Nova ransomware actor “nova” targeted Canal 9 Litoral (AR), threatening to expose “MXF secret files” stolen from the news platform AHORA Entre Ríos and offering data-leak terms upon contact with the company’s support team. The incident threatens the platform’s minute-by-minute regional reporting across Entre Ríos, Santa Fe, and the Litoral region. #Argentina
Incident Details
- Victim: Canal 9 Litoral
- Sector: Telecommunication
- Country: AR
- Actor: nova
- Source: http://pifk3xu3vad6cuxsjll4qjomyaaaoyvnyqppro75pazadzctrrvpdnyd.onion/canal-9-litoral
- Discovered: 2026-07-22T00:14:37.054785+00:00
- Published: 2026-07-22T00:13:23.197716+00:00
Information
- AHORA Entre Ríos is a news platform delivering the latest and urgent updates from Entre Ríos, Santa Fe, and the Litoral region.
- It covers topics such as society, politics, sports, economy, and health.
- The service aims to keep its audience informed with minute-by-minute news coverage.
- Its target audience includes residents and others interested in current events in these regions.
- MXF secret files are at risk.
- Nova claims it can provide a tree and samples of stolen data to the company when contacted through the support department.

Disclaimer: This post is based on public claims made by the ransomware group "nova". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.