LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Ministerio de Economía Argentina Listed by everest Ransomware Group

HIGH severityUnverified claimHow we verify

Ministerio de Economía Argentina Listed by everest Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 21, 2022
Ministerio de Economía Argentina Listed by everest Ransomware Group

Reported September 21, 2022.

HIGH
Severity
September 21, 2022
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Ministerio de Economía Argentina Listed by everest Ransomware Group (reported September 21, 2022) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In September 2022, the Ministerio de Economía Argentina appeared on a ransomware leak site operated by the group known as everest. The group claims to have stolen internal data from the ministry. Public detail on how many people may be affected remains unknown, and the precise contents of any taken files have not been independently confirmed. For anyone who has dealt with Argentina’s economy ministry—employees, contractors, businesses, or citizens whose records may sit in government systems—the listing raises a practical question: whether personal or organisational information could now sit outside official control.

Ransomware groups list victims to pressure organisations and to advertise claimed thefts. A listing is not the same as verified proof of every detail, yet it is a signal that warrants attention. When a national economic ministry is named, the stakes involve not only institutional operations but also the ordinary people whose data such bodies routinely handle.

Breaking down the breach

According to available reporting, Ministerio de Economía Argentina was listed on the everest ransomware leak site on or around September 21, 2022. The group claims to have stolen internal data and describes the material as internal files exfiltrated in a ransomware attack. The number of people affected is unknown. Public reporting does not disclose the intrusion method, the duration of any access, whether systems were encrypted, or whether any ransom demand was paid or refused. Exact file counts, volumes, and independent verification of the stolen set are not provided in the public record summarised here. What is stated is the leak-site listing itself and the group’s claim of exfiltration of internal files.

Who is everest?

Everest is a ransomware group that has operated in the criminal underground by compromising organisations, exfiltrating data, and threatening to publish it on a dedicated leak site if demands are not met. Like other actors in this category, the group typically relies on double-extortion tactics: encryption of systems combined with the threat of data release, or data theft alone used as leverage. Public reporting over time has associated everest with listings across multiple sectors and countries. The group’s leak site functions as both a pressure tool and a public claim of successful intrusion. In this case, the appearance of Ministerio de Economía Argentina on that site should be read as everest’s claim that it stole internal data; it is not, on its own, a full forensic confirmation of every asserted detail. No further specific statements by the group about this victim beyond the listing and the claim of stolen internal data are included in the facts at hand.

About Ministerio de Economía Argentina

The Ministerio de Economía Argentina is the national government ministry responsible for economic policy, public finance, and related administrative functions in Argentina. Bodies of this kind oversee budgets, fiscal rules, economic statistics, regulatory frameworks, and interactions with other state entities, businesses, and international counterparts. They typically hold substantial volumes of internal documents, correspondence, personnel records, contractor information, and data tied to economic programmes and public administration. A breach affecting such an organisation is consequential because the ministry sits at the centre of national economic governance. Compromise of internal systems or files can disrupt operations, expose sensitive policy or administrative material, and place at risk information linked to staff, partners, and members of the public who interact with economic and fiscal services.

What data was at risk

The facts name the exposed material as internal files exfiltrated in a ransomware attack. No further breakdown of data types—such as names, identification numbers, financial records, or specific document categories—is disclosed in the public summary. The number of people affected is unknown. Organisations like a national economy ministry commonly hold employee and contractor data, internal memoranda, budgetary and planning documents, correspondence, and records connected to public programmes. Whether any of those categories were present in the claimed theft has not been confirmed in the available facts. Readers should treat the exact contents as unconfirmed beyond the group’s claim of internal files.

Why it matters

When internal government files are claimed to have been taken, the real-world risks are concrete even if the full inventory is unknown. Individuals whose details appear in ministry systems could face phishing, social engineering, or identity misuse if personal or contact data were included. Businesses and contractors who work with the ministry may see proprietary or contractual information exposed. For the organisation itself, unauthorised access to internal files can undermine operational confidentiality, complicate policy work, and require costly investigation and remediation. Because the scale of affected people is unknown and the precise data types beyond “internal files” are not detailed publicly, uncertainty itself becomes part of the harm: people cannot easily know whether they are in scope. A listing by a ransomware group also signals that criminal actors believed the data had value for extortion or resale, which keeps the material relevant long after the initial report date.

What to do if you're exposed

If you have a connection to the Ministerio de Economía Argentina—as staff, a contractor, a supplier, or a member of the public who has submitted information—consider the following practical steps while public detail remains limited:

Confirmed notifications from the organisation, if any are issued, should take priority over general advice. Until more is verified, calm vigilance and basic hygiene—unique passwords, multi-factor authentication, and scepticism toward unexpected requests—remain the most useful responses.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyMinisterio de Economía Argentina security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See Ministerio de Economía Argentina’s full breach history →

More recent breaches

RS.GOV.BR/Government Brazil Listed by everest Ransomware GroupOctober 10, 2022Government Brazil Listed by everest Ransomware GroupSeptember 19, 2022GOV Brazil Listed by everest Ransomware GroupAugust 30, 2022United States of America GOV Listed by everest Ransomware GroupApril 6, 2022

Latest breaches

Read GalaxyWarden’s full analysis of the Ministerio de Economía Argentina Listed by everest Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by everest — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram