Menu
Browse

Cyber Incident Victim: Caja de Acción Social de San Juan

Date:

Apr 2025

Location:

Argentina

Summary

The official website of the San Juan SocialAction Fund was compromised, displaying an image of President Javier Milei accompanied by the message 'DO NOT PLAY QUINI, IT'S ALL A FARCE, THE SYSTEM WINS' and a signature attributing the act to @GOV.ETH with a link to T.ME/ELHACKERMASFamoso. The intrusion raised concerns about the transparency of provincial lottery games, though it remains unclear whether any user data was accessed or if the incident was isolated or part of a larger operation.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On April 6, 2025, users attempting to access the official website of the San Juan Social Action Fund to consult sweepstakes results and regular services encountered a defaced page. Instead of the expected institutional content, the site displayed a photograph of Argentine President Javier Milei. Accompanying the image was the text “DO NOT PLAY QUINI, IT'S ALL A FARCE, THE SYSTEM WINS.” The defacement included a signature attributing the message to @GOV.ETH and directing viewers to join T.ME/ELHACKERMASFamoso. The alteration was noticed immediately by visitors who were unable to perform their intended inquiries. The timing of the incident coincided with routine traffic to the site for lottery‑related information. No prior warning or indication of the compromise was reported by the organization.

Cyber Incident Image

The disruption prevented users from accessing sweepstakes data and other services offered by the San Juan Social Action Fund. Observers noted that the message cast doubt on the transparency of provincial lottery games, as referenced in contemporaneous reporting. At the time of publication, the identity of the perpetrators remained unknown, and it was unclear whether the act was isolated or part of a wider campaign. Additionally, there was no confirmation that any personal or financial data of users had been exfiltrated or otherwise compromised. The lack of clarity regarding data integrity left the potential scope of the breach undetermined. The incident highlighted vulnerabilities in the website’s security posture without detailing any specific remedial steps taken.

Sources
Sources available to members
1 source