Cybersecurity · Energy and critical infrastructure · Argentina
The sector learns what happened to it from whoever attacked it
Between 2020 and 2026, fourteen cyber incidents were documented across Argentine energy and critical infrastructure. Seven of them became known neither through the company nor through a regulator: they became known because the attacker published its victim on a leak site. There is no sector reporting duty, no peer-sharing mechanism, and no one has an inventory of what the sector exposes to the outside. These three pieces measure that gap from open sources, scanning no one.
-
What happened to the sector, row by row: date, subsector, actor and a source for each, with what the organization declared and what the attacker claimed in separate columns. It includes cards for the eleven groups, the international context and the state of the legal landscape.
Open register · fourteen cases · CC BY 4.0
-
Where each incident lands on the system around it: the physical structure of gas and power, how many nodes are stranded when each point falls, the sector's internet footprint in aggregate, and who would have to respond.
superficie.podeley.ar · interactive
-
What it would take to stand up a sector cybersecurity center here: how the Danish model works, what it actually cost to launch the US oil and gas ISAC, and a scheme of budget, dues and two draft regulations.
podeley.ar/en/isac · model, cost and rule
Why it matters
What breaks is not the power, it is the scheduling
The popular image of a cyberattack on energy is the blackout, and it is not what the Argentine cases show. In the two incidents where the affected system is known, the target was the layer that turns contracts into scheduled physical flow: nomination and dispatch. The pipe stays full and the gas keeps moving, but scheduling falls back to phone and spreadsheet, balances are reconstructed afterwards, and imbalance penalties end up in dispute. On the org chart that layer counts as administrative and in practice it is operational, which leaves it just outside the focus of the distinction the whole practice of industrial security is built on.
The institutional gap explains the rest. The State runs a critical-infrastructure cybersecurity program financed by the Inter-American Development Bank, with a 9% baseline measured in 2021 and a 50% target for 2028, and inside it a private-sector information-sharing output that is budgeted and unexecuted. On the other side, the pieces for seating a sector table have existed since 1992: the companies you would convene are already partners with one another in running electricity dispatch.
Meanwhile every operator faces the same groups one at a time, without knowing what worked for the last one. That is what these three pieces try to make visible: what happened, what is exposed, and what could be built.
Every new row and every correction to the register goes out through the Atom feed. If an incident is missing or something is wrong, emailing with the source is enough to get it corrected.