LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Ministerio de Salud de la Nación argentina Listed by nova Ransomware Group

HIGH severityUnverified claimHow we verify

Ministerio de Salud de la Nación argentina Listed by nova Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·October 12, 2025
Ministerio de Salud de la Nación argentina Listed by nova Ransomware Group

Reported October 12, 2025.

HIGH
Severity
October 12, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Argentina’s Ministerio de Salud de la Nación was listed on October 12, 2025 by the nova ransomware group, which claims to have stolen internal files from the agency. Anyone who may have records with the ministry should monitor their information and follow official guidance on protective steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On October 12, 2025, the Ministerio de Salud de la Nación of Argentina was listed by the ransomware group known as nova. Public reporting indicates that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and independent confirmation of the full scope has not been provided beyond the group's claim.

This matters because the ministry coordinates national public-health policy, epidemiology, vaccination programs, and related services. Any compromise of its systems can affect sensitive operational and personal information tied to health administration across the country.

Inside the incident

According to available records, the Ministerio de Salud de la Nación was listed by nova on October 12, 2025. The reported details state that internal files were exfiltrated as part of a ransomware attack. No public information has confirmed the precise method of initial access, the duration of any intrusion, the volume of data taken, or whether systems were encrypted in addition to the claimed exfiltration.

The number of individuals potentially affected is listed as unknown. One element associated with the listing asserts that the data include highly sensitive information for more than 2 million people; that figure has not been independently verified and should be treated as an unverified claim. Timing of the underlying intrusion itself is undisclosed. Public detail on containment, notification to regulators, or remediation steps taken by the ministry remains limited.

The group behind it: nova

Nova is a ransomware operation that has appeared in public threat reporting as a group that practices double-extortion tactics: encrypting systems while also claiming to steal data and threatening to publish it if demands are not met. Like many such groups, it typically advertises victims on dedicated leak sites to increase pressure. These sites function as claims boards rather than verified evidence repositories.

Public knowledge of nova's activity centers on opportunistic targeting of organizations across sectors, often after initial access through common vectors such as exposed remote services or compromised credentials. The group has been associated with listings of government and critical-infrastructure entities in various countries. In this case, the listing of the Ministerio de Salud de la Nación is a claim made by the group; it does not by itself constitute independent confirmation of the full extent of any breach or of the specific contents of any files.

Ministerio de Salud de la Nación and its sector

The Ministerio de Salud de la Nación is Argentina's national health ministry. It is responsible for coordinating and overseeing public-health policy in a federal system, with the stated aim of strengthening equitable access to quality health services. Its functions include epidemiology, vaccination campaigns, border health controls, and related oversight. Since September 30, 2024, the minister has been Mario Lugones, who assumed the role after Mario Russo.

Health ministries of this type typically manage large volumes of administrative, clinical, and population-level data. They interact with provincial systems, hospitals, laboratories, and international health partners. A breach involving such an agency is consequential because it can disrupt service coordination, expose personal health-related records, and undermine public trust in essential government functions. Even when the precise data set is unconfirmed, the sector's inherent sensitivity elevates the potential impact.

What data was at risk

Public facts name the exposed material as internal files exfiltrated in a ransomware attack. No further inventory of specific data categories has been independently confirmed. The group's associated claim refers to highly sensitive information affecting more than 2 million people; that assertion remains unverified, and the official count of affected individuals is recorded as unknown.

Organizations of this kind commonly hold personnel records, administrative correspondence, epidemiological datasets, vaccination registries, procurement files, and other operational documents. Whether any of those categories were among the files taken in this incident has not been established in the available record. Exact contents are therefore unconfirmed.

What's at stake

For individuals, the primary risks center on the possible exposure of personal or health-related information. If such data were involved, affected people could face identity misuse, targeted phishing that references real health details, or longer-term privacy harm. Because the precise data types and the number of people involved remain unconfirmed, these risks cannot be quantified with certainty; they are nevertheless the standard concerns that arise when a national health authority is listed in a ransomware incident.

For the ministry, stakes include operational disruption, potential regulatory scrutiny, the cost of investigation and recovery, and erosion of public confidence in health-system security. Ransomware incidents can also divert resources from core public-health work. None of these outcomes has been detailed in public reporting for this specific case; they represent the ordinary consequences observed across similar events rather than proven facts about the present one.

What to do if you're exposed

If you believe your information may have been involved, take measured first steps. Monitor official statements from the ministry or Argentine data-protection authorities for any confirmed notifications. Review financial and government accounts for unusual activity, and treat unsolicited messages that reference health services with caution. Consider placing fraud alerts with credit bureaus if personal identifiers could be at risk. Change passwords on any accounts that reused credentials linked to government or health portals, and enable multi-factor authentication where available.

Public detail on this incident remains limited. Readers who want an additional check can use free email-exposure tools that search published breach collections; such scans do not prove involvement in this specific event but can indicate whether an address has appeared elsewhere.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyMinisterio de Salud de la Nación security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See Ministerio de Salud de la Nación’s full breach history →

More recent breaches

SECONT Secretaria de Controle e Transparência Listed by nova Ransomware GroupMay 24, 2026ANG BROTHERS (M&E) PTE. LTD. (P3) Listed by nova Ransomware GroupDecember 6, 2025National Health Insurance Management Authority Listed by nova Ransomware GroupDecember 5, 2025ANG BROTHERS (M&E) PTE. LTD. (P2) Listed by nova Ransomware GroupNovember 24, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Ministerio de Salud de la Nación argentina Listed by nova Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by nova — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram