Known incidents
The 14 documented cyber incidents in Argentine energy and critical infrastructure are the only ground truth available: not what could happen, but what already did. This layer reads them from the public register that backs each row with a source, and looks at them two ways.
Cyber incidents per year, stacked by actor type. The 2025 jump holds 6 of the 14 cases. Source: register of cyber incidents in Argentine energy and critical infrastructure.
A recent jump, and a single kind of attacker
The yearly curve has a break and a color. The break is 2025: six cases in one year against one or two in each prior year. The color of the bars never changes: the identified actors are all ransomware or extortion. No state actor appears; the commodity attacker does, the same tier that automation and language models make cheapest to run at scale.
Where they hit
Each incident at its province centroid, colored by actor type; the popup links to the register row. The point marks the province, not the facility.
The map is geographic, not a ranking: an incident usually touches several provinces at once, and the administrative headquarters would concentrate the cases in Buenos Aires Province and the City of Buenos Aires, which would say more about where the offices are than about where the risk is. What does order the reading is the subsector: the 14 cases span a dozen of them, from power distribution to gas and crude transport, upstream, generation, water, nuclear, LPG, and coal. No subsector is safe.
The sector learns from the attacker
One visibility finding orders the rest: 7 of the 14 incidents are known only because the attacker published them on its leak site. There is no notice from the company, a regulator, or a CERT: there is a row on a leak site. The sector has no reporting channel, so it learns from whoever attacked it, or it does not learn at all. That is the underlying reason this register exists.
Limits of this layer
- The register covers the publicly documented. An incident that never reached the press or a leak site is not here, and absence of trace is not proof of absence.
- The location is the province centroid, not the affected facility. That is deliberate: pinning the exact point adds nothing to the analysis and would move the map closer to a pointer.
- Actor attribution is what each source states, with its confidence level. Several remain "unattributed".
Incidents are the surface already used. Network exposure measures the one on plain view, before any attack.