Matías Podeley ES

Sector register · Energy and critical infrastructure · Argentina

Fourteen incidents in six years, and seven of them never got a single published line

This is the register of known cyber incidents across Argentina's energy sector between 2020 and 2026, with a source for every row. It is built by crossing press coverage, filings to the Comisión Nacional de Valores (CNV, the securities regulator) and the sites where attackers publish their victims. It records what happened and what was said to have happened, in separate columns, because in several cases the two do not match.

Updated August 4, 2026 Go to the register Who attacks International context Legal landscape

The register

What happened to the sector, row by row

Fourteen incidents across energy and critical infrastructure, from June 2020 to August 2026. The confidence column says where each row comes from: high when the organization, a regulator or press with direct sources confirmed it; medium when the attacker's notice is all there is.

Date = the first moment the fact became publicly knowable, through any channel.
DateOrganizationSubsectorActorHow it surfacedConfidence
2020-06-07Edesur (Enel Argentina)Power distributionSnake / EKANSPresshigh
2021-01-26Aguas Bonaerenses (ABSA)Water and sanitationUnattributedPresshigh
2022-04-05Transportadora de Gas del Sur (TGS)Gas transportUnattributedPresshigh
2023-02-14Grupo AlbanesiGeneration and marketingLockBit 3.0Leak site, then CNVhigh
2023-07-13BTU S.A.Energy services8BaseLeak sitemedium
2024-06-13Amarilla GasLPG distributionPlayLeak sitemedium
2024-12-18Comisión Nacional de Energía Atómica (CNEA)NuclearMoney MessagePresshigh
2025-01-04Hidrocarburos Argentinos (HASA)UpstreamElDoradoLeak sitemedium
2025-02-04360 EnergySolar generationAkiraLeak sitemedium
2025-05-16Hidrocarburos Argentinos (HASA)UpstreamBlackLockLeak sitemedium
2025-05-27Yacimientos Carboníferos Río Turbio (YCRT)CoalUnattributedPressmedium
2025-11-26Electricidad PanamericanaElectrical servicesDire WolfLeak sitemedium
2025-12-14AySAWater and sanitationSafePayLeak sitemedium
2026-07-23Oleoductos del Valle (Oldelval)Crude transportThe GentlemenLeak site, then CNVhigh

→ the table scrolls sideways

9 3 1 1
Where each incident anchors. A cyber incident has no province: the dot is the seat of the affected systems, almost always administrative, not the organization's footprint. That 9 of 14 anchor in Buenos Aires City is the administrative-layer finding, not risk geography. Each row's criterion sits in the provincias field of the data file.

Hidrocarburos Argentinos appears twice, five months and two different groups apart. Neither appearance got any coverage. AySA and ABSA are not energy: they are included because they are essential services with operational technology and millions of users, which is the category that matters here. Transport and defense stay out, for now: EANA (the air-traffic control operator) and the state railway company ADIF surfaced on leak sites in 2026 without a single published line, and that boundary of the criterion is stated below.

Finding

The sector finds out from the attacker, or not at all

Of the fourteen incidents, seven are known only because the group that attacked chose to publish its victim. No statement, no article, no obligation to say anything.

The Oldelval case measures the gap precisely. The group The Gentlemen posted the company on its site on July 23, 2026; the material-event filing to the CNV is stamped July 31, and the first press pieces are dated August 2. For eight days the information existed and circulated, on the attacker's side. Nobody had it on the other side: not the market, not the operators who ship through that same pipeline.

The detail that orders everything else is which channel it was. Oldelval reported to the CNV, the capital-markets regulator, because it issues debt there and a material event must be filed. No equivalent duty exists toward any energy regulator. A sector company that is not listed and gets no phone call owes nobody an account of having been compromised; seven rows of this register show that, indeed, it gives none.

That channel has a history nobody had looked at. The sweep of the CNV's public filings behind this update (30 energy issuers, some 44,000 filings since 2000) found exactly two incidents ever reported: Oldelval's, and an earlier one no timeline records, the "Cyber attack" material-event filing that the three issuers of the Albanesi group submitted on February 16, 2023, two days after LockBit published them. On the other side, TGS and Edesur were also issuers when they were attacked, and neither has a cyber material event anywhere in its filing history. The rule leaves the materiality call to each issuer; the aggregate result is a channel that exists and almost never gets used.

The consequence is that no operator learns from its neighbor's incident. The sector has no peer information-sharing mechanism of the kind other countries run for electricity and for oil and gas. Each company faces the same groups, one at a time, without knowing what worked for the previous one.

