SYS::ONLINE
Wasteland.
Briefs1691
Issues22
SinceFeb 2026
LIVE
█ Ransomware OLEODUCTOS-DEL-VAL 2026-08-04

Oleoductos del Valle: INC Ransom Claims Mass Exfiltration From Argentina's Main Crude Pipeline Operator

"Oleoductos del Valle S.A. (Oldelval), the operator of Argentina's principal crude oil trunk transport network and the company that evacuates the bulk of Vaca Muerta production, disclosed a "computer security incident"…"

Oleoductos del Valle S.A. (Oldelval), the operator of Argentina's principal crude oil trunk transport network and the company that evacuates the bulk of Vaca Muerta production, disclosed a "computer security incident" to Argentina's securities regulator, the Comisión Nacional de Valores (CNV), on Friday 31 July 2026. On 3 August, the INC Ransom operation (tracked as "incransom") published a disclosure page on its Tor leak blog claiming an extensive exfiltration from the company, covering HR and payroll records, CNV/BYMA regulatory filings, AFIP tax returns, tariff and SEN policy models, pipeline incident and environmental spill reports, whistleblower complaints filed under Ley 27.401, banking and dividend documents, and personal data on directors and job candidates. Oldelval's own filing, signed by Market Relations officer Martín Castaño, states the intrusion was confined to administrative systems and that crude transport ran without interruption. Attribution is genuinely contested: several Argentine outlets attributed the attack to a different group, The Gentlemen, before the INC Ransom listing appeared. No national CERT advisory, vendor report, or full text of the company's filing was available for this brief, so every claim below is attributed.

What Happened

The confirmed spine of the story comes from the CNV "hecho relevante" filed on 31 July and reported consistently across Infobae, Ámbito, Data Energía, Vaca Muerta News and Patagonia Shale. Oldelval told the regulator that certain administrative systems had been compromised, that it activated its cybersecurity protocol, and that it restored the entirety of the affected systems and resumed normal administrative activity. Company representatives described the episode to multiple outlets as "100% controlado."

Data Energía reports that the SCADA layer monitoring pipeline flow in real time operated in isolation and outside the attackers' reach, and that field control systems recorded no alteration. Pumping programs toward the Puerto Rosales export terminal in Bahía Blanca and YPF's Luján de Cuyo refinery in Mendoza continued on schedule. Ámbito reported the company was weighing whether to file a criminal complaint with the courts in the hours following disclosure. Oldelval did not disclose the threat type or the intrusion vector, and said it was still assessing the definitive scope of the incident while continuing notifications to the competent authorities.

Two material discrepancies run through the reporting. On throughput, Infobae and Patagonia Shale put the share of Vaca Muerta crude moving through Oldelval's ducts at 75%, while Defonline and Vaca Muerta News put it at roughly 90%; the network itself is consistently described as more than 1,700 kilometres linking Neuquina Basin fields to storage and export terminals. On ownership, Infobae describes YPF as the largest shareholder of the majority state-owned oil company, while Defonline specifies a 37% YPF stake alongside ExxonMobil, Chevron, Pan American Energy, Tecpetrol, Pluspetrol and Pampa Energía.

On attribution, accounts differ outright. Defonline and Vaca Muerta News, both publishing on 3 August, named The Gentlemen, a ransomware-as-a-service operation that Defonline says is analysed by Microsoft Threat Intelligence under the actor designation Storm-2697, and reported that the claim was made on social media roughly a week after the same group hit Colombian state oil major Ecopetrol. Separately, the INC Ransom leak-site listing catalogued 3 August and surfaced 4 August is the basis for the data-theft claims in this brief. Whether these represent two claims over the same intrusion, a misattribution in early reporting, or two separate actors touching the same victim is not resolvable from the available sources. Oldelval has not publicly named any group.

What Was Taken

No source provides a record count, byte volume, or file total, and none should be inferred. The INC Ransom disclosure page enumerates categories rather than figures, and the listing itself is an unverified criminal claim that the aggregator publishing it explicitly declines to confirm. With that caveat, the claimed inventory is unusually broad for an infrastructure operator:

Three of those categories carry consequences beyond the usual identity-theft exposure. Pipeline condition assessments and spill reports describe the physical state of a 1,700-kilometre asset and would be of direct interest to anyone planning a physical or cyber-physical action against it. WACC and TIR tariff models expose the company's regulated-return position ahead of tariff reviews. And Ley 27.401 whistleblower material identifies complainants inside a company jointly held by YPF and several international supermajors, a disclosure risk to named individuals that no restoration of systems undoes.

For scale comparison on the adjacent Ecopetrol case, Vaca Muerta News reports that the Colombian operator prevented mass encryption but not the unauthorised download of data from roughly 3,300 accounts and cloud-stored information across 15 group companies.

