Ministerio de Salud de la Nación argentina Listed by nova Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Argentina’s Ministerio de Salud de la Nación was listed on October 12, 2025 by the nova ransomware group, which claims to have stolen internal files from the agency. Anyone who may have records with the ministry should monitor their information and follow official guidance on protective steps.
On October 12, 2025, the Ministerio de Salud de la Nación of Argentina was listed by the ransomware group known as nova. Public reporting indicates that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and independent confirmation of the full scope has not been provided beyond the group's claim.
This matters because the ministry coordinates national public-health policy, epidemiology, vaccination programs, and related services. Any compromise of its systems can affect sensitive operational and personal information tied to health administration across the country.
Inside the incident
According to available records, the Ministerio de Salud de la Nación was listed by nova on October 12, 2025. The reported details state that internal files were exfiltrated as part of a ransomware attack. No public information has confirmed the precise method of initial access, the duration of any intrusion, the volume of data taken, or whether systems were encrypted in addition to the claimed exfiltration.
The number of individuals potentially affected is listed as unknown. One element associated with the listing asserts that the data include highly sensitive information for more than 2 million people; that figure has not been independently verified and should be treated as an unverified claim. Timing of the underlying intrusion itself is undisclosed. Public detail on containment, notification to regulators, or remediation steps taken by the ministry remains limited.
The group behind it: nova
Nova is a ransomware operation that has appeared in public threat reporting as a group that practices double-extortion tactics: encrypting systems while also claiming to steal data and threatening to publish it if demands are not met. Like many such groups, it typically advertises victims on dedicated leak sites to increase pressure. These sites function as claims boards rather than verified evidence repositories.
Public knowledge of nova's activity centers on opportunistic targeting of organizations across sectors, often after initial access through common vectors such as exposed remote services or compromised credentials. The group has been associated with listings of government and critical-infrastructure entities in various countries. In this case, the listing of the Ministerio de Salud de la Nación is a claim made by the group; it does not by itself constitute independent confirmation of the full extent of any breach or of the specific contents of any files.
Ministerio de Salud de la Nación and its sector
The Ministerio de Salud de la Nación is Argentina's national health ministry. It is responsible for coordinating and overseeing public-health policy in a federal system, with the stated aim of strengthening equitable access to quality health services. Its functions include epidemiology, vaccination campaigns, border health controls, and related oversight. Since September 30, 2024, the minister has been Mario Lugones, who assumed the role after Mario Russo.
Health ministries of this type typically manage large volumes of administrative, clinical, and population-level data. They interact with provincial systems, hospitals, laboratories, and international health partners. A breach involving such an agency is consequential because it can disrupt service coordination, expose personal health-related records, and undermine public trust in essential government functions. Even when the precise data set is unconfirmed, the sector's inherent sensitivity elevates the potential impact.
What data was at risk
Public facts name the exposed material as internal files exfiltrated in a ransomware attack. No further inventory of specific data categories has been independently confirmed. The group's associated claim refers to highly sensitive information affecting more than 2 million people; that assertion remains unverified, and the official count of affected individuals is recorded as unknown.
Organizations of this kind commonly hold personnel records, administrative correspondence, epidemiological datasets, vaccination registries, procurement files, and other operational documents. Whether any of those categories were among the files taken in this incident has not been established in the available record. Exact contents are therefore unconfirmed.
What's at stake
For individuals, the primary risks center on the possible exposure of personal or health-related information. If such data were involved, affected people could face identity misuse, targeted phishing that references real health details, or longer-term privacy harm. Because the precise data types and the number of people involved remain unconfirmed, these risks cannot be quantified with certainty; they are nevertheless the standard concerns that arise when a national health authority is listed in a ransomware incident.
For the ministry, stakes include operational disruption, potential regulatory scrutiny, the cost of investigation and recovery, and erosion of public confidence in health-system security. Ransomware incidents can also divert resources from core public-health work. None of these outcomes has been detailed in public reporting for this specific case; they represent the ordinary consequences observed across similar events rather than proven facts about the present one.
What to do if you're exposed
If you believe your information may have been involved, take measured first steps. Monitor official statements from the ministry or Argentine data-protection authorities for any confirmed notifications. Review financial and government accounts for unusual activity, and treat unsolicited messages that reference health services with caution. Consider placing fraud alerts with credit bureaus if personal identifiers could be at risk. Change passwords on any accounts that reused credentials linked to government or health portals, and enable multi-factor authentication where available.
- Check official channels for any confirmed breach notices rather than relying solely on third-party claims.
- Watch for phishing that exploits health or government themes.
- Update passwords and enable multi-factor authentication on sensitive accounts.
- Run a free exposure scan of your email address to see whether it appears in known breach datasets.
Public detail on this incident remains limited. Readers who want an additional check can use free email-exposure tools that search published breach collections; such scans do not prove involvement in this specific event but can indicate whether an address has appeared elsewhere.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
SECONT Secretaria de Controle e Transparência Listed by nova Ransomware GroupANG BROTHERS (M&E) PTE. LTD. (P3) Listed by nova Ransomware GroupNational Health Insurance Management Authority Listed by nova Ransomware GroupANG BROTHERS (M&E) PTE. LTD. (P2) Listed by nova Ransomware GroupLatest breaches
Publicly posted by nova — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.