Ransomware victim disclosure
← All victimsAHORA Entre Ríos
listed as Canal 9 Litoral · Claimed by Nova · listed 8 days ago
Status timeline
- ListedJul 22, 2026
- Data leakeddate unknown
At a glance
- Group
- Nova
- Status
- Data leaked
- Country
- Argentina
- Sector
- Telecommunication
- Listed on leak site
- Jul 22, 2026
About the victim
AI dossier — public-source company profileAHORA Entre Ríos is a news platform serving the Litoral region of Argentina (Entre Ríos and Santa Fe provinces). It provides news coverage across society, politics, sports, economy, and health with minute-by-minute updates for regional residents and current events followers.
- Industry
- News & Media / Broadcasting
Attack summary
Severity: medium — Confirmed exfiltration claim with data publication, but no specific sensitive data types (PII, financial, medical) are detailed. No proof files or samples are currently visible in the post. News media operations typically hold limited regulated data compared to financial or healthcare sectors.The Nova ransomware group claims to have exfiltrated data from AHORA Entre Ríos. The group indicates they hold 'secret files' and offer to provide samples to the company upon contact with their support department, suggesting both encryption and data theft.
Data the group says was taken
AI dossier — extracted from the leak post- secret files
- company data
What the group claims
AHORA Entre Ríos is a news platform that provides the latest updates and urgent news from Entre Ríos, Santa Fe, and the Litoral region. The service covers a wide range of topics including society, politics, sports, economy, and health. It aims to keep its audience informed with minute-by-minute news coverage. The intended clients are residents and individuals interested in current events in the specified regions - MXF secret files at risk, Nova Provide tree and samples from stolen data to the company when its get in touch with support department.
Sources
Source
Indexed 8 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

