ShellCodeX
Tools • Events • News • Insights
Victim Claim

Oleoductos del Valle

● Listed in the last 48h
incransom 🇦🇷 Argentina Energy & Utilities
Claimed by incransom
Listed on leak site 04 Aug 2026
Reported attack date 03 Aug 2026
Group claims tracked 134
Unverified claim. This entry reproduces a listing published by the incransom group on its own extortion site. Attackers routinely exaggerate or fabricate victims. Nothing here confirms that Oleoductos del Valle suffered a breach, or what data was actually taken.

About the organisation

During the analysis of data obtained from Oldelval, we have compiled information covering key aspects of the company's operations. The materials include: 1.HR documentation: full payroll data, bank account details (CBU), employee health insurance records (OSDE, SWISS MEDICAL), as well as severance calculations and compensation agreements. 2.Financial and regulatory reports filed with CNV and BYMA, including documents related to rating agencies (Moody's) and internal shareholder agreements. 3.Tax declarations and reports submitted to AFIP (Sicore, Ganancias, DDJJ IVA). 4.Documents related to tariff policy and SEN interactions, including WACC and TIR calculations used in tariff reviews. 5.Incident reports and environmental documentation, including reports on spills in Catriel and Medanito, as well as Rosen OSSR technical reports on pipeline conditions. 6.Confidentiality agreements with key partners, including Halliburton, Horizon, YPF, Otasa, McKinsey, and KPMG. 7.Internal whistleblower channel materials (Ley 27.401), including internal complaints and compliance reports. 8.Documents related to dividend payments and banking transactions. 9.Personal data of directors, candidates, and key employees, including ID numbers and CVs.

What the listing means

Oleoductos del Valle appeared on the incransom leak site on 04 August 2026. Groups publish a victim once negotiations stall or as pressure during them, so a listing usually means data was already exfiltrated. This group has published 34 claims in the last 30 days and remains active.

Recommended actions

  • Treat any unsolicited message referencing Oleoductos del Valle as suspicious — leaked data gets weaponised for phishing within days.
  • If you hold an account with this organisation, change the password now and enable two-factor authentication.
  • Other Energy & Utilities organisations should review this group's known TTPs and validate detection coverage against them.
  • Watch for follow-on extortion: stolen data is often re-leaked or resold after the initial listing.
  • A leak-site listing is a claim made by the attacker, not a confirmed breach — check the organisation's own disclosures before acting on it.

Leak-site evidence

Listing URL https://www.ransomware.live/id/T2xlb2R1Y3RvcyBkZWwgVmFsbGVAaW5jcmFuc29t

Show leak-site screenshot

Captured from the group's extortion site. It may contain the victim's data or the attacker's messaging.

Screenshot of the incransom leak-site listing for Oleoductos del Valle