Ransomware group dragonforce hits Criba
Criba — a technology target operating in AR has been listed by the dragonforce ransomware group on 2026-08-24. The information below reflects what the threat actor has publicly claimed on their leak site; the details have not been independently verified.
Incident Report
| Target Organization | Criba |
|---|---|
| Threat Group | dragonforce |
| Summary | (release includes data on Argentina, Uruguay, and other countries, as well as financial documents and client documentation, including a vast amount of information not intended for public disclosure) CRIBA Empresa Constructora Argentina specializes in providing comprehensive solutions for every stage of construction projects, leveraging over 70 years of experience. The company focuses on quality, efficiency, and safety, ensuring that they can execute even the most ambitious architectural designs. Their portfolio includes a variety of projects such as commercial offices, healthcare facilities, and residential buildings. CRIBA is committed to maintaining a zero-accident policy, prioritizing the safety of their workforce. |
| Date of Breach | 2026-08-24 |
| Discovery Date | 2026-08-24 |
| Region | AR |
| Target Domain | criba.com.ar |
| Business Sector | Technology |
| Severity | MEDIUM |
Claim by dragonforce
(release includes data on Argentina, Uruguay, and other countries, as well as financial documents and client documentation, including a vast amount of information not intended for public disclosure) CRIBA Empresa Constructora Argentina specializes in providing comprehensive solutions for every stage of construction projects, leveraging over 70 years of experience. The company focuses on quality, efficiency, and safety, ensuring that they can execute even the most ambitious architectural designs. Their portfolio includes a variety of projects such as commercial offices, healthcare facilities, and residential buildings. CRIBA is committed to maintaining a zero-accident policy, prioritizing the safety of their workforce.
Posted by the dragonforce threat actor on its public leak site. This is the group's own statement and has not been independently verified by HackerFeeds.
Sources
Victim website
criba.com.ar
Leak post (onion / Tor)
http://z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid.onion/blog/?post_uuid=5cf8c483-41c0-4da7-800e-fcdbe6a0819b
Open this URL in Tor Browser. Browsing leak sites carries real risk — view passively, never click further.
Disclaimer
HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.

