On December 14, 2025, Argentina’s largest state-owned water and sanitation utility, AYSA, appeared on the leak site of the safepay ransomware group. The company, formally known as Agua y Saneamientos Argentinos Sociedad Anónima, confirmed that internal files had been exfiltrated during a ransomware attack. While the exact number of people affected remains unknown, any customer, employee, or contractor whose personal information passed through AYSA’s systems could now face heightened risk of identity theft and harassment.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch aysa.com.ar
Get alerted the next time aysa.com.ar files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about aysa.com.ar’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that safepay posted proof of the breach on its dark-web leak site, listing AYSA (aysa.com.ar) as a victim. The data exposed consists of internal files exfiltrated before the ransomware was deployed. No precise volume or sample of records has been publicly detailed, but the listing itself signals that negotiations between the utility and the attackers failed or were never completed. The incident follows the typical ransomware pattern of initial access, data theft, encryption, and subsequent extortion through public shaming.
Why This Matters for You and Your Family
If you or anyone in your household has ever been an AYSA customer in Buenos Aires or the surrounding provinces, your name, address, national ID number, contact details, or billing records may now sit in a criminal database. Even if you are not a direct customer, employees’ payroll files, vendor contracts, or partner databases can contain information that links back to you. Once stolen, these records rarely stay isolated. They are sold, traded, and combined with other leaks to build complete profiles that criminals use for everything from account takeovers to physical intimidation. Your family’s daily life — paying water bills, updating contact information, or even applying for government services — can become the entry point for larger attacks.
The Doxxing and Identity-Chain Risks
Credential leaks like this one frequently cascade far beyond the original victim list. A single email address or phone number allegedly taken from AYSA’s internal files can be matched against gaming accounts, social-media handles, and school registrations. Attackers then follow the chain to dox family members, including children whose usernames on popular games are often tied to the same household address or parent email. Public reporting shows that ransomware groups increasingly publish or sell this linked data to amplify pressure on victims and to profit twice — once from the company and again on underground markets. The result is a map that leads directly from a utility bill to your family’s online identities.