Medusa ransomware group attacked Argentina's National Securities Commission
- Organization
- Comisión Nacional de Valores (CNV), Argentina
- Exploit
- Ransomware
- Industry
- Financial Regulator
Argentina's National Securities Commission, the Comisión Nacional de Valores, was attacked by the Medusa ransomware group in June 2023. The regulator, which oversees the country's capital markets, filed a criminal complaint with the specialised cybercrime prosecutor's office on June 12.
Medusa demanded 500,000 dollars within a week and a further 500,000 dollars to delete what it had taken, threatening to publish around 1.5 terabytes of the commission's documents and databases on its leak site.
The CNV disputed the significance of the haul. It said the material consisted largely of balance sheets and other filings that regulated companies upload to its public information channel, documents that are already available to anyone. Medusa claimed it also held personal data and credentials.
According to the commission, its technical team isolated and halted the intrusion within about half an hour of the attack beginning at 7 a.m., data was preserved through preventive security measures and system integrity was maintained. The CNV said Argentina's financial markets operated normally throughout, that no other government bodies were affected, and that agents, market operators and custody systems reported no disruption.
The attack began on Wednesday June 7. UFECI, the specialised cybercrime prosecutor's office, recorded the commission's servers going down at 7:30 a.m. The CNV published its statement on June 11 and Medusa's deadline was Sunday June 18.