Oleoductos del Valle
● Listed in the last 48hAbout the organisation
During the analysis of data obtained from Oldelval, we have compiled information covering key aspects of the company's operations. The materials include: 1.HR documentation: full payroll data, bank account details (CBU), employee health insurance records (OSDE, SWISS MEDICAL), as well as severance calculations and compensation agreements. 2.Financial and regulatory reports filed with CNV and BYMA, including documents related to rating agencies (Moody's) and internal shareholder agreements. 3.Tax declarations and reports submitted to AFIP (Sicore, Ganancias, DDJJ IVA). 4.Documents related to tariff policy and SEN interactions, including WACC and TIR calculations used in tariff reviews. 5.Incident reports and environmental documentation, including reports on spills in Catriel and Medanito, as well as Rosen OSSR technical reports on pipeline conditions. 6.Confidentiality agreements with key partners, including Halliburton, Horizon, YPF, Otasa, McKinsey, and KPMG. 7.Internal whistleblower channel materials (Ley 27.401), including internal complaints and compliance reports. 8.Documents related to dividend payments and banking transactions. 9.Personal data of directors, candidates, and key employees, including ID numbers and CVs.
What the listing means
Oleoductos del Valle appeared on the incransom leak site on 04 August 2026. Groups publish a victim once negotiations stall or as pressure during them, so a listing usually means data was already exfiltrated. This group has published 34 claims in the last 30 days and remains active.
Recommended actions
- Treat any unsolicited message referencing Oleoductos del Valle as suspicious — leaked data gets weaponised for phishing within days.
- If you hold an account with this organisation, change the password now and enable two-factor authentication.
- Other Energy & Utilities organisations should review this group's known TTPs and validate detection coverage against them.
- Watch for follow-on extortion: stolen data is often re-leaked or resold after the initial listing.
- A leak-site listing is a claim made by the attacker, not a confirmed breach — check the organisation's own disclosures before acting on it.
Leak-site evidence
Listing URL https://www.ransomware.live/id/T2xlb2R1Y3RvcyBkZWwgVmFsbGVAaW5jcmFuc29t
Show leak-site screenshot
Captured from the group's extortion site. It may contain the victim's data or the attacker's messaging.