Finding

"Administrative systems only" does not mean what it seems to

It is the phrase that appears in nearly every disclosure in this register. Worth looking at which system it actually was, in the two cases where that is known.

At TGS the attack hit SPAC, the platform that processes requests, allocation and scheduling of gas volumes across the pipeline network. Nobody moves a valve from there. What gets decided from there is how much gas enters, whose it is, and where it goes. An oil pipeline has an equivalent layer for crude nomination and balance, and it serves the same purpose: it is what turns contracts into scheduled physical flow.

That layer is administrative on the org chart and operational in practice. When it goes down, the pipe stays full and the gas keeps moving, but scheduling falls back to phone and spreadsheet, balances are reconstructed afterwards, and imbalance penalties end up in dispute. The distinction between information technology and operational technology, which structures the whole practice of industrial security, lets the system that decides dispatch fall straight through the middle.

The 2020 Edesur incident points at the other side of the problem. The ransomware was Snake, also known as EKANS, which ships with a list of industrial processes it terminates before encrypting, operator-interface programs and process historians included. There is no public evidence that this capability was exercised at Edesur, and this register does not claim it was. What can be said is that the family carries it by design, and that it reached an Argentine power distributor in June 2020.

Finding

The sector's most-cited incident is its worst documented

TGS is the case that shows up in every Argentine timeline of cyber incidents. It is also the one that least survives verification.

The two professional compilations that record it classify it as denial of service. In parallel there circulates an attribution to the ALPHV/BlackCat group that there is no way to support: TGS is not among that group's 731 listed victims, and the article usually cited as backing covers Creos Luxembourg, a Luxembourg gas and power utility, with no mention of Argentina. They appear to be two distinct events that at some point fused into one.

That is why the TGS row stands unattributed, and why this register separates confidence that the incident happened from confidence in who did it. A sector that debates its exposure on the strength of a case whose authorship nobody verified is not debating on data.

The groups

Eleven brands signed eleven rows, and none repeated

Each card gathers what an official advisory or a primary vendor report can support, with its status dated August 4, 2026. The discipline is the same as the rows': what no primary source supports does not get claimed.

A group name is not a stable organization. Under the brand there are operators who rotate, platforms that rent their encryptor to affiliates (the RaaS model), infrastructure that police seize, and brands that come back under another name. The cards note this case by case: two of the eleven, the ones that published the same company five months apart, may well be one operator behind two signs.

Snake / EKANSransomwareinactive 2020
Aliases
EKANS, SNAKEHOSE
First observed
December 2019
In this register
Edesur, June 2020

The register's only family with explicit industrial design: before encrypting, it runs a fixed kill list of processes that includes operator-interface software and process historians. Dragos describes it as termination to free file locks, not sabotage. No reports since mid-2020; the inactivity is inference from silence, not a declared shutdown.

Sources: Dragos · MITRE ATT&CK · Unit 42

LockBit 3.0RaaSdisrupted 2024
Aliases
LockBit Black
First observed
June 2022 (the brand, since 2019)

An affiliate platform: third parties paid to use the encryptor and the brand. Operation Cronos seized its panel, source code and over a thousand decryption keys in February 2024; in May, the UK and the US identified and sanctioned its operator, who remains at large. The British agency also established that paying did not guarantee data deletion. The brand resurfaced as LockBit 5.0 in 2025; the variant that published Albanesi was neutralized.

Sources: NCA, Operation Cronos · NCA, sanctions · ransomware.live

8Baseransomwaredisrupted 2025
First observed
March 2022
In this register
BTU, July 2023

A closed group running its own variant of the Phobos ransomware, with double extortion and opportunistic targeting, no sector specialization. In February 2025, Operation Phobos Aetor arrested four alleged leaders in Thailand and took down the leak site; no resurgence reported since.

Sources: VMware · Europol · ransomware.live

Playransomwareactive
Aliases
Playcrypt
First observed
June 2022
In this register
Amarilla Gas, May 2024

The joint FBI/CISA advisory presumes it a closed group, designed to guarantee the secrecy of deals. It enters through valid accounts and exposed services, recompiles the encryptor for every attack, and its ransom note carries no amount: the victim has to write to an email address. As of the June 2025 advisory update, the FBI was aware of some 900 affected organizations.

Sources: FBI/CISA AA23-352A · ransomware.live

Money Messageransomwareactive
First observed
March 2023
In this register
CNEA, November 2024

Double extortion against Windows and virtualization servers, with exfiltration before encryption. There is no official advisory from any agency and no public classification of its model. The thinness of the literature on a group that published data from a nuclear agency is itself a data point.

