TGS is the case that shows up in every Argentine timeline of cyber incidents. It is also the one that least survives verification.
The two professional compilations that record it classify it as denial of service. In parallel there circulates an attribution to the ALPHV/BlackCat group that there is no way to support: TGS is not among that group's 731 listed victims, and the article usually cited as backing covers Creos Luxembourg, a Luxembourg gas and power utility, with no mention of Argentina. They appear to be two distinct events that at some point fused into one.
That is why the TGS row stands unattributed, and why this register separates confidence that the incident happened from confidence in who did it. A sector that debates its exposure on the strength of a case whose authorship nobody verified is not debating on data.
The groups
Eleven brands signed eleven rows, and none repeated
Each card gathers what an official advisory or a primary vendor report can support, with its status dated August 4, 2026. The discipline is the same as the rows': what no primary source supports does not get claimed.
A group name is not a stable organization. Under the brand there are operators who rotate, platforms that rent their encryptor to affiliates (the RaaS model), infrastructure that police seize, and brands that come back under another name. The cards note this case by case: two of the eleven, the ones that published the same company five months apart, may well be one operator behind two signs.
Snake / EKANS
- Aliases
- EKANS, SNAKEHOSE
- First observed
- December 2019
- In this register
- Edesur, June 2020
The register's only family with explicit industrial design: before encrypting, it runs a fixed kill list of processes that includes operator-interface software and process historians. Dragos describes it as termination to free file locks, not sabotage. No reports since mid-2020; the inactivity is inference from silence, not a declared shutdown.
Sources: Dragos · MITRE ATT&CK · Unit 42
LockBit 3.0
- Aliases
- LockBit Black
- First observed
- June 2022 (the brand, since 2019)
- In this register
- Grupo Albanesi, February 2023
An affiliate platform: third parties paid to use the encryptor and the brand. Operation Cronos seized its panel, source code and over a thousand decryption keys in February 2024; in May, the UK and the US identified and sanctioned its operator, who remains at large. The British agency also established that paying did not guarantee data deletion. The brand resurfaced as LockBit 5.0 in 2025; the variant that published Albanesi was neutralized.
Sources: NCA, Operation Cronos · NCA, sanctions · ransomware.live
8Base
- First observed
- March 2022
- In this register
- BTU, July 2023
A closed group running its own variant of the Phobos ransomware, with double extortion and opportunistic targeting, no sector specialization. In February 2025, Operation Phobos Aetor arrested four alleged leaders in Thailand and took down the leak site; no resurgence reported since.
Sources: VMware · Europol · ransomware.live
Play
- Aliases
- Playcrypt
- First observed
- June 2022
- In this register
- Amarilla Gas, May 2024
The joint FBI/CISA advisory presumes it a closed group, designed to guarantee the secrecy of deals. It enters through valid accounts and exposed services, recompiles the encryptor for every attack, and its ransom note carries no amount: the victim has to write to an email address. As of the June 2025 advisory update, the FBI was aware of some 900 affected organizations.
Sources: FBI/CISA AA23-352A · ransomware.live
Money Message
- First observed
- March 2023
- In this register
- CNEA, November 2024
Double extortion against Windows and virtualization servers, with exfiltration before encryption. There is no official advisory from any agency and no public classification of its model. The thinness of the literature on a group that published data from a nuclear agency is itself a data point.
Sources: Cyble · The Record · ransomware.live
ElDorado
- First observed
- March 2024
- In this register
- HASA, January 2025
An affiliate program announced on a criminal forum, with its own encryptor for Windows, Linux and virtualization servers. Two firms report it went on operating as BlackLock, the group that published HASA again five months later. The continuity is a strong hypothesis on technical and operator overlap; public forensic proof there is none.
Sources: Group-IB · DarkAtlas · Resecurity
Akira
- First observed
- March 2023
- In this register
- 360 Energy, February 2025
It mostly enters through VPN access without a second factor and can exfiltrate within hours. The November 2025 joint advisory declares it an imminent threat to critical infrastructure and estimates some US$ 244 million collected as of late September 2025. The link to the defunct Conti group is one firm's blockchain analysis, not an established fact.
