CSIDB logo
Incident

Senado de la Nación Argentina

Incident posture

Attack window
Apr 2022
Location
Argentina
Status
Historical
CIA posture
Available to members
Updated
2025-10-19 00:00

Linked entities

Victim
Senado de la Nación Argentina
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Apr 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Senado de la Nación Argentina experienced multiple cyberattacks, including a recent denial-of-service incident that temporarily disrupted its website by overwhelming servers with excessive traffic. This followed a more severe prior ransomware attack that compromised internal systems, leading to the theft of sensitive employee data such as fingerprints, identification documents, and operational records, despite initial claims that only publicly accessible information was affected. The ransomware incident caused prolonged operational disruptions and preceded another unrelated breach targeting a national registry entity.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On April 21, 2022, the official website of Argentina's Senado de la Nación became inaccessible due to a cyberattack, marking the second major incident targeting the chamber within three months. The attack was identified as a denial-of-service (DoS) operation that overwhelmed the Senate's servers with excessive traffic, preventing legitimate users from accessing the site. Service was restored approximately 30 minutes after the disruption began. This incident followed a significantly more severe ransomware attack on January 12, 2022, which had occurred at 4:00 AM and crippled Senate operations for weeks, including during the critical period preceding the March 1 opening of ordinary legislative sessions. The April attack demonstrated persistent vulnerabilities despite prior compromises.

The January ransomware incident involved attackers encrypting Senate systems and exfiltrating sensitive data. Initially, the Senate's official Twitter account downplayed the severity, asserting that stolen information was publicly available through transparency portals. Subsequent investigations revealed extensive data breaches, including employee databases containing personal identifiers, passport details, digital fingerprints, salary records, and internal operational documents. The attackers demanded a ransom for decryption, though the Senate did not disclose whether payments were made. Operational recovery spanned weeks, with systems remaining partially impaired during legislative preparations. The discrepancy between initial official statements about the nature of the stolen data and later evidence of sensitive information exposure underscored the attack's severity. Both incidents collectively highlighted systemic cybersecurity challenges within the institution, with the April DoS attack serving as a reminder of unresolved infrastructure weaknesses following the January breach.

Sources

Sources available to members: 1 source.

CSIDB