Ransomware victim disclosure
← All victimsAdministración Tributaria Provincial de Formosa (Dirección General de Rentas)
listed as atpformosa.gob.ar · Claimed by Lockbit3 · listed 1 year ago
Status timeline
- ListedJan 13, 2025
- Data leakeddate unknown
At a glance
- Group
- Lockbit3
- Status
- Data leaked
- Country
- Argentina
- Sector
- Government
- Listed on leak site
- Jan 13, 2025
About the victim
AI dossier — public-source company profileATP Formosa is the provincial tax administration agency (Dirección General de Rentas) for Formosa Province, Argentina. It manages collection and administration of provincial taxes including gross income tax, rural property tax, and related fiscal obligations. The organization operates from a central office in Formosa Capital with a branch office in Buenos Aires.
- Industry
- Government / Tax Administration
- Address
- Ayacucho 810, Formosa Capital 3600, Argentina
Attack summary
Severity: high — Confirmed compromise of a government tax administration agency with likely exfiltration of sensitive taxpayer personal and financial data at scale. Government sector compromise is inherently high-severity due to regulatory sensitivity and potential national security implications.LockBit3 claims to have compromised the Formosa tax administration agency. The group posted the victim on their leak site indicating data exfiltration, though specific details on what data was taken or encryption deployment are not detailed in the provided post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- Taxpayer records
- Tax payment information
- Fiscal documentation
- Administrative records
What the group claims
Greetings! Today we are posting here the new company, "Administracion Tribunaria Provincal (Dirección General de Rentas de Formosa)". Company Description: Formosa Tax Administration Headquarters: Ayacuch 810 ,Formosa, Argentina Web site:...
Sources
Source
Indexed 1 year agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