Sources: CISA AA24-109A · Nov 2025 update (PDF) · ransomware.live
BlackLock
- Aliases
- ElDorado (previous brand, per two firms)
- First observed
- 2024
- In this register
- HASA, May 2025
The second brand to publish HASA. Resecurity researchers got into its site through a vulnerability, collected credentials and warned victims and authorities before the group could publish; the infrastructure was wound down in March 2025, and the last published victim dates to July of that year.
Sources: Resecurity · ransomware.live
Dire Wolf
- First observed
- May 2025
- In this register
- Electricidad Panamericana, November 2025
A targeted operation with double extortion and a one-month clock before publishing; the encryptor turns off event logs and deletes backup copies. No police action known; the last published victim dates to June 2026.
Sources: Trustwave SpiderLabs · CSA Singapore · ransomware.live
SafePay
- First observed
- late 2024
- In this register
- AySA, December 2025
A closed group with no affiliates: the same crew enters through VPN and remote desktop with valid credentials, exfiltrates and encrypts within a day, on code related to the leaked LockBit Black builder. Among the most active groups of 2025; its site went dark for weeks in early 2026 for unknown reasons, then came back.
Sources: Huntress · Picus · ransomware.live
The Gentlemen
- Aliases
- Storm-2697
- First observed
- July 2025
- In this register
- Oldelval, July 2026
- In the context table
- Ecopetrol, July 2026
The register's newest group. Custom tooling to disable security products through vulnerable drivers, deployment through domain policies and a self-propagating encryptor; it opened its affiliate program in late 2025. It published Ecopetrol six days before Oldelval: to the operator, the region is a single market.
Sources: Trend Micro · Unit 42 · Microsoft · ransomware.live
The full cards, with aliases, dated statuses and sources: under the actores key of ciber-incidentes.json.
Context
Elsewhere this story already has more chapters
Twelve foreign precedents, with the selection criterion said out loud: a case enters if it illuminates something that already happened here, and if its source is official or the company's own. This is not a register like the one above: it is the part of the map Argentina has not been dealt yet.
| Date | Organization | Subsector | Actor | Affected layer | What happened |
|---|---|---|---|---|---|
| 2015-12-23 | Three distributors (Ukraine) | Power distribution | Sandworm (GRU) | OT / industrial control | 225,000 users in the dark; SCADA driven remotely |
| 2016-12-17 | Ukrenergo (Ukraine) | Power transmission | Sandworm (GRU) | OT / industrial control | Industroyer: one hour of outage in part of Kyiv |
| 2017-08 | Petrochemical plant (Saudi Arabia) | Petrochemicals | TsNIIKhM (Russian state) | Safety instrumented systems | Reprogrammed the last barrier before the accident; the plant tripped itself |
| 2019-03-19 | Norsk Hydro (Norway) | Aluminum | LockerGoga | Corporate IT | Plants on manual; refused to pay, published everything: NOK 800 million |
| 2019-11-10 | Pemex (Mexico) | Oil and gas | DoppelPaymer | Corporate IT | Administrative payments frozen; production went on |
| 2021-02-01 | Copel (Brazil) | Electricity | DarkSide | Corporate IT | Suspended its own systems by choice; 6-K to the SEC that day |
| 2021-02-03 | Eletrobras (Brazil) | Nuclear | Unidentified | Corporate IT | Eletronuclear's administrative network; 6-K to the SEC |
| 2021-05-07 | Colonial Pipeline (US) | Fuel transport | DarkSide | Corporate IT | Five days of pipeline down, by the operator's own decision |
| 2022-04-08 | Power operator (Ukraine) | Electricity | Sandworm | OT / industrial control | Industroyer2, thwarted mid-invasion |
| 2022-12-12 | EPM (Colombia) | Multi-utility | BlackCat/ALPHV | Commercial / dispatch | 304,000 prepaid customers with no top-up channel |
| 2023-05-11 | 22 operators (Denmark) | Electricity | Unattributed | OT / industrial control | The sector CERT's sensors caught the sweep |
| 2026-07-17 | Ecopetrol (Colombia) | Oil and gas | The Gentlemen | Corporate IT | Same actor as Oldelval, six days earlier |
→ the table scrolls sideways
economic crime · state operation · unattributed
The regional half of the table is the same economy that produced the Argentine register: criminal ransomware against the administrative layer of energy companies, with physical operations intact and data held hostage. Two details connect straight to Argentina. Copel, Eletrobras and Ecopetrol told the market about their incidents through 6-K filings to the SEC, which is the same channel through which Oldelval's case surfaced: disclosure through the securities regulator instead of the energy one is a regional pattern, not a local quirk. And the group that published Oldelval had published Ecopetrol six days earlier: to a ransomware operator, the region is a single market.
