A Stock Filing, Not a Cyber Alert
On July 31, Oleoductos del Valle (Oldelval) — operator of the trunk pipeline that carries roughly 75% of the crude produced in Vaca Muerta, Argentina's shale basin — told the Comisión Nacional de Valores (CNV) that its administrative systems had been hit by a cyberattack. The company called the filing a hecho relevante, the mechanism Argentine securities law uses to force listed and bond-issuing companies to disclose anything that could move a reasonable investor. Oldelval said the episode was "100% controlled," that crude transport never stopped, and that affected systems were restored (Infobae). A ransomware-as-a-service outfit calling itself The Gentlemen claimed the intrusion on social media.
That the public learned about a strike on critical energy infrastructure through a market-disclosure obligation, rather than a dedicated cyber-incident reporting channel, is the real story here — and it's worth asking whether that's an accident Argentina got lucky on, or a structural gap.
Who Hit Them
The Gentlemen is not a fringe actor. It split from the Qilin RaaS operation in mid-2025 after a payoff dispute, then began recruiting affiliates with a 90% revenue-share offer — among the most generous in the ransomware underground. Halcyon's threat researchers count nearly 300 claimed victims across more than 66 countries within roughly a year, with monthly attack counts nearly doubling between January and February 2026 (Halcyon). One week before Oldelval, the same group claimed Ecopetrol, Colombia's largest oil company, exfiltrating cloud data from 15 companies inside Ecopetrol's corporate group before publishing it on a leak site (Infobae Colombia). Two major Latin American oil operators, one group, one week apart — that pattern, not any single filing, is what should concern regulators.
Where the Reporting Duty Actually Lives
Argentina has, on paper, moved to build a modern cyber authority. Decreto 941/2025 created the Centro Nacional de Ciberseguridad (CNC) as the country's governing body for cyberspace protection, critical information infrastructure, and the digital systems behind essential public services; Decreto 92/2026 installed its leadership in February. But read the decree closely: its incident-response mandate — running CERT.ar, maintaining a critical-infrastructure registry, coordinating response — is scoped to the national public sector (Decreto 941/2025, Boletín Oficial; CNC mission page). A privately held pipeline operator like Oldelval has no statutory duty to report an intrusion to the CNC or CERT.ar. It reported to the CNV because it has bonds outstanding, not because a pipeline carrying three-quarters of a strategic export basin's output is, self-evidently, critical infrastructure.
The Case for Mandating More — and Why Argentina Should Wait
The argument for closing that gap fast is a strong one. Vaca Muerta is central to Argentina's export ambitions under the RIGI investment regime, and Oldelval's own systems will only grow more interconnected with operational technology as throughput expands — an administrative breach today is a discovery process for an OT breach tomorrow. Regulators in the US and EU have already concluded that voluntary, market-driven disclosure is too slow and too partial: CIRCIA in the US and NIS2 in the EU both impose mandatory, short-fuse (often 24–72 hour) incident reporting on designated critical-infrastructure operators specifically because securities disclosure only catches breaches material enough to move a stock price, not the reconnaissance and near-misses that matter for threat intelligence.
But Argentina is not the US or the EU, and the CNC is barely six months old with a director named in February 2026. Layering a NIS2-style mandatory reporting regime, with its compliance audits and penalty schedules, onto private operators before the CNC has the staff to receive and act on that intelligence would produce paperwork, not security — a familiar failure mode where the compliance burden lands on the still-developing state's timeline, not the threat's. Argentina has the better first move already available: it joined the International Counter Ransomware Initiative, a 68-member coalition built around threat-intel sharing and capability-building, in August 2024 (CRI 2024 Joint Statement). Building CERT.ar's private-sector liaison function and using CRI channels to pull in allied threat intelligence costs far less than standing up a new compliance regime, and it doesn't require the CNC to have enforcement muscle it doesn't yet have.
What Should Happen Next
The fix isn't to ignore the gap — it's to sequence it correctly. Decreto 941/2025 already instructs the CNC to build a critical-infrastructure registry; formally designating Oldelval and its peers onto that registry, with a voluntary-to-mandatory reporting glide path tied to CNC capacity milestones, would close the loophole without importing a compliance regime built for larger, better-resourced regulators. What Argentina should firmly resist is the reflexive alternative — a blanket ban on private-sector ransom payments modeled on the CRI's public-sector pledge. Without a functioning mandatory-reporting backbone first, a payment ban would only push operators to pay quietly and never disclose at all, which is a strictly worse outcome than the CNV filing that, however incidentally, let the public learn what happened here within days.