🚨 🇦🇷 PREVENTIVE ALERT: ALLEGED COMPROMISE AND EXFILTRATION OF SENSITIVE DATA UNDER EVALUATION — DEFENSE SECTOR / ARMED FORCES (ARGENTINE ARMY)
[STATUS: UNCONFIRMED / ALLEGED EXFILTRATION AND FREE RELEASE / SOURCE: UNDERGROUND FORUM / DATE: JULY 31, 2026]
THE "ESQUELESQUAD" COLLECTIVE ANNOUNCES THE RELEASE OF FINANCIAL DATA, CREDENTIALS, AND MORE THAN 120,000 LIFE INSURANCE POLICIES BELONGING TO THE ARGENTINE ARMY (https://t.co/0VrpSKDlvi)
Through perimeter technical monitoring of cybercriminal forums, a post made by the actor Skull1172 on behalf of [the group] has been detected. From the EsqueleSquad collective. In the announcement, the group claims to have compromised the web infrastructure, databases, and administrative portals of the Argentine Army (https://t.co/GRmHM8l64H).
The collective asserts it possesses a compressed batch of 218,704 files (approximately 4.96 GB in size) that includes credentials for administrative panels and military personnel files. They announce they will make the material publicly available free of charge through their Signal messaging channel. The signal is classified as strictly precautionary and unconfirmed, remaining under evaluation to determine the authenticity and validity of the exposed files.
🗂️ BREAKDOWN OF ALLEGEDLY EXPOSED ASSETS AND RECORDS
According to the manifesto and the documentary samples shown in the attached screenshots:
Affected Entity: Argentine Army (https://t.co/GRmHM8l64H / Army General Accounting Office).
Threat Group: EsqueleSquad (Actor: Skull1172).
Lot Size: 218,704 PDF files (~4.96 GB) | 130 administrative credentials | ~120,000 Group Life Insurance Policies.
Compromised Databases and Credentials:
The Mil_argentina.db database containing institutional emails, usernames, and hashed passwords (SHA-256).
Access to the application administration panel
Sensitive Identifiable Information (PII/Financial):
Personal Data: Full names, CUIT/CUIL (Argentine Tax ID), date of birth, home address, city/town, and holographic/digital signatures.
Military and Employment Data: Date of entry into the armed forces, status (soldiers, students, administrative staff), and budget allocation/position.
Financial and Beneficiary Data: Bank account numbers (CBU), bank details, insured capital, and beneficiary designation forms.
🛡️ PREVENTIVE TECHNICAL RECOMMENDATIONS FOR CONTAINMENT (SOC / DEFENSE HARDENING)
🛑 Mass Reset of Credentials and Session Invalidation (Immediate Action): Force the immediate reset of passwords for all users listed in Mil_argentina.db and revoke access/session tokens
🔑 Subdomain and Exposed Infrastructure Audit: Inspect access logs on the General Accounting Office's subdomains (seadea, sigehhmm, sitm3) to identify the entry vector used (web vulnerabilities, webshells, or leaked credentials).
🛡️ Implementation of Spoof-Resistant MFA: Require mandatory multi-factor authentication (MFA) on all webmail platforms, VPNs, and military administration panels.
📊 CENTRALIZED THREAT MONITORING SYSTEM
Intelligence System: https://t.co/wk9bZJ2Nli
Monitoring Console: https://t.co/5LuqwzYuS6
#CyberSecurity #Argentina #ArgentineArmy #EsqueleSquad #DataLeakClaim #PIIExposure #MilSec #PreventiveAlerts #ThreatIntelligence #CyberAlert #VECERT #Infosec #UnverifiedIncident
❌ Adiós a los días de 24 horas en la Tierra: a partir de esta fecha todos los días tendrán 25 horas.
🌔 La influencia de la Luna sobre las mareas terrestres estaría provocando el alejamiento del satélite y el alargamiento de los días en la Tierra https://t.co/3v0gQk8r4j
🇦🇷 Argentine Government Credentials Allegedly Offered for Sale on Dark Web
A threat actor is advertising what they claim is a bundle of active login credentials for 21 Argentine government platforms.
According to the listing, the package allegedly includes verified access to multiple government portals spanning public administration, judicial services, taxation, municipal systems, and internal communications. The actor claims the credentials are active and ready for use, though no independent evidence has been provided to verify these assertions.
Some of the referenced platforms include:
* AFIP (Tax Authority)
* PJN SSO (Judiciary)
* DNRPA
* RRHH GBA
* Municipalidad de Neuquén
* Webmail services
* Additional provincial and municipal government portals
At the time of writing, there is no public confirmation from Argentine authorities that these credentials are genuine or that any of the listed systems have been compromised.
* Country: Argentina 🇦🇷
* Alleged targets: 21 government platforms
* Alleged access: Active government login credentials
* Status: Unverified claim
Analyst Note: If authentic, access to legitimate government accounts poses a significantly higher risk than leaked databases, potentially enabling unauthorized access to sensitive information, internal communications, and administrative systems. Organizations should immediately review authentication logs, reset affected credentials, and enforce phishing-resistant MFA where possible.
#DDW #Intelligence #DarkWeb #Argentina
🚨 The Gentlemen Ransomware claims 18 victims
🇺🇸 Dash Door & Glass - A commercial door, glass, and architectural hardware supplier serving clients across South Florida.
🇬🇷 BDO Greece - A Greek audit, tax, accounting, and business advisory firm within the global BDO network.