The global half is the ladder that sits above the administrative layer. Colonial Pipeline is the rung this register most needs to look at: the ransomware came in through the IT network and the operator shut down the entire pipeline for five days, by its own decision and in doubt about the reach; the pipeline regulator later charged it with having no plan to run on manual. The three Ukrainian cases and the Saudi one are the rungs above, and they are no longer economic crime but state operations with formal indictments behind them: substation controls driven remotely in 2015 and 2016, the attempt repeated mid-invasion in 2022, and the reprogramming of a petrochemical plant's safety controllers, the last barrier before the physical accident.
Two cases in the table work as counterexamples more than as threats. Denmark's power sector caught a coordinated sweep against 22 operators within days because its sector CERT had sensors on member networks: that is the working version of the peer-exchange mechanism whose absence the disclosure section records. And Norsk Hydro answered its ransomware by publishing the entire process, with the cost put in numbers by the company itself: the exact inverse of the disclosure pattern this register documents.
The twelve cases with their primary sources (SEC 6-Ks, formal indictments, CERT reports): in the data file, under the contexto_internacional key of ciber-incidentes.json.
The rules
Who must be told: nobody
Argentina's legal landscape explains the shape of this register. Every claim in this section comes from the official text linked next to it; the reading is descriptive, dated August 3, 2026.
What exists is a definition with no obligations attached. Resolution 1523/2019 defines critical infrastructure and lists eleven sectors, energy included, but imposes nothing on any operator. Administrative Decision 641/2021 sets minimum requirements and a 48-hour reporting duty, for the national public administration only. CERT.ar answers incidents from the National Cybersecurity Center, created by emergency decree in late 2025, but cannot demand a report from a private company. And the electricity and gas framework mentions cyber-incident reporting nowhere: not laws 24.065 and 24.076, not the brand-new ENRGE that merged ENRE and ENARGAS in 2025.
The clocks that do run in Argentina sit elsewhere. The CNV's: an issuer reports "immediately" any event that could affect its securities (the rule never mentions cyber incidents), and that general clause is how the sector's only two reported cases surfaced, Albanesi in 2023 and Oldelval in 2026. The central bank's: since 2025, a financial institution reports a cyber incident within the first hour. A bank has one hour; a gas transporter, no obligation at all.
The absence is not an oversight: bills existed, and they lapsed. The one creating a national institute with mandatory reporting for essential-service operators lapsed in 2021 without a committee report, and lapsed again when reintroduced. A national critical-infrastructure plan specific to energy lapsed twice in the lower house. The period's only effective decision, the National Cybersecurity Center, arrived by decree, without passing through Congress and without any reporting duty for private companies.
| Jurisdiction | Rule | Who it binds | Clock | Status |
|---|---|---|---|---|
| Argentina · energy | none exists | nobody | none | the bills lapsed without a committee report |
| Argentina · market | Law 26.831, art. 99 | listed issuers, through the general clause | immediate | no cyber mention; the sector used it twice |
| Argentina · banks | BCRA Communication "A" 8280 | financial institutions and payment providers | 1 hour | in force since 2025 |
| Chile | Law 21.663 (ANCI) | ~1,150 operators of vital importance, energy included | 3 hours | in force; fuels entered in July 2026 |
| US · pipelines | TSA security directives | designated pipeline operators | 72 hours | renewed every year since Colonial |
| US · market | SEC, Form 8-K Item 1.05 | listed issuers | 4 business days | in force since December 2023 |
| European Union | NIS2, article 23 | essential operators; energy opens Annex I | 24 h / 72 h | 4 countries taken to court over transposition |
→ the table scrolls sideways
The nearest mirror is Chile. Electricity entered the first roster of operators of vital importance in December 2025; fuels and pipelines, the second, in July 2026. The reporting duty that does not exist on this side of the mountains runs on a 3-hour clock across them. And the closest parallel to the Argentine channel is the SEC's: the same kind of securities regulator that received Oldelval's filing here named cyber incidents in its form there, and gave them a clock of their own.
