Discovered
2026-08-04 00:24 UTC
Est. attack date
2026-08-03
Country
Sector
Agriculture and Food Production
Education
Energy & Utilities
Financial Services
Government & Defense
Healthcare
Hospitality
Manufacturing
Other
Professional Services
Retail & E-Commerce
Technology
Transportation
Duplicate Entry
This victim has been identified as a duplicate of another entry in our database. However, this may not always be the case: the same organization can be targeted multiple times by the same or different ransomware groups, which may result in separate legitimate entries.
Search for related entries
Description:
During the analysis of data obtained from Oldelval, we have compiled information covering key aspects of the company's operations. The materials include:
1.HR documentation: full payroll data, bank account details (CBU), employee health insurance records (OSDE, SWISS MEDICAL), as well as severance calculations and compensation agreements.
2.Financial and regulatory reports filed with CNV and BYMA, including documents related to rating agencies (Moody's) and internal shareholder agreements.
3.Tax declarations and reports submitted to AFIP (Sicore, Ganancias, DDJJ IVA).
4.Documents related to tariff policy and SEN interactions, including WACC and TIR calculations used in tariff reviews.
5.Incident reports and environmental documentation, including reports on spills in Catriel and Medanito, as well as Rosen OSSR technical reports on pipeline conditions.
6.Confidentiality agreements with key partners, including Halliburton, Horizon, YPF, Otasa, McKinsey, and KPMG.
7.Internal whistleblower channel materials (Ley 27.401), including internal complaints and compliance reports.
8.Documents related to dividend payments and banking transactions.
9.Personal data of directors, candidates, and key employees, including ID numbers and CVs.
Infostealer activity detected by HudsonRock
Compromised Employees: 4
Compromised Users: 8
Third Party Employee Credentials: 6
External Attack Surface:
25
DNS Records:
The following DNS records were found for the victim's domain.
- nu88u68d7jdnetworksolutionsprivateregistration.com
- domain.operationsweb.com
-
oldelval-com.mail.protection.outlook.com.
Microsoft 365
- cisco-ci-domain-verification=eaf0fcaff1d75927ea195155fadbbb41a6144cc33547e50e0fe77b8b7907d07
- mandrill_verify.8ye0FnfTtAVLOoKSGiXSyg
- teamviewer-sso-verification=0d0956a2107b48c787fc3ab6867264e5
- atlassian-domain-verification=FOEXq76CLUzhFHmv1hXjyFD554NaFFW0N2X64U1vuaI/LNkdiDB0draKhfYBvHdA
- google-gws-recovery-domain-verification=47048903
- ziNK/Q01hE+qCsfPHmhi4K+btS3wIlyv/xTZTkt9aDwrtvmOGagV9fpSB9bpNlTzjPyzhEvUm4lQJfItsZ83Xg==
- google-site-verification=F3bWeTX2FDu2hHiwUrkpRR0mm8MV60aVIaWzWfsh0JI
- v=spf1 ip4:200.70.23.188 include:spf.protection.outlook.com -all
- MS=ms63707881
Cloud / SaaS Services Detected
Atlassian
Cisco
Mailchimp
Microsoft 365
Teamviewer
Leak Screenshot:
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.