Quick Summary
AllegedExecutive Summary
Mercado Libre, a prominent technology company based in Argentina, has been listed on the dark web portal of the TheGentlemen ransomware group, with the incident published on July 7, 2026. This discovery was made through SOCRadar’s Dark Web Monitoring service. While Mercado Libre operates consumer-facing platforms across Latin America, its profile as a large Argentine technology company differs from TheGentlemen’s typical targeting of the business services, manufacturing, and healthcare sectors, predominantly in the United States, Germany, and India.
Technical Analysis
SOCRadar’s analysis of stealer-log telemetry revealed a limited exposure related to the mercadolibre.com.ar domain, consisting of 25 credentials tied to public-facing customer registration and password-management endpoints. No corporate employee credentials or high-value identity, mail, or VPN endpoints were compromised. This exposure indicates a risk of customer account takeovers rather than a corporate intrusion. The observed credentials are not believed to be directly linked to the TheGentlemen listing, and CTI teams are advised to treat the listing with skepticism and monitor for any corroborating corporate domain exposure.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.