Known incidents
Between 2020 and 2026, 14 cyber incidents were documented across Argentine energy and critical infrastructure. This layer reads them from the public register, which backs each row with a source.
Cyber incidents per year, stacked by actor type. Source: register of cyber incidents in Argentine energy and critical infrastructure.
A recent jump, and a single kind of attacker
The curve has a break and a color. The break is 2025: 6 cases in one year against one or two in each prior year. The color of the bars never changes: the identified actors are all ransomware or extortion. No state actor appears; the commodity attacker does, the same tier that automation and language models make cheapest to run at scale.
The cases span 12 subsectors, from power distribution and gas and crude transport to water, nuclear generation, and coal.
Seven of fourteen are known only because the attacker published them
For half the register there was no company statement, no regulator notice, no report to a CERT. There was a row on a leak site. The sector has no reporting channel of its own, so it learns from whoever attacked it.
Nor is there a chart by province. An incident usually touches several at once, and the administrative headquarters would concentrate the cases in Buenos Aires Province and the City of Buenos Aires, which says where the offices are and not where the risk is. The row-by-row reading, with date, subsector, actor, and source, lives in the register.
What this count is missing
- It covers the publicly documented. An incident that never reached the press or a leak site is not here, and absence of trace does not prove absence of incident.
- Seven rows come solely from the attacker's site, which is an interested party with an incentive to exaggerate the scope of what it took.
- Actor attribution is what each source states, with its confidence level. Several rows remain unattributed.