Sources: Cyble · The Record · ransomware.live

ElDoradoRaaSrebranded 2024
First observed
March 2024
In this register
HASA, January 2025

An affiliate program announced on a criminal forum, with its own encryptor for Windows, Linux and virtualization servers. Two firms report it went on operating as BlackLock, the group that published HASA again five months later. The continuity is a strong hypothesis on technical and operator overlap; public forensic proof there is none.

Sources: Group-IB · DarkAtlas · Resecurity

AkiraRaaSactive
First observed
March 2023

It mostly enters through VPN access without a second factor and can exfiltrate within hours. The November 2025 joint advisory declares it an imminent threat to critical infrastructure and estimates some US$ 244 million collected as of late September 2025. The link to the defunct Conti group is one firm's blockchain analysis, not an established fact.

Sources: CISA AA24-109A · Nov 2025 update (PDF) · ransomware.live

BlackLockRaaSinactive 2025
Aliases
ElDorado (previous brand, per two firms)
First observed
2024
In this register
HASA, May 2025

The second brand to publish HASA. Resecurity researchers got into its site through a vulnerability, collected credentials and warned victims and authorities before the group could publish; the infrastructure was wound down in March 2025, and the last published victim dates to July of that year.

Sources: Resecurity · ransomware.live

Dire Wolfransomwareactive
First observed
May 2025

A targeted operation with double extortion and a one-month clock before publishing; the encryptor turns off event logs and deletes backup copies. No police action known; the last published victim dates to June 2026.

Sources: Trustwave SpiderLabs · CSA Singapore · ransomware.live

SafePayransomwareactive
First observed
late 2024
In this register
AySA, December 2025

A closed group with no affiliates: the same crew enters through VPN and remote desktop with valid credentials, exfiltrates and encrypts within a day, on code related to the leaked LockBit Black builder. Among the most active groups of 2025; its site went dark for weeks in early 2026 for unknown reasons, then came back.

Sources: Huntress · Picus · ransomware.live

The GentlemenRaaSactive
Aliases
Storm-2697
First observed
July 2025
In this register
Oldelval, July 2026
In the context table
Ecopetrol, July 2026

The register's newest group. Custom tooling to disable security products through vulnerable drivers, deployment through domain policies and a self-propagating encryptor; it opened its affiliate program in late 2025. It published Ecopetrol six days before Oldelval: to the operator, the region is a single market.

Sources: Trend Micro · Unit 42 · Microsoft · ransomware.live

Context

Elsewhere this story already has more chapters

Twelve foreign precedents, with the selection criterion said out loud: a case enters if it illuminates something that already happened here, and if its source is official or the company's own. This is not a register like the one above: it is the part of the map Argentina has not been dealt yet.

Date = the incident's own; where only the month is defensible, the month is shown. The affected layer is what connects each case to the Argentine register.
DateOrganizationSubsectorActorAffected layerWhat happened
2015-12-23Three distributors (Ukraine)Power distributionSandworm (GRU)OT / industrial control225,000 users in the dark; SCADA driven remotely
2016-12-17Ukrenergo (Ukraine)Power transmissionSandworm (GRU)OT / industrial controlIndustroyer: one hour of outage in part of Kyiv
2017-08Petrochemical plant (Saudi Arabia)PetrochemicalsTsNIIKhM (Russian state)Safety instrumented systemsReprogrammed the last barrier before the accident; the plant tripped itself
2019-03-19Norsk Hydro (Norway)AluminumLockerGogaCorporate ITPlants on manual; refused to pay, published everything: NOK 800 million
2019-11-10Pemex (Mexico)Oil and gasDoppelPaymerCorporate ITAdministrative payments frozen; production went on
2021-02-01Copel (Brazil)ElectricityDarkSideCorporate ITSuspended its own systems by choice; 6-K to the SEC that day
2021-02-03Eletrobras (Brazil)NuclearUnidentifiedCorporate ITEletronuclear's administrative network; 6-K to the SEC
2021-05-07Colonial Pipeline (US)Fuel transportDarkSideCorporate ITFive days of pipeline down, by the operator's own decision
2022-04-08Power operator (Ukraine)ElectricitySandwormOT / industrial controlIndustroyer2, thwarted mid-invasion
2022-12-12EPM (Colombia)Multi-utilityBlackCat/ALPHVCommercial / dispatch304,000 prepaid customers with no top-up channel
2023-05-1122 operators (Denmark)ElectricityUnattributedOT / industrial controlThe sector CERT's sensors caught the sweep
2026-07-17Ecopetrol (Colombia)Oil and gasThe GentlemenCorporate ITSame actor as Oldelval, six days earlier

