Sector register · Energy and critical infrastructure · Argentina
Thirteen incidents in six years, and eight of them never got a single published line
This is the register of known cyber incidents across Argentina's energy sector between 2020 and 2026, with a source for every row. It is built by crossing press coverage, filings to the Comisión Nacional de Valores (CNV, the securities regulator) and the sites where attackers publish their victims. It records what happened and what was said to have happened, in separate columns, because in several cases the two do not match.
The register
What happened to the sector, row by row
Thirteen incidents across energy and critical infrastructure, from June 2020 to August 2026. The confidence column says where each row comes from: high when the organization, a regulator or press with direct sources confirmed it; medium when the attacker's notice is all there is.
| Date | Organization | Subsector | Actor | How it surfaced | Confidence |
|---|---|---|---|---|---|
| 2020-06-07 | Edesur (Enel Argentina) | Power distribution | Snake / EKANS | Press | high |
| 2022-04-05 | Transportadora de Gas del Sur (TGS) | Gas transport | Unattributed | Press | high |
| 2023-02-14 | Grupo Albanesi | Generation and marketing | LockBit 3.0 | Leak site | medium |
| 2023-07-13 | BTU S.A. | Energy services | 8Base | Leak site | medium |
| 2024-06-13 | Amarilla Gas | LPG distribution | Play | Leak site | medium |
| 2024-12-18 | Comisión Nacional de Energía Atómica (CNEA) | Nuclear | Money Message | Press | high |
| 2025-01-04 | Hidrocarburos Argentinos (HASA) | Upstream | ElDorado | Leak site | medium |
| 2025-02-04 | 360 Energy | Solar generation | Akira | Leak site | medium |
| 2025-05-16 | Hidrocarburos Argentinos (HASA) | Upstream | BlackLock | Leak site | medium |
| 2025-05-27 | Yacimientos Carboníferos Río Turbio (YCRT) | Coal | Unattributed | Press | medium |
| 2025-11-26 | Electricidad Panamericana | Electrical services | Dire Wolf | Leak site | medium |
| 2025-12-14 | AySA | Water and sanitation | SafePay | Leak site | medium |
| 2026-07-23 | Oleoductos del Valle (Oldelval) | Crude transport | The Gentlemen | Leak site, then CNV | high |
→ the table scrolls sideways
Hidrocarburos Argentinos appears twice, five months and two different groups apart. Neither appearance got any coverage. AySA is not energy: it is included because it is an essential service with operational technology and millions of users, which is the category that matters here.
The full data, with what each organization declared, what each attacker claimed and the sources behind every row: ciber-incidentes.json.
Finding
The sector finds out from the attacker, or not at all
Of the thirteen incidents, eight are known only because the group that attacked chose to publish its victim. No statement, no article, no obligation to say anything.
The Oldelval case measures the gap precisely. The group The Gentlemen posted the company on its site on July 23, 2026; the material-event filing to the CNV and the first press pieces are dated August 2. For ten days the information existed and circulated, on the attacker's side. Nobody had it on the other side: not the market, not the operators who ship through that same pipeline.
The detail that orders everything else is which channel it was. Oldelval reported to the CNV, the capital-markets regulator, because it is listed and a material event must be filed. No equivalent duty exists toward any energy regulator. A sector company that is not listed and gets no phone call owes nobody an account of having been compromised — and eight rows of this register show that, indeed, it gives none.
The consequence is that no operator learns from its neighbor's incident. The sector has no peer information-sharing mechanism of the kind other countries run for electricity and for oil and gas. Each company faces the same groups, one at a time, without knowing what worked for the previous one.
Finding
"Administrative systems only" does not mean what it seems to
It is the phrase that appears in nearly every disclosure in this register. Worth looking at which system it actually was, in the two cases where that is known.
At TGS the attack hit SPAC, the platform that processes requests, allocation and scheduling of gas volumes across the pipeline network. Nobody moves a valve from there. What gets decided from there is how much gas enters, whose it is, and where it goes. An oil pipeline has an equivalent layer for crude nomination and balance, and it serves the same purpose: it is what turns contracts into scheduled physical flow.
