ARSAT corporate-systems compromise and Play ransomware leak (Argentina, 2022)
What happened
On 30 November 2022, ARSAT, the Argentine state-owned satellite and telecommunications operator, was hit by a cyberattack. ARSAT stated the same day that the incident brought down its corporate-systems area, that only the company's internal systems were affected, and that no service and no customer data were affected. The attack fell on the day of Argentina's World Cup match against Poland, which ARSAT's terrestrial digital television network was carrying, and ESET's regional research team reported that a successful attack could have interrupted the broadcast nationally. The Play ransomware group subsequently listed ARSAT on its leak site with a payment window running 16 to 23 December 2022, and at the end of December part of the stolen material was published. No source cited here characterises the contents of the published material, and no source reports that ARSAT's satellite systems, its SSGAT geostationary satellites, or its ARSAT-1 and ARSAT-2 spacecraft were reached.
ONE TECHNIQUE EDGE, AND THIS GLOSS CALLED THE RECORD EDGE-LESS FROM 2026-08-05 UNTIL 2026-08-22. It carries EX-0010.01 Ransomware at derived/moderate, recovered under decision 67 because the earlier rejection turned only on SPARTA writing that technique as ransomware on a spacecraft. The zero-edge precedent this sentence used to cite, gonets-ground-crm-compromise-2022 and starlink-api-ddos-2022, still holds for those two records and no longer describes this one. A ransomware compromise of a satellite operator's corporate IT estate is enterprise IT: ARSAT states the satellite systems were not the route in. What was published is known by file name and not by content: Clarin carries the threat analyst Mauro Eldritch reading Play's manifest, a text file listing the names of the leaked files rather than the files, which names the Gerencia de Servicios Satelitales and lists financial and personnel documentation, administrative data on services provided, meeting minutes, digitised scans, copies of internal emails, material on the ARSAT-1 and ARSAT-2 projects, and a plaintext file called "Contrasena regeneracion recibos". ARSAT told the same paper the extracted data lacks strategic value because it is the management-control information the company reports or must report. SPARTA's bibliography cites this incident at REC-0003, REC-0008, REC-0009 and IMP-0006, but a bibliography citation is not a mapping, and each of those four requires a claim about what information the adversary obtained that no source supports. The four bibliography citations above remain unmapped. The record is worth keeping because a state satellite operator confirming a ransomware intrusion, and a ransomware group then publishing part of the proceeds, is the documented shape of the risk even where the contents are not known. Record confidence moved from low to moderate on 2026-08-18 under decisions entry 157, on the reading in docs/audits/2026-08-18-entry-148-confidence-value-audit.md: the account is established and what is missing is not the account. Entry 148 puts the actor and any one mapping outside this axis.
Attack vector
Not established by any source cited here. ESET reports the attackers attempted access through the corporate systems rather than the satellite systems; the initial access method is not reported.
Operational impact
ARSAT states no service and no customer data were affected. The corporate-systems area went down. ESET notes the broadcast of the World Cup match carried by the TDA terrestrial television network could have been interrupted had the attack succeeded further, which is a stated risk rather than a reported effect.
Data compromised
Unspecified. Play published part of the material it took; no source cited here describes its contents.
Disclosed
2022-11-30
SPARTA techniques evidenced
Each row is a technique this record evidences, with the reasoning and the source that attests to it.
What relationship, confidence, and evidence mean on the rows below
- Relationship
What kind of link this is between the technique and the target.
Mitigates: the target actively prevents, detects, or recovers from the technique.
Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.
Triggers obligation: the technique occurring is what triggers the duty the target imposes.
Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.
- Confidence
How strongly the source supports this mapping, not how severe the technique is.
High: the source supports the mapping squarely.
Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.
Low: the source reaches the technique only in part.
- Evidence
How close to the source text the mapping was made.
Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.
Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.
Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.
ARSAT states the attack brought down its corporate-systems area; the Play ransomware group later listed ARSAT on its leak site with a 16-23 December payment window and published part of the material at the end of December. Ransomware denying an organisation the use of its own systems and converting that denial into extortion leverage is EX-0010.01's behaviour. Derived because no cited source states directly that systems were encrypted: the outage is ARSAT's account and the encryption is inferred from the group's operating model and its leak-site process. Recovered per decision 67: previously rejected only because SPARTA writes EX-0010.01 as ransomware on a spacecraft. The other four rejections on this record stand, because they fail on what no source reports rather than on segment.
Considered and not mapped
These techniques were considered for this record because a source, a related record or SPARTA's own catalogue pointed at them. Each was read against what the sources say and not mapped. The reason is given in full.
Covers operator workstations, mission control software, antenna control, key-loading tools, data gateways. Re-evaluated under decision 67 and held. The ruling removes the segment restriction, but ARSAT states affirmatively that the satellite systems were not the route in and that only the corporate-systems area was affected. That is the source reporting the technique's object was not reached, which is an evidentiary bar the ruling does not lower.
SPARTA writes IMP-0006 as theft of "the data that is being gathered, processed, and sent from the victim spacecraft". Material was taken and published, but from the corporate systems, and ARSAT states the satellite systems were not the route in.
REC-0003 is about assembling the mission's RF and networking posture: bands, modulation, link budgets, station locations, handover rules. Nothing is reported about the contents of the leak.
Requires the adversary to be mapping manufacturers, logistics routes, integrator touchpoints or procurement artefacts. Same defect: the contents are unreported.
The most tempting of the four, and Clarín is why: it reports that Play's manifest lists "información de los proyectos ARSAT-1 y ARSAT-2 y otros programas", so a cited source names material on both spacecraft programmes. The same article defines those manifests as .txt files the group generates containing the list of the names of leaked files. REC-0009 is the adversary compiling a CONOPS-level portrait of the mission, its mode logic, duty cycles, operational constraints and contingency concepts, and a file name that mentions a programme does not report what the file holds. What these files contain is described by no source here.
Sources
The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.
A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.
- ARSAT sufrió un ciberataque que solo afectó a sus sistemas internosVendor threat intelligence
Tier 2: Named vendor research team (ESET Latin America) reporting ARSAT's own same-day statement. Closest thing to a first-party account that could be retrieved; ARSAT's original Twitter statement is quoted rather than read directly.
Tier 3: Security trade press reporting the leak-site listing. States in terms that the details of the data accessed were not disclosed.
- Publican parte de los datos robados a Arsat luego de ser encriptados por un grupo de ransomwareTrade presssupporting
Tier 3: General-interest Argentine daily. SPARTA's own bibliography cites this URL at four techniques.
- Argentina | Publican parte de los datos robados a Arsat luego de ser encriptados por un grupo de ransomwareTrade presscorroborating
Tier 3: Regional telecoms trade press. A news brief that reports the publication of the stolen data and points to the Clarín report for detail.
Every source SafeMode Space reproduces, and on what terms: sources and attribution.