At the end of September 2026, Argentina's government opened an investigation after dark-web posts in which a group of attackers claimed to have breached the Mi Argentina application and stolen the personal data of six million citizens. The claim is unverified, and the government has published no findings. This article does not assume the breach happened. It asks what the episode shows about concentrating citizen services in one government app.
The case for a single state app
The argument for Mi Argentina is serious. The government describes it as a way to reach the state's digital services "con una única sesión y en un sólo lugar": one login for procedures, appointments and credentials. For a country with long queues, patchy offices outside Buenos Aires and a history of paper bureaucracy, one well-run app can cut costs and widen access. A single point of identity can also be defended better than dozens of ministry portals, each with its own weak password reset flow. Consolidation is not the problem in itself.
What the record shows
The problem is that the app's security has not been demonstrated, and the public record is thin. We do not know whether the six-million claim is true, inflated, or recycled from earlier leaks. Attackers on dark-web forums routinely overstate their hauls. Skepticism is warranted, and so is the demand that the state settle the question quickly.
We do know of one earlier, confirmed incident. In December 2024 the government said it had detected a hack affecting 12,976 Mi Argentina users, mainly older people. The exposed data included DNI numbers, addresses, email addresses, nationalities and postal codes. Officials said the platform's central database was not breached and that the attack reached users through their own phones, "por afuera de la base de la aplicación". They also put the platform at more than 20 million users.
That official account has a limit. Whether the compromise happened at the server or the handset, the harm to the citizen is the same: a stolen national ID number tied to an address. The distinction matters for assigning blame. It matters less for deciding how much trust a mandatory channel deserves.
The legal duty already exists
Argentina does not need a new statute to hold the state to account. Article 9 of Ley 25.326 on personal data protection, enacted in 2000, requires the data controller to adopt the technical and organisational measures needed to ensure the security and confidentiality of personal data and to prevent unauthorised processing. The state is a controller like any other.
The weakness is in what follows. The law is a quarter-century old. According to a secondary summary of the legal landscape, it does not require breach notification, and a reform bill that would add it has been pending. We have not been able to confirm that summary against the statute's current text, so treat it as indicative. Even so, the practical consequence is clear. Whether citizens learn of a breach promptly depends on the government's goodwill, not on a legal duty.
A separate episode shows how the app's data can be repurposed. In 2021 the civil-society group ADC objected that Mi Argentina users had received political messaging, arguing that the app's terms did not cover it and that people had downloaded it to use state services. The two episodes differ, but they share one lesson: when one app holds identity, credentials and a messaging channel, every weakness in how it is governed carries over to the whole system.
Where proportion matters
There are two ways to respond, and one of them is wrong.
The wrong response is to abandon digital government. Paper identity documents are lost, forged and stolen too, and citizens who cannot get through a digital channel are already excluded from a growing share of services. Fear of breaches should not freeze useful infrastructure.
The right response is to make the state earn its mandate. A proportionate rule would tie any move to require, or strongly steer, citizens into the app to demonstrable security and clear fallbacks:
- Publish findings. The government should say what it has established about the six-million claim, including whether any records match real accounts, and should do so on a stated timeline.
- Notify on a statutory clock. Affected users should be told within a fixed period, as private firms increasingly must be in other jurisdictions.
- Commission independent audits. An external security review, with a public summary, should precede any expansion of what the app holds, such as a driver's licence or digital ID.
- Keep non-digital routes open. Nobody should lose access to a service for declining to use the app.
- Minimise what is stored. The fewer fields the app retains, the less a breach can expose.
The test
A free-speech and pro-innovation position does not mean trusting whoever holds the database. Governments that want citizens to rely on digital tools should be held to the standard they would impose on a private bank: secure systems, honest disclosure, and no coercion into a single channel. If the investigation clears the app, publishing the evidence will strengthen the case for consolidation. If it does not, the mandate should wait. Either way, the burden of proof sits with the state.