Argentina ransomware and cyber extortion policy

Argentina's Oldelval Cyberattack Disclosure Shows Securities Law, Not Cyber Law, Is Doing the Work

A ransomware hit on the pipeline carrying 75% of Vaca Muerta's crude surfaced via a stock filing, exposing a gap in Argentina's new cyber-incident rules.

The Gentlemen Hit Two Latin American Oil Majors in O… People of Internet Research · Argentina 75% Share of Vaca Muerta crude Oldelval's pipeline network carrie… ~300 Gentlemen claimed victims Across more than 66 countries sinc… 15 Ecopetrol companies breached Corporate-group entities whose clo… 68 CRI member nations Argentina joined the Counter Ranso… peopleofinternet.com
The Gentlemen Hit Two Latin American O… People of Internet Research · Argentina 75% Share of Vaca Muerta crude ~300 Gentlemen claimed victims 15 Ecopetrol companies breach… 68 CRI member nations peopleofinternet.com

Key Takeaways

A Stock Filing, Not a Cyber Alert

On July 31, Oleoductos del Valle (Oldelval) — operator of the trunk pipeline that carries roughly 75% of the crude produced in Vaca Muerta, Argentina's shale basin — told the Comisión Nacional de Valores (CNV) that its administrative systems had been hit by a cyberattack. The company called the filing a hecho relevante, the mechanism Argentine securities law uses to force listed and bond-issuing companies to disclose anything that could move a reasonable investor. Oldelval said the episode was "100% controlled," that crude transport never stopped, and that affected systems were restored (Infobae). A ransomware-as-a-service outfit calling itself The Gentlemen claimed the intrusion on social media.

That the public learned about a strike on critical energy infrastructure through a market-disclosure obligation, rather than a dedicated cyber-incident reporting channel, is the real story here — and it's worth asking whether that's an accident Argentina got lucky on, or a structural gap.

Who Hit Them

The Gentlemen is not a fringe actor. It split from the Qilin RaaS operation in mid-2025 after a payoff dispute, then began recruiting affiliates with a 90% revenue-share offer — among the most generous in the ransomware underground. Halcyon's threat researchers count nearly 300 claimed victims across more than 66 countries within roughly a year, with monthly attack counts nearly doubling between January and February 2026 (Halcyon). One week before Oldelval, the same group claimed Ecopetrol, Colombia's largest oil company, exfiltrating cloud data from 15 companies inside Ecopetrol's corporate group before publishing it on a leak site (Infobae Colombia). Two major Latin American oil operators, one group, one week apart — that pattern, not any single filing, is what should concern regulators.

Where the Reporting Duty Actually Lives

Argentina has, on paper, moved to build a modern cyber authority. Decreto 941/2025 created the Centro Nacional de Ciberseguridad (CNC) as the country's governing body for cyberspace protection, critical information infrastructure, and the digital systems behind essential public services; Decreto 92/2026 installed its leadership in February. But read the decree closely: its incident-response mandate — running CERT.ar, maintaining a critical-infrastructure registry, coordinating response — is scoped to the national public sector (Decreto 941/2025, Boletín Oficial; CNC mission page). A privately held pipeline operator like Oldelval has no statutory duty to report an intrusion to the CNC or CERT.ar. It reported to the CNV because it has bonds outstanding, not because a pipeline carrying three-quarters of a strategic export basin's output is, self-evidently, critical infrastructure.

The Case for Mandating More — and Why Argentina Should Wait

The argument for closing that gap fast is a strong one. Vaca Muerta is central to Argentina's export ambitions under the RIGI investment regime, and Oldelval's own systems will only grow more interconnected with operational technology as throughput expands — an administrative breach today is a discovery process for an OT breach tomorrow. Regulators in the US and EU have already concluded that voluntary, market-driven disclosure is too slow and too partial: CIRCIA in the US and NIS2 in the EU both impose mandatory, short-fuse (often 24–72 hour) incident reporting on designated critical-infrastructure operators specifically because securities disclosure only catches breaches material enough to move a stock price, not the reconnaissance and near-misses that matter for threat intelligence.

But Argentina is not the US or the EU, and the CNC is barely six months old with a director named in February 2026. Layering a NIS2-style mandatory reporting regime, with its compliance audits and penalty schedules, onto private operators before the CNC has the staff to receive and act on that intelligence would produce paperwork, not security — a familiar failure mode where the compliance burden lands on the still-developing state's timeline, not the threat's. Argentina has the better first move already available: it joined the International Counter Ransomware Initiative, a 68-member coalition built around threat-intel sharing and capability-building, in August 2024 (CRI 2024 Joint Statement). Building CERT.ar's private-sector liaison function and using CRI channels to pull in allied threat intelligence costs far less than standing up a new compliance regime, and it doesn't require the CNC to have enforcement muscle it doesn't yet have.

What Should Happen Next

The fix isn't to ignore the gap — it's to sequence it correctly. Decreto 941/2025 already instructs the CNC to build a critical-infrastructure registry; formally designating Oldelval and its peers onto that registry, with a voluntary-to-mandatory reporting glide path tied to CNC capacity milestones, would close the loophole without importing a compliance regime built for larger, better-resourced regulators. What Argentina should firmly resist is the reflexive alternative — a blanket ban on private-sector ransom payments modeled on the CRI's public-sector pledge. Without a functioning mandatory-reporting backbone first, a payment ban would only push operators to pay quietly and never disclose at all, which is a strictly worse outcome than the CNV filing that, however incidentally, let the public learn what happened here within days.

Sources & Citations

  1. Decreto 941/2025 — creation of the Centro Nacional de Ciberseguridad
  2. Centro Nacional de Ciberseguridad — mission page
  3. International Counter Ransomware Initiative 2024 Joint Statement
  4. Infobae — Oldelval cyberattack disclosure
  5. Infobae Colombia — Ecopetrol breach response
  6. Halcyon — Threat Assessment: The Gentlemen Ransomware Group