Ransomware victim disclosure
← All victimsProvincia Leasing S.A.
listed as Proleasing · Claimed by Qilin · listed 5 months ago
Status timeline
- ListedJan 22, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileProvincia Leasing S.A. is an Argentine financial services company specialising in leasing contracts for capital goods such as machinery and vehicles. Operating since 1996, it serves the public sector, construction, transport, services, industry, and agriculture, and describes itself as a market leader among the largest leasing providers in Argentina. Its registered offices are in Buenos Aires.
- Industry
- Financial Services – Equipment & Capital Goods Leasing
- Address
- Carlos Pellegrini 91, Piso 7, C1009ABA, Buenos Aires, Argentina
- Founded
- 1996
Attack summary
Severity: high — Data has been confirmed as published by the threat actor against a regulated financial services company, implying exfiltration of potentially sensitive business and client financial data. The financial sector nature of the victim elevates severity even absent a detailed data inventory.The Qilin ransomware group claims to have attacked Provincia Leasing S.A. and has published data (disclosed status: data_published), though the leak post excerpt does not specify the volume of data exfiltrated or whether encryption was also performed.
What the group claims
N/A
The leak post
captured from the group's siteLaw Firms & Legal Services [John G Yphantides A Professional Law](http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/blog?uuid=1e464ce5-6e74-4e62-be0b-eac503e43af8) Law Firms & Legal Services Law Firms & Legal Services [Keller Williams Real Estate - Exton](http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/blog?uuid=ac8e3226-6965-4f8e-a2d5-53a0dbce8535)
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