That layer is administrative on the org chart and operational in practice. When it goes down, the pipe stays full and the gas keeps moving, but scheduling falls back to phone and spreadsheet, balances are reconstructed afterwards, and imbalance penalties end up in dispute. The distinction between information technology and operational technology, which structures the whole practice of industrial security, lets the system that decides dispatch fall straight through the middle.
The 2020 Edesur incident points at the other side of the problem. The ransomware was Snake, also known as EKANS, which ships with a list of industrial processes it terminates before encrypting, operator-interface programs and process historians included. There is no public evidence that this capability was exercised at Edesur, and this register does not claim it was. What can be said is that the family carries it by design, and that it reached an Argentine power distributor in June 2020.
Finding
The sector's most-cited incident is its worst documented
TGS is the case that shows up in every Argentine timeline of cyber incidents. It is also the one that least survives verification.
The two professional compilations that record it classify it as denial of service. In parallel there circulates an attribution to the ALPHV/BlackCat group that I found no way to support: TGS is not among that group's 731 listed victims, and the article usually cited as backing covers Creos Luxembourg, a Luxembourg gas and power utility, with no mention of Argentina. They appear to be two distinct events that at some point fused into one.
That is why the TGS row stands unattributed, and why this register separates confidence that the incident happened from confidence in who did it. A sector that debates its exposure on the strength of a case whose authorship nobody verified is not debating on data.
What comes next
The layer being added right now
Everything above describes a sector with poor visibility into its own exposure. On top of it, something else is being mounted.
On the offensive side, artificial-intelligence agents already compete in industrial security: one of them placed in the top 10 of the Dragos operational-technology capture-the-flag in 2025, a tournament built for human specialists. On the defensive side, test benches have begun to appear that measure what models can do in real industrial environments, such as CritBench on digital substations under the IEC 61850 standard.
None of that work touches the nomination and dispatch layer. That is: the literature measures substations and controllers, while the two Argentine incidents with a known affected system hit the commercial layer that schedules flow. At the same time, that commercial layer is where copilots and agents are arriving first, because it is the one with tabular data, written procedures and repetitive decisions.
This register does not answer what happens when an agent with write access operates there. It leaves the question posed on the only base that is proper: the incidents that already happened.
Limits
What these data cannot support
It cannot be said that these thirteen are all there are. They are the ones that left a public trace, and the register itself shows that the trace depends on whether the attacker chose to publish and whether the company is listed. An incident resolved quietly, with no exfiltration and no listing, appears neither here nor anywhere.
It cannot be said that the eight medium-confidence rows happened the way the attacker tells them. A ransomware group publishes victims to apply pressure, and has an incentive to exaggerate the reach, the volume and the sensitivity of what it took. What is verifiable is that the publication exists, not what it says.
Nothing can be said about the state of security of any of these organizations. Appearing in the register means they were attacked, not that they were unprepared; several of them contained the incident with no service interruption. Absence from the register does not mean the opposite either.
And it cannot be said that the nomination and dispatch layer is the preferred way in. That is two cases with a known system, out of thirteen incidents. It is a hypothesis the available evidence makes reasonable, and one that needs checking with people who operate those systems.
How it is made
Sources, updates and corrections
Rows come through three channels. Argentina's specialized press and the organizations' own communications give five rows, of which four reach high confidence: YCRT stays at medium because its only source is a secondary compilation. The sites where ransomware groups publish their victims give the other eight, and are consulted through the public interface of ransomware.live, which to date lists 178 Argentine victims across all sectors. The leak-site addresses are on record and are not published.
A monitor runs against that same interface, crosses every new Argentine victim against a sector lexicon and flags when a row needs writing. The row itself I write by hand: no endpoint returns what the company declared, and that column is half the value of this.
Corrections that arrive are applied to the row and dated in the correcciones array of the data file, with what changed and who flagged it. Nothing is edited silently. The request is above, with the address: back to the notice.
Who is behind this
Matías Podeley. Eighteen years in energy — reservoir engineering, then business development, mostly on the side that hires the specialists. I build these tools myself, with public data and AI. Buenos Aires.
The AI-safety research behind the last section: research.