→ the table scrolls sideways

The 12 context cases, on the map. Each dot leads to its row; the shape says who attacks.

economic crime · state operation · unattributed

The regional half of the table is the same economy that produced the Argentine register: criminal ransomware against the administrative layer of energy companies, with physical operations intact and data held hostage. Two details connect straight to Argentina. Copel, Eletrobras and Ecopetrol told the market about their incidents through 6-K filings to the SEC, which is the same channel through which Oldelval's case surfaced: disclosure through the securities regulator instead of the energy one is a regional pattern, not a local quirk. And the group that published Oldelval had published Ecopetrol six days earlier: to a ransomware operator, the region is a single market.

The global half is the ladder that sits above the administrative layer. Colonial Pipeline is the rung this register most needs to look at: the ransomware came in through the IT network and the operator shut down the entire pipeline for five days, by its own decision and in doubt about the reach; the pipeline regulator later charged it with having no plan to run on manual. The three Ukrainian cases and the Saudi one are the rungs above, and they are no longer economic crime but state operations with formal indictments behind them: substation controls driven remotely in 2015 and 2016, the attempt repeated mid-invasion in 2022, and the reprogramming of a petrochemical plant's safety controllers, the last barrier before the physical accident.

Two cases in the table work as counterexamples more than as threats. Denmark's power sector caught a coordinated sweep against 22 operators within days because its sector CERT had sensors on member networks: that is the working version of the peer-exchange mechanism whose absence the disclosure section records. And Norsk Hydro answered its ransomware by publishing the entire process, with the cost put in numbers by the company itself: the exact inverse of the disclosure pattern this register documents.

The rules

Who must be told: nobody

Argentina's legal landscape explains the shape of this register. Every claim in this section comes from the official text linked next to it; the reading is descriptive, dated August 3, 2026.

What exists is a definition with no obligations attached. Resolution 1523/2019 defines critical infrastructure and lists eleven sectors, energy included, but imposes nothing on any operator. Administrative Decision 641/2021 sets minimum requirements and a 48-hour reporting duty, for the national public administration only. CERT.ar answers incidents from the National Cybersecurity Center, created by emergency decree in late 2025, but cannot demand a report from a private company. And the electricity and gas framework mentions cyber-incident reporting nowhere: not laws 24.065 and 24.076, not the brand-new ENRGE that merged ENRE and ENARGAS in 2025.

The clocks that do run in Argentina sit elsewhere. The CNV's: an issuer reports "immediately" any event that could affect its securities (the rule never mentions cyber incidents), and that general clause is how the sector's only two reported cases surfaced, Albanesi in 2023 and Oldelval in 2026. The central bank's: since 2025, a financial institution reports a cyber incident within the first hour. A bank has one hour; a gas transporter, no obligation at all.

The absence is not an oversight: bills existed, and they lapsed. The one creating a national institute with mandatory reporting for essential-service operators lapsed in 2021 without a committee report, and lapsed again when reintroduced. A national critical-infrastructure plan specific to energy lapsed twice in the lower house. The period's only effective decision, the National Cybersecurity Center, arrived by decree, without passing through Congress and without any reporting duty for private companies.

Who must tell whom, and how fast. Texts in force as of August 3, 2026.
JurisdictionRuleWho it bindsClockStatus
Argentina · energynone existsnobodynonethe bills lapsed without a committee report
Argentina · marketLaw 26.831, art. 99listed issuers, through the general clauseimmediateno cyber mention; the sector used it twice
Argentina · banksBCRA Communication "A" 8280financial institutions and payment providers1 hourin force since 2025
ChileLaw 21.663 (ANCI)~1,150 operators of vital importance, energy included3 hoursin force; fuels entered in July 2026
US · pipelinesTSA security directivesdesignated pipeline operators72 hoursrenewed every year since Colonial
US · marketSEC, Form 8-K Item 1.05listed issuers4 business daysin force since December 2023
European UnionNIS2, article 23essential operators; energy opens Annex I24 h / 72 h4 countries taken to court over transposition

→ the table scrolls sideways

The nearest mirror is Chile. Electricity entered the first roster of operators of vital importance in December 2025; fuels and pipelines, the second, in July 2026. The reporting duty that does not exist on this side of the mountains runs on a 3-hour clock across them. And the closest parallel to the Argentine channel is the SEC's: the same kind of securities regulator that received Oldelval's filing here named cyber incidents in its form there, and gave them a clock of their own.

