Skip to content
Back to Blog
high severity June 11, 2023 · 4 min read Unverified claim — what this is

Comisión Nacional de Valores Listed by Medusa Ransomware Group

If you are a customer of Comisión Nacional de Valores, here’s what is being claimed, and what it would mean for you.

Regulatory agency in charge of authorizing IPOs and securing compliance by market participants with federal securities laws in the Argentine Republic. It supervises brokerage firms, issuers, stock exchanges, mutual funds and credit rating agencies. It is a member of IOSCO. More than 1.5TB of documents & database dumps has been uploaded.

— from Medusa’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Comisión Nacional de Valores Listed by Medusa Ransomware Group

On June 11, 2023, the Comisión Nacional de Valores, Argentina’s national securities regulator, appeared on the leak site of the Medusa ransomware group. The listing states that the agency suffered a ransomware attack in which internal files were exfiltrated; more than 1.5 TB of documents and database dumps have already been published on the extortion portal.

Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →

Watch Comisión Nacional de Valores

Get alerted the next time Comisión Nacional de Valores files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.

We’ll email you only about Comisión Nacional de Valores’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.

Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.

Reported Details from the Listing

The Medusa leak site entry, still accessible via the .onion link, identifies the Comisión Nacional de Valores as a victim and confirms that attackers extracted internal files during a ransomware incident. The disclosure does not specify the exact number of individuals whose records were taken, nor does it list every data type exposed. It does state that the stolen material includes both documents and database dumps totaling more than 1.5 TB. No ransom demand figure is published on the page, and the listing does not indicate whether the agency paid or refused to pay.

Why This Matters for You and Your Family

When a national securities regulator is breached, the consequences reach far beyond corporate boardrooms. Investors, brokerage customers, mutual-fund holders, and anyone whose identity or financial activity appears in CNV-supervised records may now face heightened risk. If your broker, issuer, or credit-rating file was among the exfiltrated material, your name, tax identifiers, contact details, or transaction history could be sitting in an attacker-controlled archive. That information sells quickly on underground markets and can be used to file fraudulent tax returns, open accounts in your name, or pressure you with targeted phishing. Even if you never directly interacted with the CNV, shared service providers or counterparties may have routed your data through systems now confirmed compromised.

Exposure Pack · one payment
The full list, and what to lock in ten minutes.
  • Every indexed leak tied to your address — all of them, named and dated
  • A deeper search of collected breach data — the kinds of your information it holds, where it finds you
  • What this kind of incident typically exposes
  • A ten-minute lock list written for this kind of organisation
One payment. Nothing renews, and no account is created. Emailed to you within a minute.

The Doxxing and Identity-Chain Risk

Leaked regulatory documents frequently contain more than dry compliance forms. They often link personal identifiers to email addresses, phone numbers, employer details, and sometimes family-member information. Attackers chain these fragments with data from previous breaches to build complete identity profiles. A single exposed email can unlock linked gaming accounts, social-media handles, or cloud storage belonging to you or your children. Credential leaks of this nature routinely cascade into account takeovers that expose private messages, location history, and photographs. Continuous monitoring across 13.1B+ breach records and 100+ platforms is therefore essential, because the first time you learn of the exposure is rarely the last time the data is reused.

Medusa’s Publicly Known Track Record

Public reporting attributes Medusa’s first major campaigns to late 2021. The group operates a double-extortion model: it encrypts victim networks and simultaneously exfiltrates data before threatening to publish it. Notable prior victims include manufacturing firms, healthcare providers, and government-adjacent entities across multiple continents. Medusa typically gains initial access through compromised remote-desktop credentials or vulnerable web applications, then moves laterally to locate high-value file servers. After exfiltration, the group posts samples on its leak site and sets a deadline for payment. If none is received, larger portions of the stolen archive are released in batches. The Comisión Nacional de Valores listing follows this exact playbook.

What to do

  • Run a DoxxScan to map every link between your handles, emails, phone numbers, and real identity, then use the cleanup to remove what you can.
  • Rotate any password you used at the Comisión Nacional de Valores or any Argentine brokerage it regulates, and enable 2FA through an authenticator app rather than SMS.
  • Enable continuous DoxxScan monitoring so the next breach exposing your household is caught and acted on within hours instead of months.
  • Cover the entire household — DoxxScan family coverage extends to dependents and children’s gaming accounts that often chain back to the same address or parent email.
  • Let remediation specialists handle takedown requests across data-broker sites and extortion portals on your behalf.

The breach of a national securities regulator reminds us that even institutions tasked with protecting market integrity can become unwilling gateways for identity compromise. One practical forward step is to treat every new leak as a prompt to lock down the chains that lead back to you and your family. DoxxScan’s continuous monitoring across 13.1B+ breach records and 100+ platforms, combined with AI-powered identity-chain mapping and hands-on remediation by specialists, gives households the visibility and response capability that used to be available only to large organizations. Start that process before the next wave of Medusa releases makes today’s 1.5 TB archive look small.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove — and removing them is what we do.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample580 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Check your exposure
Comisión Nacional de Valores is one listing. Your email is probably in others.
We can’t confirm any single incident against the sources we search, so we won’t pretend to. What we can show you is your own exposure — your email against 13.1B+ leaked records and the sites that publish your address. About 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High the filing does not enumerate what was exposed
Disclosed June 11, 2023
Last reviewed August 8, 2026
Affected Unconfirmed
Unverified claim — what this report is
This page documents a public listing on a ransomware/extortion group’s leak site, tracked via public threat-intelligence sources. A listing is the attacker’s claim. GalaxyWarden aggregates and reports such claims; we have not independently verified that a breach occurred, what data (if any) was taken, or the accuracy of anything the group asserts, and the named organisation has not necessarily confirmed the incident. Sections above describe what the listing shows and the group’s documented history — not verified findings about the named organisation. If you represent this organisation and believe anything here is inaccurate, tell us and we’ll review it promptly.
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email