What comes next
The layer being added right now
Everything above describes a sector with poor visibility into its own exposure. On top of it, something else is being mounted.
What artificial intelligence changes, on the record so far, is the cost and scale of attacks that already existed: drafting the lure, negotiating the ransom, writing the code. And one clarification that orders the section: none of the fourteen rows above has a documented AI component. This section is here for what is coming, not for what happened.
In 2025 the offensive side stopped being hypothetical. Anthropic documented an operator who used its coding agent to automate an extortion campaign across at least 17 organizations, ransom notes included. ESET described PromptLock, a ransomware that generates its scripts on the fly with a local model, later revealed as an academic prototype. And a new RaaS platform went out recruiting affiliates with a negotiation chatbot built into the panel. Three primary reports, three different links of the same extortion chain.
On the defensive side there is less news than it seems. Anomaly detection on industrial networks predates the language-model wave by more than a decade, and where models help today is in digesting advisories and triaging alerts. Adoption in operational technology is slow for a healthy reason: a false positive can cost physical production.
Measurement is moving faster than doctrine. An artificial-intelligence agent placed in the top 10 of the Dragos operational-technology capture-the-flag in 2025, a tournament built for human specialists. And test benches have begun to appear that measure models in real industrial environments, such as CritBench on digital substations under the IEC 61850 standard.
None of that work touches the nomination and dispatch layer. That is: the literature measures substations and controllers, while the two Argentine incidents with a known affected system hit the commercial layer that schedules flow. At the same time, that commercial layer is where copilots and agents are arriving first, because it is the one with tabular data, written procedures and repetitive decisions.
This register does not answer what happens when an agent with write access operates there. It leaves the question posed on the only base that is proper: the incidents that already happened.
Fiction
Film imagined blackouts; the register shows encrypted servers
Six works shaped what the public expects an infrastructure attack to look like. Holding them against the rows above is the shortest way to measure the distance between the imagined and the documented.
- WarGames (1983): the founding myth of the teenager who gets into everything. It produced actual policy: Reagan watched it, asked whether something like it could happen, and the answer ended in the first US directive on information security, NSDD-145 of 1984. There, fiction produced regulation; here, reality has not yet.
- Live Free or Die Hard (2007): the "fire sale", all infrastructure collapsing in days, with explosions. Across the fourteen Argentine rows the pipe stayed full and the lights stayed on.
- Blackhat (2015): the genre's oddity, because the target is a market layer. It is the closest fiction has come to the commercial layer this register documents, and it still needed to blow up a plant to carry the plot.
- Mr. Robot (2015–2019): praised for technical realism. Its central attack does not turn off the lights: it encrypts a conglomerate's debt records. A screenwriter picked, as a credible apocalypse, exactly the economy of this register.
- Zero Days (2016): the documentary on Stuxnet, the list's only nonfiction entry and the direct bridge to the state-actor rows of the international table.
- Leave the World Behind (2023): total collapse as mass imagination, by the creator of Mr. Robot. The exact contrast: fourteen incidents here, and not one blackout.
The cases that do look like the movies exist, and they sit in the international table: Ukraine in 2015, 2016 and 2022, the Saudi plant in 2017. All of them are state operations with formal indictments behind them; none belongs to the criminal economy that produced the Argentine rows. Fiction trained the public to fear the blackout. The risk documented here is duller, cheaper and closer: an encrypted server, a stolen invoice, a countdown reaching zero on a Tor site.
Limits
What these data cannot support
It cannot be said that these fourteen are all there are. They are the ones that left a public trace, and the register itself shows that the trace depends on whether the attacker chose to publish and whether the company is listed. An incident resolved quietly, with no exfiltration and no listing, appears neither here nor anywhere.
It cannot be said that the eight medium-confidence rows happened the way the attacker tells them. A ransomware group publishes victims to apply pressure, and has an incentive to exaggerate the reach, the volume and the sensitivity of what it took. What is verifiable is that the publication exists, not what it says.
Nothing can be said about the state of security of any of these organizations. Appearing in the register means they were attacked, not that they were unprepared; several of them contained the incident with no service interruption. Absence from the register does not mean the opposite either.
It cannot be said that the groups in the cards are stable organizations. A name bundles operators who rotate, affiliates who switch platforms, and infrastructure that gets seized and reborn under another sign; two cards in this register may well be the same operator. Each status holds at its cutoff date, not after.
