🚨 🇦🇷 CYBER INTELLIGENCE ALERT: SECURITY AND DEFENSE SECTOR — ARGENTINA
[STATUS: ALLEGED DATA COMPROMISE / UNCONFIRMED, EVIDENCE VISIBLE / SOURCE: TELEGRAM (vLeakz) / DATE: JULY 7, 2026]
THE ACTOR "SQX" CLAIMS EXFILTRATION OF THE ARGENTINE FEDERAL POLICE'S (PFA) OPERATIONAL AND PERSONNEL DATABASE
A direct escalation of attacks against the IT assets of the public security sector in the Southern Cone has been detected. The threat actor using the alias sqx has announced, through its Telegram broadcast channel, the compromise and complete intrusion into databases belonging to the Argentine Federal Police (PFA).
The attacker claims to possess the complete roster of executives, officers, and ranks of the force, openly stating that they will release a proof of concept (PoC) on the clandestine Spear platform.
🏢 Allegedly Affected Entity: Argentine Federal Police (PFA) — Ministry of Security.
👤 Threat Actor: sqx (Associated with the vLeakz/vnsleaks infrastructure).
⚔️ Technical Ecosystem According to the Actor: Relational database (allegedly structured in SQLite according to internal schemas) with tables of personnel files, operational areas, and detailed medical records.
🔍 Verification Status: UNCONFIRMED BY ARGENTINE AUTHORITIES. As of July 7, 2026, the Ministry of Security, the PFA Directorate, or the National Cybersecurity Directorate have not issued any institutional statements regarding a breach or contingency.
🗂️ ANALYSIS OF THE ANATOMY OF DIGITAL COMPROMISE
The leak would directly compromise the governance of data and personnel files of the force:
Exposed Table Structure (Tables (4)):
educational_entity_benefit: Record of benefit categories linked to force personnel.
medical_license: Health database that catalogs identifiers such as ID, rank, file number, last_name_first_name, CUIL (tax ID number), incident_number, incident_date, report_date, medical_discharge_date, discharge_type, and the physical unit of assignment.
personnel: The core PFA (Argentine Federal Police) personnel registry, structured with the fields ID, last_name, first_name, file number, and specific tactical deployment area.
Optimistic Fast Search Indices: Indexes such as idx_lic_legajo and idx_personal_legajo are detailed, demonstrating that the database was designed for quick cross-corporate searches.
🛡️ PREVENTIVE TECHNICAL RECOMMENDATIONS FOR CONTAINMENT (SOC/DEFENSE)
Argentine public sector incident response teams are urged to implement immediate defensive mitigation measures:
🛑 Identify Leaks in Human Resources and CIPRES/Health Applications: Trace API calls, web accesses, and bulk exports that occurred in the logical databases of occupational medicine or personnel files systems of the Argentine Federal Police (PFA) in recent weeks. Revoke compromised credentials and session tokens globally.
🔑 Segregation of Security Personnel Records: Completely isolate personnel files and tactical assignment servers from any network exposed to the public internet. All authorized queries must be processed in encrypted form over private internal networks and monitored by perimeter SIEM systems.
📊 THREAT MONITORING AND ASSESSMENT
Intelligence System: https://t.co/wk9bZJ2Nli
Monitoring Console: https://t.co/5LuqwzYuS6
#CyberSecurity #Argentina #PFA #FederalPolice #vLeakz #DataLeak #Sqx #PoliceFiles #MedicalLicense #Doxing #ThreatIntelligence #CyberAlert #VECERT #Infosec #UnverifiedIncident
🚨 🇦🇷 CYBER INTELLIGENCE ALERT FOR THE HEALTH SECTOR — ARGENTINA
[STATUS: ALLEGED / HIGH-IMPACT CAMPAIGN / UNCONFIRMED SOURCE: INTELLIGENCE PLATFORMS / DATE: JULY 6, 2026]
THE "CHRONUSTEAM" GROUP CLAIMS MASSIVE INTRUSION AND COMPROMISE IN 50 UNION AND PROVINCIAL HEALTH INSURANCE PROVIDERS
Through technical monitoring of criminal environments, an alert has been issued regarding one of the exfiltration attacks on the health system in Argentina. The leaking group known as CHRONUSTEAM claims to have simultaneously compromised the systems of 50 health insurance providers across the country (including union, national, and corporate mutual insurance funds, and almost all provincial medical institutes).