What comes next

The layer being added right now

Everything above describes a sector with poor visibility into its own exposure. On top of it, something else is being mounted.

What artificial intelligence changes, on the record so far, is the cost and scale of attacks that already existed: drafting the lure, negotiating the ransom, writing the code. And one clarification that orders the section: none of the fourteen rows above has a documented AI component. This section is here for what is coming, not for what happened.

In 2025 the offensive side stopped being hypothetical. Anthropic documented an operator who used its coding agent to automate an extortion campaign across at least 17 organizations, ransom notes included. ESET described PromptLock, a ransomware that generates its scripts on the fly with a local model, later revealed as an academic prototype. And a new RaaS platform went out recruiting affiliates with a negotiation chatbot built into the panel. Three primary reports, three different links of the same extortion chain.

On the defensive side there is less news than it seems. Anomaly detection on industrial networks predates the language-model wave by more than a decade, and where models help today is in digesting advisories and triaging alerts. Adoption in operational technology is slow for a healthy reason: a false positive can cost physical production.

Measurement is moving faster than doctrine. An artificial-intelligence agent placed in the top 10 of the Dragos operational-technology capture-the-flag in 2025, a tournament built for human specialists. And test benches have begun to appear that measure models in real industrial environments, such as CritBench on digital substations under the IEC 61850 standard.

None of that work touches the nomination and dispatch layer. That is: the literature measures substations and controllers, while the two Argentine incidents with a known affected system hit the commercial layer that schedules flow. At the same time, that commercial layer is where copilots and agents are arriving first, because it is the one with tabular data, written procedures and repetitive decisions.

This register does not answer what happens when an agent with write access operates there. It leaves the question posed on the only base that is proper: the incidents that already happened.

Fiction

Film imagined blackouts; the register shows encrypted servers

Six works shaped what the public expects an infrastructure attack to look like. Holding them against the rows above is the shortest way to measure the distance between the imagined and the documented.

The cases that do look like the movies exist, and they sit in the international table: Ukraine in 2015, 2016 and 2022, the Saudi plant in 2017. All of them are state operations with formal indictments behind them; none belongs to the criminal economy that produced the Argentine rows. Fiction trained the public to fear the blackout. The risk documented here is duller, cheaper and closer: an encrypted server, a stolen invoice, a countdown reaching zero on a Tor site.

Limits

What these data cannot support

It cannot be said that these fourteen are all there are. They are the ones that left a public trace, and the register itself shows that the trace depends on whether the attacker chose to publish and whether the company is listed. An incident resolved quietly, with no exfiltration and no listing, appears neither here nor anywhere.

It cannot be said that the eight medium-confidence rows happened the way the attacker tells them. A ransomware group publishes victims to apply pressure, and has an incentive to exaggerate the reach, the volume and the sensitivity of what it took. What is verifiable is that the publication exists, not what it says.

Nothing can be said about the state of security of any of these organizations. Appearing in the register means they were attacked, not that they were unprepared; several of them contained the incident with no service interruption. Absence from the register does not mean the opposite either.

It cannot be said that the groups in the cards are stable organizations. A name bundles operators who rotate, affiliates who switch platforms, and infrastructure that gets seized and reborn under another sign; two cards in this register may well be the same operator. Each status holds at its cutoff date, not after.

It cannot be said that the nomination and dispatch layer is the preferred way in. That is two cases with a known system, out of fourteen incidents. It is a hypothesis the available evidence makes reasonable, and one that needs checking with people who operate those systems.

The international table cannot be read as a census. It is a curated set of twelve cases under the criterion its section declares: the world had far more incidents than these, and the selection picked them because they illuminate Argentine findings, not because they represent anything.

And the rules section cannot be taken as legal opinion. It describes texts in force as of August 3, 2026, several of them moving (the permanent US pipeline rule is still a proposal, the ENRGE is still being stood up), and it does not judge whether other countries' rules work: it records only which obligation exists and which does not.

Roadmap

What is missing, and what would unlock it

Four open lines of work. Each one closes a concrete limit from the section above, and none of them needs anyone's permission to start.

