Criba Data Breach

Alleged

Ransomware claim involving Criba

Published: Aug 24, 2026 DragonForce
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Criba
Industry
Technology
Threat Actor
DragonForce
Date of Incident
Aug 24, 2026

Executive Summary

Criba, an Argentine technology company operating under criba[.]com[.]ar, was listed on DragonForce’s leak site on August 24, 2026. The targeting of an Argentina-based technology firm is consistent with DragonForce’s documented expansion into Latin American markets, extending the group’s reach beyond its core English-speaking geography. DragonForce claimed 48 victims in the preceding 60 days, with Business Services and Manufacturing as its primary sectors and the United States, UK, and China as the highest-volume target geographies. Argentina isn’t among the group’s most active geographies, but DragonForce has actively pursued tech-sector organizations across Latin America. Comparable victims in regional and tech contexts include Baicizhan, Intron Technology Holdings, HIVE360, and Petrini Valores.

Technical Analysis

SOCRadar’s stealer-log telemetry returned no records for criba[.]com[.]ar in the queried slice. The dataset is a paginated sample and won’t reflect all active log feeds, alternate domains, or credentials harvested under personal email aliases — coverage gaps are inherent to this kind of telemetry query. DragonForce’s access chain runs through IABs sourcing infostealer logs from underground markets, validating corporate credentials, then authenticating to Microsoft 365, VPN, or remote-access portals. Argentine technology companies frequently run Spanish-language portals and regional hosting infrastructure that may be underrepresented in current log feeds — stealer-log searches limited to the primary domain may undercount exposure here.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.