🏢 Allegedly Affected Entities: 50 medical and social security institutions, including: the social welfare organizations of the Light and Power Workers Union, YPF (the state-owned oil company), the Oil Workers Union, the Senior Staff Union, the Truck Drivers Union, the Metalworkers Union (UOM), the Banking Union, the Army (IOSE), OSPA (the provincial social welfare organization), Incluir Salud (PROFE), Osplad (the provincial social welfare organization), and the provincial social welfare organizations of La Pampa (SEMPRE), Formosa, Tierra del Fuego (IPAUSS), San Luis (DOSEP), Santa Cruz, San Juan, Río Negro (IPROSS), Jujuy (ISJ), Santiago del Estero (IOSEP), Corrientes (IOSCOR), Chubut (SEROS), Catamarca (OSEP), Neuquén (ISSN), Misiones (IPS), Entre Ríos (IOSPER), the City of Buenos Aires, and Salta (IPS).
👤 Threat Actor: CHRONUSTEAM.
⚔️ Data Ecosystem at Extreme Risk: Medical records, contributor affiliation records, medical billing data, prescriptions, member numbers, and personal information (PII).
🔍 Verification Status: NOT CONFIRMED BY ENTITIES IN ARGENTINA. As of July 6, 2026, the Superintendency of Health Services, provincial governments, or the corporate cybersecurity committees of the listed health insurance providers have not issued official statements acknowledging a chain intrusion. However, the alert is being processed under a national alert.
🛡️ PREVENTIVE TECHNICAL RECOMMENDATIONS FOR CONTAINMENT (SOC / INCIDENT RESPONSE)
The infrastructure departments and security directors of the affected Argentine social security organizations are urged to deploy an immediate contingency plan in response to this chain of threats:
🛑 Audit of Software Providers and Shared APIs: Due to the simultaneous nature of the report, it is recommended to forensically audit connections with external providers of medical clearing, online prescription validation, and integrated registry systems, isolating any compromised interfaces.
🔑 Session Invalidation and MFA Deployment: Force the closure of all active sessions on provider administration platforms and extranets. Mandatory implementation of Multi-Factor Authentication (MFA) to prevent the misuse of exposed administrative credentials.
📊 MONITORING AND EVALUATION
Intelligence System: https://t.co/wk9bZJ2Nli
Monitoring Console: https://t.co/5LuqwzYuS6
#CyberSecurity #Argentina #ArgentineHealth #HealthInsurance #ChronusTeam #DataLeak #SuperintendenceOfHealth #ProvincialHealthInsurance #DataBreak #ThreatIntelligence #CyberAlert #VECERT #Infosec #UnverifiedIncident
🚨 CYBER INTELLIGENCE ALERT: PROBABLE SALE OF BANKING DATABASE — ARGENTINA 🇦🇷
💥 THREAT ACTOR LISTS RECORDS OF 750,000 BBVA ARGENTINA PREMIUM CREDIT CARD CUSTOMERS FOR SALE
[STATUS: THREAT UNDER INVESTIGATION / UNCONFIRMED / CLANDESTINE CHINESE MARKETPLACE]
A threat actor identified by the obfuscated alias F****3 has announced—on a Chinese-origin underground data marketplace—the exclusive sale of a massive database attributed to high-end credit card customers of Banco Bilbao Vizcaya Argentaria Argentina (BBVA Argentina).
The actor claims the repository consolidates personal information on 750,000 premium cardholders (Gold, Platinum, Black, and International categories), obtained via direct intrusion techniques.
🏢 Allegedly Affected Entity: BBVA Argentina (https://t.co/LRibAKOeZn).
👤 Threat Actor: Seller registered under ID F3.
