Fabricaciones Militares
Incident posture
Linked entities
- Victim
- Fabricaciones Militares
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
Fabricaciones Militares suffered a ransomware attack carried out by the group MONTI, which encrypted systems and exfiltrated over 300 gigabytes of data including plans for advanced weapons projects such as upgrades to the TAM 2IP main battle tank and development of a CH‑14 helicopter. The attackers claimed responsibility, criticized the company’s insufficient cooperation, and indicated that negotiations for data recovery are underway. The breach aligns with an Interpol warning about ransomware groups targeting defense contractors in neutral countries and follows a series of hacks on Argentine government sites. The incident occurs while the state‑owned manufacturer is being restructured into a public limited company and faces possible privatization, raising concerns about the security of sensitive defense information and the impact on its workforce.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On 1 March 2025, reports emerged that Fabricaciones Militares, Argentina’s state‑owned military manufacturing company, had suffered a ransomware attack. The attack was first disclosed by the specialist outlets FalconFeeds.io and Cyber Press, which identified the responsible group as MONTI. According to those sources, MONTI claimed responsibility for the intrusion and announced the theft of more than 300 gigabytes of data. The group also posted a message on its dark‑web portal mocking the company’s management for what it described as insufficient cooperation, indicating that negotiations were underway to attempt to recover the stolen information.
Fabricaciones Militares is a key entity in Argentina’s defense industry and the parent of the Villa María Military Powder and Explosives Factory, which is currently in transition to become a public limited company as part of a government‑announced privatization process under President Javier Milei. The stolen data reportedly includes sensitive plans for cutting‑edge weapons projects, specifically the upgrade of the TAM 2IP main battle tank and the development of a CH‑14 helicopter. The article notes that the attack coincides with an Interpol alert issued in 2024 warning of increasing ransomware interest in defense contractors located in geopolitically neutral countries. It also follows a series of hacks at the end of 2024 that compromised the “Mi Argentina” platform and around twenty official government sites, underscoring existing cybersecurity weaknesses in the public sector.
The breach has generated considerable concern among Argentine authorities because of the potential exposure of future defense capabilities and the strategic implications for ongoing modernization programs. More than a thousand workers at Fabricaciones Militares face uncertainty about their employment as the company’s equipment and vehicles are being auctioned off amid expectations of privatization by firms linked to NATO and the United States. The official response has been marked by silence, with no public statements from government officials detailing containment measures or mitigation steps taken after the incident.
Sources
Sources available to members: 1 source.