Ransomware victim disclosure
← All victimsOldelval Oleoductos del Valle
Claimed by Thegentlemen · listed 6 days ago
Status timeline
- ListedJul 23, 2026
- Data leakeddate unknown
At a glance
- Group
- Thegentlemen
- Status
- Data leaked
- Country
- Argentina
- Sector
- Energy & Utilities
- Listed on leak site
- Jul 23, 2026
About the victim
AI dossier — public-source company profileOldelval (Oleoductos del Valle S.A.) is a leading Argentine midstream energy company specializing in the transportation of liquid hydrocarbons. Based in Cipolletti, Río Negro, it transports over 50% of Argentina's oil production and approximately 80% of oil from the Neuquén Basin, with a national concession extended to 2037.
- Industry
- Oil & Gas Transportation / Midstream Energy
- Address
- Cipolletti, Río Negro, Argentina
- Founded
- 1963
Attack summary
Severity: high — Confirmed data exfiltration from a critical infrastructure operator (oil transportation) responsible for majority of national hydrocarbon flows. Operational disruption to this company could impact national energy security. No ransom demand suggests data may have been published or monetized separately.The ransomware group 'thegentlemen' claims to have breached Oldelval and published data. No specific details on encryption, exfiltration scope, or data categories are provided in the post excerpt.
What the group claims
***.com zoominfo.com/c/oleoductos-del-valle-sa/456337922 Oldelval (Oleoductos del Valle S.A.) is a leading Argentine midstream energy company specializing in the transportation of liquid hydrocarbons. Based in Cipolletti, Río Negro, it transports over 50% of the oil produced in Argentina and approximately 80% of the oil from the Neuquén Basin. With over 60 years of history, the company focuses on sustainable operations, safety, and infrastructure maintenance, having recently extended its national concession until 2037.
Sources
- Victim siteoldelval.com
Source
Indexed 6 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

