Menu
Browse

Cyber Incident Victim: Policía de Seguridad Aeroportuaria

Date:

Jan 2025

Location:

Argentina

Summary

Hackers compromised Argentina's airport security police payroll system through a vulnerability in Banco Nación, the agency's payroll processor, resulting in unauthorized deductions from employee salaries labeled with false descriptors. The attackers extracted funds ranging from approximately $100 to $245 per transaction while accessing personal and financial data of officers and civilian personnel. The agency responded by blocking certain services and initiating cybersecurity awareness training, though neither the organization nor the bank has publicly confirmed the breach. The operation's origin—potentially involving internal collaboration or foreign actors—and motivation remain undetermined, mirroring recent cyber incidents affecting other Argentine government and financial systems.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 2 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

In early January 2025, Argentina’s Policía de Seguridad Aeroportuaria (PSA) experienced a cyberattack compromising its payroll system, impacting officers and civilian personnel. Unknown threat actors exploited a vulnerability in Banco Nación’s infrastructure—the bank responsible for processing PSA salaries—to access payroll records. The attackers made unauthorized deductions ranging from 2,000 to 5,000 pesos ($100 to $245) from employee accounts, disguising transactions under fabricated labels such as “DD mayor” and “DD seguros.” Local media reported the breach on January 1, citing internal PSA sources, though neither the agency nor Banco Nación publicly confirmed the incident. The attackers’ operational base remained unclear, with speculation about potential foreign involvement or domestic collaboration, including internal accomplices. The breach exposed personal and financial data of PSA personnel, though the total number of affected individuals and exact scope of data exfiltrated were not disclosed.

Cyber Incident Image

In response, PSA temporarily disabled certain services to contain the breach and initiated an internal cybersecurity awareness campaign for staff. The agency did not specify which services were blocked or the duration of disruptions. Authorities had not determined whether the attack was financially motivated, politically driven, or a combination of both by the time reports emerged. The cumulative financial losses from fraudulent salary deductions remained unquantified, and no threat actor claimed responsibility. This incident followed broader cybersecurity challenges in Argentina, including December 2024 breaches of government platforms Mi Argentina and SUBE, though no direct link between these events was established. PSA’s investigation continued without public updates on forensic findings or recovery timelines.

Sources
Sources available to members
1 source