During analysis of data obtained from Oleoductos del Valle (AR), incransom ransomware actors compiled extensive HR, financial/regulatory (CNV/BYMA), tax (AFIP), tariff/SEN-related, incident/environmental, partner confidentiality, whistleblower (Ley 27.401), and banking/dividend materials, along with personal data including IDs and CVs. The impacted country(s): #Argentina
Incident Details
- Victim: Oleoductos del Valle
- Sector: Energy & Utilities
- Country: AR
- Actor: incransom
- Source: http://incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion/blog/disclosures/6a5e4dc55ae71db30c1d10a0
- Discovered: 2026-08-04T00:24:30.100408+00:00
- Published: 2026-08-03T23:59:00+00:00
Information
- Full payroll records, bank account details, health insurance information, severance calculations, and compensation agreements.
- Financial and regulatory filings submitted to CNV and BYMA, including rating agency documents and shareholder agreements.
- Tax declarations and reports filed with AFIP, including Sicore, Ganancias, and IVA returns.
- Tariff policy documents and SEN-related materials, including WACC and TIR calculations used in tariff reviews.
- Incident reports and environmental records, including spill reports and technical pipeline condition assessments.
- Confidentiality agreements with major partners and service providers.
- Internal whistleblower channel materials, including complaints and compliance reports.
- Documents related to dividend payments and banking transactions.
- Personal data of directors, candidates, and key employees, including ID numbers and CVs.

Disclaimer: This post is based on public claims made by the ransomware group "incransom". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.