It cannot be said that the nomination and dispatch layer is the preferred way in. That is two cases with a known system, out of fourteen incidents. It is a hypothesis the available evidence makes reasonable, and one that needs checking with people who operate those systems.
The international table cannot be read as a census. It is a curated set of twelve cases under the criterion its section declares: the world had far more incidents than these, and the selection picked them because they illuminate Argentine findings, not because they represent anything.
And the rules section cannot be taken as legal opinion. It describes texts in force as of August 3, 2026, several of them moving (the permanent US pipeline rule is still a proposal, the ENRGE is still being stood up), and it does not judge whether other countries' rules work: it records only which obligation exists and which does not.
Roadmap
What is missing, and what would unlock it
Four open lines of work. Each one closes a concrete limit from the section above, and none of them needs anyone's permission to start.
-
Extend the CNV sweep
The sweep behind this update read the titles of some 44,000 filings from 30 issuers; it did not read the attachments, nor cover the small provincial distributors, nor run on its own. What follows: read the content of material events with opaque titles, add the missing issuers, and automate the sweep of each public filing sheet with the same mechanics as the ransomware.live monitor. It shrinks the limit of "these fourteen are not necessarily all".
-
Check the hypothesis with the people who run those systems
Eight to ten conversations with operator staff (the people who use the nomination, balance and dispatch systems), aggregated and anonymized into a two-page annex. It closes the register's most uncomfortable limit: the commercial-layer hypothesis currently rests on two cases with a known system.
-
Measure AI agents on the nomination and dispatch layer
A test bench with scenarios drawn from the incidents in this register, on a synthetic nomination and dispatch layer. The artificial-intelligence section leaves a question posed; the literature measures substations and controllers, and nobody measures this layer.
-
Size a peer information-sharing mechanism
A technical note on the minimum version of the Danish model that fits a sector with fourteen known incidents and zero reporting obligation: who deploys the sensors, who sees what, and what gets shared without exposing anyone. It closes the finding that every operator faces the same groups alone.
Reference
The terms of this register, in order of appearance
Thirteen terms defined by what they do here, not by the dictionary. Each entry says in which section it first appears.
ransomware
A program that encrypts the victim's files and keeps them inaccessible until a ransom is paid. Since 2019 the term also names the groups that operate it, which usually steal the data before encrypting it. Appears in the register →
leak site
The attacker's storefront: a site, almost always on the Tor network, where the group publishes its victims and a sample of what it took, to press for payment. Seven rows of this register exist only because they appeared there. Appears in the register →
material event (CNV and AIF)
The filing an issuer of stock or debt submits to the Comisión Nacional de Valores when something happens that could affect its securities; it becomes public on the Autopista de la Información Financiera (AIF). It is the channel through which the sector's only two reported incidents surfaced. Appears in disclosure →
IT / OT
Information technology (IT) manages data: email, invoicing, spreadsheets. Operational technology (OT) controls physical processes: valves, pumps, substations. Industrial security practice is organized around that boundary, and this register documents systems that fall straight through it. Appears in the line →
nomination and dispatch layer
The systems where how much gas or crude moves through a transport network gets requested, allocated and scheduled: they turn contracts into scheduled physical flow. Administrative on the org chart, operational in practice. The term is this register's own. Appears in the line →
operator interface (HMI) and process historian
The HMI is the screen from which an operator watches and commands a plant; the historian is the database that stores each sensor's time series. Industrial software running on ordinary computers, which is why it shows up on some ransomware's process kill list. Appears in the line →
attribution
Determining who carried out an attack. Public forensic proof is rare: most criminal attributions come from a group publishing the victim on its site, which proves it claims the attack, not that it did it. Appears in provenance →
RaaS and affiliates
Ransomware as a service: a platform rents out the encryptor, the leak site and the brand; affiliates do the intrusion and share the proceeds. It explains how one sign can be behind attacks of very different skill. Appears in the groups →
double extortion
Stealing the data before encrypting it, to charge twice: for decryption and for silence. It turned backups into an incomplete defense, because restoring systems does not stop the leak. Appears in the groups →
exfiltration
Copying data out of the victim's network, before encryption in double extortion. In several documented cases it takes hours, not weeks. Appears in the groups →
SCADA
Supervisory control and data acquisition: the system that concentrates remote operation of a power, gas or water network. Driving it remotely is exactly what happened in Ukraine in 2015. Appears in context →
SIS, safety instrumented system
The autonomous controllers that take a plant to safe shutdown when the process leaves its range: the last barrier before the physical accident. The 2017 Triton case is the only publicly documented attack on that layer. Appears in context →
CERT
A computer emergency response team, national or sector-wide. Denmark's detected a sweep against 22 operators within days because it had sensors on its members' networks; Argentina's, CERT.ar, cannot demand a report from a private company. Appears in context →
Resources
Where to look, besides here
Thirteen entries, each with its purpose stated. Whatever does not serve a reader of this register stayed out: four organizations whose cyber work is members-only or nonexistent were cut.