🇫🇷 Carita - A French luxury skincare and beauty brand owned by L’Oréal’s Luxury Division.
🇺🇸 Lopes Law - A Philadelphia-based law firm specializing in franchise law and business legal services.
🇺🇸 Gene Codes Forensics - A forensic technology company providing DNA identification software and services for mass-disaster investigations.
🇪🇸 VASBE - A Spanish security company providing guarding, surveillance, alarm monitoring, and protection services.
🇺🇸 Welders Supply Equipment Rentals - A Pennsylvania-based supplier and rental provider of welding equipment, tools, and machinery.
🇺🇸 Pharma Wholesale - A Florida-based pharmaceutical wholesaler distributing prescription drugs, OTC products, vitamins, and medical supplies.
🇺🇸 Crossroads Medical Management - A Georgia-based company providing financial, clinical, and operational management services to senior-care facilities.
🇩🇪 INTERNET AG - A German IT services provider specializing in hosting, servers, managed infrastructure, and secure digital operations.
🇺🇸 Open Options - A Texas-based developer of open-architecture access-control and physical-security software.
🇨🇿 Energon - A Czech technology and energy group operating across engineering, telecommunications, renewable energy, and infrastructure.
🇮🇹 Vicenzi Group - An Italian confectionery company known for biscuits, pastries, and traditional baked sweets.
🇸🇬 Triquesta - A Singapore-based financial technology company providing collateral management software for commodity-finance operations.
🇨🇦 Aveiro Constructors Limited - A Canadian general contractor delivering industrial, commercial, institutional, and design-build construction projects.
🇦🇷 Martin Cava - An Argentine supplier of equipment, specialty papers, printable materials, and products for the graphics industry.
🇬🇧 Fortray - A UK-based IT training, recruitment, managed-services, and cybersecurity company.
🇦🇷 Ferretería Scopazzo - An Argentine hardware and industrial-tools retailer serving individuals and businesses.
𝗛𝗢𝗪 𝗗𝗢 𝗬𝗢𝗨 𝗛𝗔𝗖𝗞 𝗧𝗛𝗘 𝗣𝗘𝗡𝗧𝗔𝗚𝗢𝗡 𝗔𝗡𝗗 𝗚𝗘𝗧 𝗖𝗔𝗨𝗚𝗛𝗧 𝗕𝗬 𝗔 $𝟮𝟱𝟬 𝗧𝗥𝗔𝗡𝗦𝗔𝗖𝗧𝗜𝗢𝗡.
– Kai West was 25, British, and running the dark web's biggest stolen data marketplace under the name IntelBroker
– His victim list reads like a who's who. Apple. AMD. Cisco. Nokia. General Electric. Europol. The US Pentagon.
– And a database containing the personal information of every member of the US Congress.
– He sold everything in Monero only. Untraceable by design. For 2 years nobody could touch him.
– Then in January 2023 an FBI agent reached out to buy $250 worth of stolen data and talked him into accepting Bitcoin just this once
– That $250 went into a wallet tied to his real Coinbase account. Registered with his actual UK driver's license. His real name and his real face.
– The FBI spent the next 2 years quietly building the case. Matching his YouTube watch history to posts on his hacker forum. Piecing everything together.
– He even had a fake LinkedIn saying he worked at the UK equivalent of the FBI. They publicly said they had never heard of him.
– In January 2025 he stepped down from running the forum. Said he was "too busy."
– He was arrested in France 3 weeks later.
– $25 million in damage. 40+ companies. 2 years of running the biggest stolen data operation on the dark web.
Brought down by $250 and one moment of trusting the wrong coin.
The most untraceable hacker on the internet forgot that Coinbase needs your ID.
🇦🇷 A dataset allegedly linked to Argentina’s Ministry of Justice platform (https://t.co/SzKVkayXI8) is being advertised on a cybercrime forum.
* Threat actor claims the dataset contains citizen contact records, legal case applications, and customer interaction logs associated with Ministry of Justice services
* Alleged exposed data includes national ID numbers, names, email addresses, phone numbers, home addresses, dates of birth, nationality, and case-related information
* Listing references legal application records, review outcomes, case references, approval statuses, officer assignments, and communication logs
* Analyst Note: Government justice-sector databases are among the most sensitive targets in the underground economy. Beyond personal information, legal case records can expose highly confidential citizen interactions, creating risks ranging from identity theft and fraud to targeted harassment, blackmail, and intelligence collection activities.
#DDW #Intelligence #DarkWeb #Argentina
A Japanese manga artist lost his entire Google account forever after he uploaded private files from an old comic he drew to Google Drive.
Google’s AI checked the files and flagged them as not allowed. He asked Google to review it again, but they rejected his appeal and banned the account immediately.
He can no longer access years of his private drawings and lost access to many websites and services that used his Google login.
The artist said this is very embarrassing and causes him a lot of trouble. He warned that it might not happen to people who always follow every rule, but others should be careful.
So Google is scanning files that people upload to its cloud storage even if they are supposed to be private. I wonder how long they have been doing this.
Imagínense una red de trenes de alta velocidad con todas las capitales de Suramérica conectadas. Salgo el viernes en la tarde de viaje y llego a cualquier país en la mañana del sábado. Suramérica conectada tipo Europa.
I just stumbled upon this optical illusion,some of you might already be familiar with it.
I’m usually pretty good at these, but this one has me stumped; it just messes with my head.