Ransomware victim disclosure
← All victimsLibrería Santa Fe APS S.R.L.
listed as Librería Santa Fe · Claimed by Thegentlemen · listed 20 hours ago
Status timeline
- ListedSep 15, 2026
- Data leakeddate unknown
At a glance
- Group
- Thegentlemen
- Status
- Data leaked
- Country
- Argentina
- Sector
- Retail & E-Commerce
- Listed on leak site
- Sep 15, 2026
About the victim
AI dossier — public-source company profileLibrería Santa Fe APS S.R.L. is an Argentine book retailer and distributor founded in 1996, operating a chain of bookstores in Buenos Aires named after Avenida Santa Fe, the city's historic book district. The company operates both retail locations and B2B distribution of books and stationery to schools and institutions across Argentina, with some export operations linked to Italy.
- Industry
- Book Retail & Distribution
- Address
- Buenos Aires, Argentina (Barrio Norte, near Avenida Santa Fe)
- Founded
- 1996
Attack summary
Severity: low — Disclosure listing only with no proof files, no data inventory details, no confirmation of encryption or exfiltration, and no stated operational impact.The threat actor claims to have compromised Librería Santa Fe. No specific details on encryption, exfiltration, or data types are provided in the disclosed leak post.
What the group claims
santafelibros.com.ar Librería Santa Fe APS S.R.L. is an Argentine book retailer and distributor from Buenos Aires — founded 1996 (SIC 5942 Book Stores, Active status), operating a chain of bookstores (named after Avenida Santa Fe, the city's legendary book district in Barrio Norte) plus B2B book/stationery distribution to schools and institutions across Argentina, with traces in Italian business aggregators (export/Italy-linked operations). Classic family bookselling business — pre-Amazon era model: retail + distribution. Bottom line: a Buenos Aires book chain riding the avenue that made the city UNESCO's 2011 World Book Capital.
Sources
- Victim sitesantafelibros.com.ar
Source
Indexed 20 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

