Policía de Seguridad Aeroportuaria
Incident posture
Linked entities
- Victim
- Policía de Seguridad Aeroportuaria
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
Hackers infiltrated the payroll system of Argentina’s airport security police by exploiting a vulnerability in the bank that processes salaries, diverting small sums from employees’ wages under false labels such as “DD mayor” and “DD seguros.” The agency responded by suspending some services and launching a cybersecurity awareness initiative while investigators examined whether the breach was financially or politically motivated and the total amount taken. Separate intrusions compromised government applications, a telecommunications provider, and a central bank database, exposing personal data and highlighting broader weaknesses in the nation’s digital infrastructure.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On Monday, January 1, 2025, local media reported that Argentina’s airport security police (PSA) had suffered a cyberattack in which an unknown threat actor gained access to the agency’s payroll records. The attackers allegedly exploited a vulnerability in the systems of Banco Nación, the bank that processes PSA’s payroll, to obtain unauthorized access. Once inside, they deducted small amounts of money from employees’ salaries, with the fraudulent withdrawals ranging from 2,000 to 5,000 pesos (approximately $100 to $245). These deductions were recorded under false labels such as “DD mayor” and “DD seguros” to conceal their nature. The reports indicated that the operation could have been conducted either from abroad or from within Argentina, with the possibility of internal accomplices cited by local sources.
In response to the incident, PSA blocked some of its services and initiated an internal cybersecurity awareness campaign for its personnel. Neither PSA nor Banco Nación have publicly commented on the allegations or acknowledged the breach. Authorities have not yet determined whether the attack was financially or politically motivated, nor have they disclosed the total amount of funds that may have been stolen. The article also notes unrelated cyber events in Argentina, including a December breach of the Mi Argentina and SUBE e‑government platforms that exposed personal data of millions and was attributed to the threat actor using the pseudonym "h4xx0r1337". Additionally, it mentions a July ransomware attack on Telecom Argentina that encrypted up to 18,000 workstations using stolen admin credentials and an April claim by hackers of accessing a Central Bank of Argentina database containing customer names and ID numbers.
Sources
Sources available to members: 1 source.