Cyber Incident Victim: The Argentinian National Institute of Statistics and Census
Date:
Dec 2022
Location:
Argentina
Summary
The Argentinian National Institute of Statistics and Census experienced a cyber incident involving a virus that compromised its hosting server and user validation system, forcing the organization to take its website offline and disconnect additional servers as a precaution. The malware, detected within a periodic backup, activated during a scheduled backup process and encrypted the virtual machine responsible for internal user authentication, prompting security testing before service restoration. While operational recovery was achieved, the disruption temporarily impacted system availability and user access.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
The National Institute of Statistics and Census (INDEC) of Argentina announced via social media on December 5, 2022, that its website had been taken offline due to a virus affecting its hosting server and user validation system. The institute proactively disconnected affected systems to prevent further spread and protect other servers and data. According to subsequent reporting by Infobae, the virus had been detected within INDEC’s periodic backup system. During a scheduled backup execution on the night of December 4-5, the virus activated and encrypted the virtual machine responsible for authenticating internal users. This encryption event prompted INDEC to deactivate remaining servers as a precautionary containment measure, resulting in widespread service unavailability. The institute did not initially disclose whether data exfiltration or deletion occurred, focusing instead on system isolation and recovery efforts.

INDEC restored its website by the evening of December 5, following security testing across all systems to ensure data protection. The institute publicly apologized for service delays, emphasizing that the extended downtime was necessary to validate system integrity before reconnection. No ransomware group claimed responsibility for the incident, and INDEC’s communications characterized the event strictly as a “virus” without referencing extortion attempts or data leaks. Operational impacts were confined to temporary website inaccessibility and authentication disruptions for internal users, with no explicit mention of compromised statistical data or long-term operational consequences. The response prioritized containment through server isolation, backup system scrutiny, and phased reactivation after verification.