Why It Matters

The gap between "operations were never affected" and "the adversary took the whistleblower file, the spill history and the tariff model" is the entire lesson here, and it is one energy defenders keep relearning. Oldelval's IT/OT segmentation appears to have held, and that is a real and creditable outcome that Colonial Pipeline in 2021 did not achieve. But modern ransomware crews increasingly do not need OT. The corporate side alone yielded regulator filings, tax returns, banking detail and partner NDAs, which is leverage enough to extort a listed company without ever touching a valve.

The victim profile compounds it. Oldelval sits at a single point of concentration for Argentine energy exports, moving somewhere between 75% and 90% of Vaca Muerta crude depending on which outlet you read, during the buildout of the Duplicar Norte expansion. Undercode News notes the attack landed during a major expansion phase and raises the question of whether attackers deliberately targeted a period of organisational change and system upgrades, a hypothesis worth holding lightly given it is a single-outlet inference rather than a finding.

Regionally, the pattern is what defenders should be tracking. Whether the actor was The Gentlemen or INC Ransom, Latin American energy operators are being worked systematically: Ecopetrol in Colombia, then Oldelval in Argentina, roughly a week apart per Vaca Muerta News. Argentine cybersecurity practitioner Marcela Pallero, cited by Defonline, has characterised the country as fifteen years behind Europe on cybersecurity, and the incident is being read domestically as a stress test of national critical infrastructure readiness rather than a single company's bad week.

The Attack Technique

There is no confirmed initial access vector. Oldelval explicitly declined to disclose the threat type or the entry point used, and said it was still assessing the definitive scope. Nothing in the available reporting identifies an exploited CVE, a phished credential, an exposed edge appliance, or a compromised third party.

What can be said structurally: both candidate actors operate double-extortion models, and the observable behaviour in this case is consistent with exfiltration-led extortion. INC Ransom's leak blog is the standard name-and-shame pressure mechanism, and the disclosure posted 3 August names data categories rather than demanding a headline ransom in public. Defonline describes The Gentlemen as an emerging RaaS threat tracked by Microsoft as Storm-2697. Vaca Muerta News reports that in the Ecopetrol case the same group failed to achieve mass file encryption but succeeded at bulk download, which is the pattern to plan against: assume encryption may be stopped and exfiltration still succeeds.

Company sources told both Infobae and Ámbito that they could not rule out local actors but that the foreign-origin hypothesis was the stronger one. That is a source-attributed operational hypothesis from the victim, not a technical attribution.

What Organizations Should Do

  1. Treat exfiltration as the primary loss event, not encryption. Oldelval restored every affected system and still faces a full-category data dump. Build the incident response and legal playbook around what leaves the network, and instrument egress accordingly with DLP on document repositories holding HR, tax and regulatory filings.
  2. Verify that IT/OT segmentation is enforced, not assumed. The SCADA isolation described by Data Energía is the control that made this survivable. Test it adversarially: no shared domain trust, no flat jump hosts, no engineering workstations dual-homed into the corporate domain, and unidirectional gateways where the process data flow permits.
  3. Inventory and lock down regulatory and compliance repositories. CNV/BYMA filing systems, AFIP tax platforms, tariff modelling spreadsheets and Ley 27.401 whistleblower channels are rarely covered by the crown-jewels programme and are exactly what was catalogued here. Apply strict least-privilege, separate the whistleblower channel from general file shares, and encrypt at rest with keys not held by the file server's own domain.
  4. Protect pipeline integrity documentation as sensitive operational intelligence. Spill reports and technical condition assessments describe physical weak points. Restrict them to a named group, log every access, and alert on bulk reads.
  5. Hunt for RaaS precursors specific to this cluster. Look for suspicious remote monitoring and management tooling, unsanctioned cloud-sync clients, archive utilities producing large staged files, and abnormal outbound volume to file-sharing services. Given the Ecopetrol-then-Oldelval sequence, regional energy operators and their shared service providers should hunt on the assumption they are already in the target set.
  6. Rehearse the regulator and disclosure path before you need it. Oldelval's filing to the CNV on the same working day it was detected is the part of this response worth copying. Pre-draft the material-event notification, pre-identify who signs it, and pre-agree what is said about scope while scope is still unknown.
  7. Extend monitoring through the expansion programme. Capital projects introduce new contractors, new integrations and temporary access. Whether or not the timing was deliberate here, expansion phases widen the attack surface, and access granted for a project should expire with it.

Sources: Ransom! Oleoductos del Valle (AUG-2026) | La operadora del oleoducto por el que circula el 75% del petróleo d... | Denuncian un intento de ciberataque al operador del mayor oleoducto... | Odelval, la mayor transportadora de crudo de Vaca Muerta sufrió un... | Ciberataque a Oldelval: incidente en Vaca Muerta revela falencias | Oldelval informó un ciberataque que no afectó el transporte de crud... | Cyberattack on Oldelval Exposes Growing Cyber Risks Inside Argentin... | Vaca Muerta: un ciberataque atentó contra los sistemas de Oldelval...