LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Banco central argentina Listed by zerotolerance Ransomware Group

HIGH severityUnverified claimHow we verify

Banco central argentina Listed by zerotolerance Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·May 5, 2024
Banco central argentina Listed by zerotolerance Ransomware Group

Reported May 5, 2024.

HIGH
Severity
May 5, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Banco central argentina Listed by zerotolerance Ransomware Group (reported May 5, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Contact / identity PII exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to single out financial institutions because of the sensitive data they hold and the pressure those organisations face to restore operations quickly. In this climate, claims of breaches at central banks attract particular scrutiny, even when independent confirmation remains limited.

On 5 May 2024 the ransomware group zerotolerance listed Banco Central Argentina on its leak site, asserting that it had carried out a data breach earlier that year and exfiltrated internal files. Public reporting of the claim notes that names, identification details and other material were among the compromised data. The number of people affected has not been disclosed, and the listing itself remains an unverified claim by the group.

Inside the incident

According to the information published with the listing, the incident was reported on 5 May 2024 at 5:53:55 am. The group stated that Banco Central of Argentina had suffered a data breach in 2024 involving the exfiltration of internal files. The same report mentioned that names, ID details and similar information had been compromised and referenced a download link for the material. No further technical details—such as the initial access method, the duration of the intrusion, the precise volume of data taken, or whether systems were encrypted—have been made public. The number of individuals affected remains unknown. Because the account originates from the threat actor’s own leak-site posting, it should be treated as a claim rather than independently verified fact.

The group behind it: zerotolerance

Zerotolerance is a ransomware operation that follows the now-common double-extortion model: after gaining access to a network, operators typically exfiltrate data and then encrypt systems, threatening to publish the stolen material if a ransom is not paid. The group maintains a leak site where it names victims and, in some cases, releases sample files or full archives to increase pressure. Like other ransomware crews active in recent years, it has focused on organisations whose data or operational continuity carries high value, including entities in the financial sector. Public reporting has documented its use of standard ransomware tactics—credential theft, lateral movement and data staging—though specific tooling and infrastructure can change between campaigns. In this instance the group claims responsibility for the Banco Central Argentina listing; no independent confirmation of the intrusion or of the group’s full access has been released in the available record.

Banco central argentina and its sector

Banco Central Argentina is the country’s central bank. It is responsible for monetary policy, currency issuance, financial-system oversight and the management of national reserves. Institutions of this type routinely handle large volumes of confidential information: records relating to commercial banks, payment systems, regulatory filings, internal administrative data and, in some cases, personal details of employees, contractors or individuals involved in official processes. A breach at a central bank is consequential because it can affect public confidence in the financial system, expose sensitive economic or supervisory information, and create secondary risks for the broader banking sector that depends on the central bank’s integrity and continuity.

What was likely exposed

The available facts state that internal files were exfiltrated in a ransomware attack and that names, identification details and similar data were compromised. Beyond those descriptions, the exact contents of the stolen material have not been independently catalogued in public sources. Organisations such as a central bank typically hold employee records, identification documents, internal correspondence, policy drafts, system logs and data exchanged with commercial banks or government agencies. Whether any of those categories were present in the claimed archive, and in what volume, remains unconfirmed. Readers should therefore treat the exposure as limited to the categories named by the group until further verified information appears.

The real-world impact

For individuals whose names or identification numbers may have been included, the primary risks are identity fraud, targeted phishing and the long-term reuse of personal data in social-engineering schemes. Even limited personal identifiers can be combined with other publicly available information to craft convincing scams. For the organisation itself, the consequences include potential regulatory scrutiny, the need to investigate and remediate any residual access, possible disruption to internal operations, and reputational pressure arising from the public claim. Because the scale of the incident and the precise data set remain undisclosed, the full extent of harm cannot yet be quantified; the prudent assumption is that any personal or internal material that was taken could be misused until proven otherwise.

Were you affected?

If you have had any professional or official dealings with Banco Central Argentina, or if you are an employee or contractor, treat the claim as a reason for heightened caution. Monitor bank and credit accounts for unusual activity, enable multi-factor authentication wherever possible, and be alert to unsolicited messages that reference personal details. Consider placing fraud alerts with credit bureaus if you reside in a jurisdiction that offers them. As a practical first step, you can run a free exposure scan of your email address to check whether that address or associated credentials have already appeared in known breach data sets; such a scan will not confirm involvement in this specific incident but can surface other exposures that require attention.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyBanco central argentina security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See Banco central argentina’s full breach history →

More recent breaches

Banco Sucredito Regional S.A.U. Listed by hunters Ransomware GroupOctober 25, 2024decreditos.com Listed by darkvault Ransomware GroupJune 25, 2024UNICRED.COM.AR Listed by clop Ransomware GroupMay 30, 2024AbelSantosyAsociados Listed by knight Ransomware GroupFebruary 2, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the Banco central argentina Listed by zerotolerance Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by zerotolerance — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram