Ransomware victim disclosure
← All victimsLIBRERIA SANTA FE A P S SRL
Claimed by Vexy Ransomware · listed 6 days ago
Status timeline
- ListedSep 7, 2026
- Data leakeddate unknown
At a glance
- Group
- Vexy Ransomware
- Status
- Data leaked
- Country
- Argentina
- Sector
- Retail & E-Commerce
- Listed on leak site
- Sep 7, 2026
About the victim
AI dossier — public-source company profileLibrería Santa Fe (LSF) is a multi-branch bookstore chain based in Buenos Aires, Argentina, offering a wide selection of national and imported books across various genres. The company operates physical locations throughout CABA and maintains an online shopping platform with an active social media presence.
- Industry
- Retail & E-Commerce – Bookstores
- Address
- Buenos Aires (CABA), Argentina (multiple branches)
Attack summary
Severity: low — The leak post contains only a company description with no proof of data exfiltration, encryption, or operational impact. No data inventory, proof files, or ransom demand are advertised.The Vexy ransomware group claims to have attacked Librería Santa Fe. No specific data exfiltration or encryption details are provided in the available leak post excerpt; the post primarily describes the company's business operations rather than attack specifics.
What the group claims
LSF (Librería Santa Fe) is a bookstore based in Buenos Aires, Argentina, with multiple branches across the city (CABA). It offers a wide selection of both national and imported books across various genres and authors. The store provides an easy online shopping experience where customers can browse and purchase titles with just a few clicks. It also maintains an active social media presence on Instagram (@libreriasantafe) to share news, promotions, and updates. Visitors are welcome to visit their physical locations in person.
Sources
- Victim sitelsf.com.ar
Source
Indexed 6 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