⚔️ Potential Attack Vector: Exfiltration via infiltration of relational databases (SQL Injection or compromised credentials) within loyalty systems, account statement generation platforms, or premium customer service portals.
🔍 Verification Status: SUSPECTED / UNCONFIRMED. The intrusion into the bank's central servers remains under investigation and preventive audit. However, this alert is supported by a high level of structural evidence due to the exposure of plaintext samples indexed on June 16 and 17, 2026.
📈 1. Timestamp Assessment (Last Access / Modification Dates)
Data Freshness (June 2026): The final column of the data dump reveals detailed timestamps corresponding to very recent dates within the current month. Consecutively dated records are observed between June 9, 2026, and June 15, 2026 (e.g., row 6: 15/06/2026 04:23:10 am; row 2: 13/06/2026 11:36:19 pm; row: 15/06/2026 09:13:23 am).
Date Conclusion: The timestamps align perfectly with the release date declared by the attacker (June 16). This indicates a high level of authenticity, demonstrating that the file is not a repackaging of historical leaks, but rather a compilation or active extraction carried out during the first half of June 2026.
📊 2. Internal Consistency and Data Structure (Data Integrity)
Identifier Validation (Banking Series IDs): The sequential numbers accompanying the card details begin with... From a technical-operational standpoint, the prefix "54" corresponds to Argentina's international telecommunications code, followed by the indexing structure typical of telephony databases or regional customer profiles.
Premium Segmentation Correlation: The variables in the card-type column correspond exactly to BBVA's Argentine financial market, listing valid classifications such as "Visa Platinum and Mastercard Platinum cards," "Visa Gold and Mastercard Gold cards," and "Visa Signature and Mastercard Black."
Actual Service Usage: All records in the sample show the variable "Normal use," indicating that these are active production accounts rather than developer test or staging environments.
Authentic Names and Emails: Name structures perfectly aligned with the regional context are detected, combined with email addresses from common and local domains, such as .com.ar. ⚠️ RISK ANALYSIS REGARDING THE EXPOSED DATA FIELDS
If the illicit use of this batch of 750,000 cleaned records takes hold, the criminal implications for financial users in Argentina are severe:
👤 Identity Theft and High-Value Customer Profiling: The file consolidates and exposes Full Name, Gender, Date of Birth, and Email Address. By identifying which customers hold "Black" or "Signature" cards, attackers obtain a list of targets with high purchasing power.
🛡️ TECHNICAL RECOMMENDATIONS AND PREVENTIVE MITIGATION
🛑 Immediate Activation of the Entity's IR Protocol (Corporate Action): BBVA Argentina's security incident response team (CSIRT) is urged to initiate an in-depth forensic audit of all relational database queries executed between June 1 and June 15, 2026, identifying potential mass data leaks via compromised third-party access points or telemarketing APIs.
📊 MONITORING AND EVALUATION
Intelligence System:
https://t.co/wk9bZJ2Nli
Quickly assess your website's security at:
https://t.co/QZhWp0kFrO
#CyberSecurity #Argentina #BBVA #BBVAArgentina #DataLeak #CreditCardLeak #FinancialFraud #IdentityTheft #PremiumCards #ThreatIntelligence #CyberAlert #VECERT #Infosec #UnverifiedBreach
@Elpablito78 No me cierra el numero por 35% en negro mas no vale la pema moverse. No le pagas prepaga? Ya con eso si se lo tiene que pagar él pierde plata
@Supremadel5toj@charriceclurxs 3 años imvirtiendo en fondos y me termine pagando 15 dias de vacaciones en cordoba. Tener lingote ya no es para cualquiera antes ni ahora
@ivangseg@PonzistaAnti Es asi, tengo un amigo gana 10M mensuales en mano y debe guita todo el tiempo. Mi novia es docente doble turno y gana 1.3M y vive, como se puede pero vive o sobrevive. Deja de comprar carne de vaca y compra de cerdo y asi como todos papsan de 1era a 2da o 3era marcas
@Supremadel5toj@charriceclurxs No, es que hubo una pesificacion asimetrica. Solo algunos activos en usd (que no era tan facil tenerlos como ahora) no fueron pesificados