Reference

The terms of this register, in order of appearance

Thirteen terms defined by what they do here, not by the dictionary. Each entry says in which section it first appears.

ransomware

A program that encrypts the victim's files and keeps them inaccessible until a ransom is paid. Since 2019 the term also names the groups that operate it, which usually steal the data before encrypting it. Appears in the register →

leak site

The attacker's storefront: a site, almost always on the Tor network, where the group publishes its victims and a sample of what it took, to press for payment. Seven rows of this register exist only because they appeared there. Appears in the register →

material event (CNV and AIF)

The filing an issuer of stock or debt submits to the Comisión Nacional de Valores when something happens that could affect its securities; it becomes public on the Autopista de la Información Financiera (AIF). It is the channel through which the sector's only two reported incidents surfaced. Appears in disclosure →

IT / OT

Information technology (IT) manages data: email, invoicing, spreadsheets. Operational technology (OT) controls physical processes: valves, pumps, substations. Industrial security practice is organized around that boundary, and this register documents systems that fall straight through it. Appears in the line →

nomination and dispatch layer

The systems where how much gas or crude moves through a transport network gets requested, allocated and scheduled: they turn contracts into scheduled physical flow. Administrative on the org chart, operational in practice. The term is this register's own. Appears in the line →

operator interface (HMI) and process historian

The HMI is the screen from which an operator watches and commands a plant; the historian is the database that stores each sensor's time series. Industrial software running on ordinary computers, which is why it shows up on some ransomware's process kill list. Appears in the line →

attribution

Determining who carried out an attack. Public forensic proof is rare: most criminal attributions come from a group publishing the victim on its site, which proves it claims the attack, not that it did it. Appears in provenance →

RaaS and affiliates

Ransomware as a service: a platform rents out the encryptor, the leak site and the brand; affiliates do the intrusion and share the proceeds. It explains how one sign can be behind attacks of very different skill. Appears in the groups →

double extortion

Stealing the data before encrypting it, to charge twice: for decryption and for silence. It turned backups into an incomplete defense, because restoring systems does not stop the leak. Appears in the groups →

exfiltration

Copying data out of the victim's network, before encryption in double extortion. In several documented cases it takes hours, not weeks. Appears in the groups →

SCADA

Supervisory control and data acquisition: the system that concentrates remote operation of a power, gas or water network. Driving it remotely is exactly what happened in Ukraine in 2015. Appears in context →

SIS, safety instrumented system

The autonomous controllers that take a plant to safe shutdown when the process leaves its range: the last barrier before the physical accident. The 2017 Triton case is the only publicly documented attack on that layer. Appears in context →

CERT

A computer emergency response team, national or sector-wide. Denmark's detected a sweep against 22 operators within days because it had sensors on its members' networks; Argentina's, CERT.ar, cannot demand a report from a private company. Appears in context →

Resources

Where to look, besides here

Thirteen entries, each with its purpose stated. Whatever does not serve a reader of this register stayed out: four organizations whose cyber work is members-only or nonexistent were cut.

Tracking and response

Technical reference

Learning and community

How it is made

Sources, updates and corrections

Rows come through three channels. The specialized press, the organizations' own communications and the material-event filings to the CNV give seven rows, of which six reach high confidence: YCRT stays at medium because its only source is a secondary compilation. The sites where ransomware groups publish their victims give the other seven, and are consulted through the public interface of ransomware.live, which as of August 3, 2026 lists 178 posts about Argentine victims across all sectors. The leak-site addresses are on record and are not published.

A monitor runs against that same interface, crosses every new Argentine victim against a sector lexicon and flags when a row needs writing. The row itself is written by hand: no endpoint returns what the company declared, and that column is half the value of the register.

The CNV sweep ran over the public filing sheets of the Autopista de la Información Financiera: 30 energy issuers, some 44,000 filings since 2000, scanned by title in two lexicon passes, plus a row-by-row manual review in the windows of the incidents already known. The method's limit sits in the title: a cyber material event with an opaque heading goes undetected, and there are issuers that title theirs "HR" and nothing else. The attachments were not read; that is the first item on the roadmap.

Corrections that arrive are applied to the row and dated in the correcciones array of the data file, with what changed and who flagged it. Nothing is edited silently. The request is above, with the address: back to the notice.

Who is behind this

Matías Podeley. An ITBA engineer, eighteen years in energy: four in operations in Neuquén, simulation of giant fields like Camisea, appraisal of petrochemical projects, technical backing of asset purchases above US$ 300 million, and five years teaching project appraisal. The craft behind this site: understanding the business need, and building the project or the tool that answers it, with AI and auditable sources. Buenos Aires.