Tracking and response
- CERT.ar: the national incident-response team, today under the National Cybersecurity Center; where the public sector reports, and the source of the official statistics.
- ransomware.live: the open tracker of ransomware victims that feeds this register's monitor; data and API free of charge.
- CISA ICS Advisories: the official US advisories on vulnerabilities in industrial control equipment, by vendor and by product.
- Centro de Ciberseguridad Industrial (CCI): the Spanish-speaking industrial cybersecurity network, with an active Argentine chapter and free basic membership.
- SektorCERT, the 2023 attack report: the best public post-mortem of a coordinated attack on a power sector, written by the CERT that detected it (PDF).
- ONE-ISAC: the North American oil & gas peer-exchange center: the model of sector collaboration missing here.
Technical reference
- NIST SP 800-82 rev. 3: the free reference guide for securing operational technology; the starting point when a program has to be built from zero.
- SANS, Five ICS Cybersecurity Critical Controls: the five controls an energy company should have before anything else, in 20 pages a manager can read; asks for a free account.
- ISA/IEC 62443: the industrial cybersecurity standard, explained for free by its authors in the ISAGCA guides; the full standard text is paid.
- MITRE ATT&CK for ICS: the standard catalog of attack tactics against industrial systems: the vocabulary of the technical reports this register cites.
- Dragos, OT Cybersecurity Report: the sector's most-cited annual report on threats to industrial systems; the 2026 edition asks for an email to download.
Learning and community
- BlueDot, "How AI could enable critical infrastructure collapse": Li-Lian Ang's essay on how artificial intelligence lowers the skill and time barrier to attacking critical infrastructure; Colonial Pipeline, NotPetya and Ukraine as reference, and every claim linked to its source.
- BAISH (Buenos Aires AI Safety Hub): Buenos Aires's AI safety community; the local doorway into the discipline this register’s AI section crosses with energy.
How it is made
Sources, updates and corrections
Rows come through three channels. The specialized press, the organizations' own communications and the material-event filings to the CNV give seven rows, of which six reach high confidence: YCRT stays at medium because its only source is a secondary compilation. The sites where ransomware groups publish their victims give the other seven, and are consulted through the public interface of ransomware.live, which as of August 3, 2026 lists 178 posts about Argentine victims across all sectors. The leak-site addresses are on record and are not published.
A monitor runs against that same interface, crosses every new Argentine victim against a sector lexicon and flags when a row needs writing. The row itself is written by hand: no endpoint returns what the company declared, and that column is half the value of the register.
The CNV sweep ran over the public filing sheets of the Autopista de la Información Financiera: 30 energy issuers, some 44,000 filings since 2000, scanned by title in two lexicon passes, plus a row-by-row manual review in the windows of the incidents already known. The method's limit sits in the title: a cyber material event with an opaque heading goes undetected, and there are issuers that title theirs "HR" and nothing else. The attachments were not read; that is the first item on the roadmap.
Corrections that arrive are applied to the row and dated in the correcciones array of the data file, with what changed and who flagged it. Nothing is edited silently. The request is above, with the address: back to the notice.
The data file is published under a CC BY 4.0 license: use it anywhere, with attribution. Every new row and every correction also goes out through the Atom feed.
Who is behind this
Matías Podeley. An ITBA engineer, eighteen years in energy: four in operations in Neuquén, simulation of giant fields like Camisea, appraisal of petrochemical projects, technical backing of asset purchases above US$ 300 million, and five years teaching project appraisal. The craft behind this site: understanding the business need, and building the project or the tool that answers it, with AI and auditable sources. Buenos Aires.
The AI-safety research behind the last section: research.