Ransomware victim disclosure
← All victimsCeresTolvas
listed as Ceres Tolvas · Claimed by Qilin · listed 6 hours ago
Status timeline
- ListedSep 18, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileCeresTolvas is an Argentine agricultural services company operating 25 grain storage plants, 3 John Deere dealerships, and 29 agronomies across Buenos Aires, La Pampa, and Córdoba provinces. They provide grain aggregation, agricultural technology, farm inputs, animal nutrition (3,200 tonnes monthly capacity), and agro-sustainability services. The company was recognized as 'Best Company in Production Services' by Banco Galicia and La Nación in 2025.
- Industry
- Agriculture and Food Production - Grain Storage, Agricultural Inputs, Animal Nutrition, Farm Equipment Distribution
- Address
- Multiple locations: Buenos Aires, La Pampa, and Córdoba provinces, Argentina
Attack summary
Severity: medium — Data has been published by the group (disclosed_status = 'data_published'), indicating confirmed exfiltration, but no specific data inventory, proof file count, or sensitive data category is detailed in the available materials. The company operates in agriculture with customer/supplier relationships but no clear evidence of regulated PII or critical infrastructure impact.The Qilin group claims to have attacked CeresTolvas and published data. No detailed claim of specific exfiltration or encryption activity is provided in the available leak post excerpt.
What the group claims
N/A
Sources
Source
Indexed 6 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

