Cyber Incident Victim: Aceitera General Deheza
Date:
Aug 2022
Location:
Argentina
Summary
Aceitera General Deheza (AGD), an Argentinian agribusiness, experienced a ransomware attack where attackers demanded payment to restore data. The company activated security protocols, initiated system recovery using backups, and filed a legal complaint citing exemptions from regulatory forms during the incident. AGD's president refused ransom payment, asserting no data was compromised and anticipating near-complete system restoration shortly. Production operations continued uninterrupted throughout the response.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
Aceitera General Deheza (AGD), an Argentinian agribusiness, experienced a ransomware attack on August 10, 2022. The company publicly disclosed the incident, confirming unauthorized access to its computer systems. Attackers demanded payment in exchange for data recovery, though AGD did not specify the ransom amount or the identity of the threat actors. Upon detecting the intrusion, AGD activated established security protocols to contain the incident. The company initiated a thorough analysis of the breach and formally reported the event to relevant authorities. Production operations continued uninterrupted throughout the response period, with no reported downtime affecting manufacturing or business activities.

AGD President Roberto Urquía explicitly stated the company would not pay any ransom, asserting that attackers had failed to compromise critical data. He emphasized that backup systems would enable full data restoration, projecting 90% system recovery by the following Tuesday. The company filed a legal complaint addressing both the cyberattack and resulting regulatory complications, as the incident prevented timely submission of mandatory national and provincial documentation. Authorities granted AGD exemptions for these compliance failures directly stemming from the attack. No customer data breaches or operational disruptions beyond administrative reporting obligations were disclosed in available reports. The organization maintained public communications through media statements while conducting internal recovery efforts using preserved backups.
