LIBRERIA SANTA FE A P S SRL Data Breach

Alleged

Vexy Ransomware claim involving LIBRERIA SANTA FE A P S SRL

Published: Sep 7, 2026
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
LIBRERIA SANTA FE A P S SRL
Industry
Retail & E-Commerce
Date of Incident
Sep 7, 2026

Executive Summary

Vexy Ransomware listed LIBRERIA SANTA FE A P S SRL on its dark web portal on September 7, 2026. LIBRERIA SANTA FE A P S SRL, operating under the names LSF and Librería Santa Fe, is a bookstore chain based in Buenos Aires, Argentina, with multiple physical stores and an online presence. The company belongs to the Retail & E-Commerce sector, which is frequently targeted by ransomware operations. In the preceding 60 days, Vexy Ransomware claimed 7 other victims across the Retail & E-Commerce, Other, and Manufacturing sectors. These victims were located in India, Argentina, and Mexico. Recent victims in Argentina within the retail space include Annapurna Fashion, Sancity, Mega Velocity, and Sancity Soft Touch. LIBRERIA SANTA FE A P S SRL’s listing aligns with Vexy Ransomware’s pattern of targeting mid-size retail operators in emerging markets.

Technical Analysis

SOCRadar’s telemetry identified 25 records associated with the domain lsf[.]com.ar. These records exclusively target e-commerce and customer portal authentication endpoints, with 8 specifically pointing to the customer portal login page at /clientes/new/login.aspx. Notably, no corporate email addresses using the domain @lsf.com.ar were found within the queried sample. Two temporal patterns were observed in the data. A significant portion of the records dates back to 2024 and 2025, still appearing in September 2026, suggesting persistent stealer activity or the use of unrotated credentials over an extended period. A more concentrated cluster of activity occurred from late August leading up to September 4, 2026, immediately preceding the ransomware listing date. This intensification of credential harvesting shortly before a listing is consistent with post-compromise exfiltration activities. The absence of corporate credentials within this specific data slice does not definitively rule out the exposure of employee accounts. The queried sample is paginated, and additional records, potentially including internal system credentials, may exist in data sources not covered by this analysis. The concentration of customer account data is consistent with the victim’s profile as a business with a customer-facing platform. The observed temporal pattern warrants ongoing monitoring of LIBRERIA SANTA FE A P S SRL’s authentication infrastructure and a proactive approach to rotating any unverified customer and operational credentials.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.