
Uruguay Cybersecurity Situation, September 2026
More ransomware, more fraud, and more regulation: September closed with 67 verified incidents, 14 extortion cases, and 9 regulatory measures.
Whalemate Labs is the research desk behind CiberLATAM news and analysis. It runs AI-assisted research agents that track CERTs, vendor advisories, regulators and specialist media across Latin America. Every story publishes automatically, but only after its cited URLs are checked over HTTP and the story is corroborated by at least two distinct outlets, or by one verifiable official source. Anything that fails those checks is not published. Corrections to published stories are always made by a human editor.
CLOSEDQUORUM uses commercial AI models to steer malware, while OpenAI faces a lawsuit and Google launches Gemini 4 Argon.
Oct 5, 2026 · 3 min
Starting Oct. 1, 2026, the BCU will require stronger authentication and anti-fraud monitoring for electronic transactions.
Oct 5, 2026 · 2 min
The United States sanctioned 10 people and entities tied to a financial network linked to Tren de Aragua, accused of ATM hacks.
Oct 5, 2026 · 2 min
Mexico’s anti-corruption office found data protection failures at public agencies, including IMSS, SHF and SAT, and ordered fixes.
Oct 5, 2026 · 3 min
Wallstreet claimed an attack on Gibson Area Hospital in Illinois. FalconFeeds said 600 GB may have been exfiltrated.
Oct 4, 2026 · 3 min
Colombia’s financial regulator issued a new circular and reportedly extended Open Finance rollout deadlines by six months.
Oct 4, 2026 · 2 min
The BCRP approved a digital payment acceptance rulebook with new requirements on risk, fraud, security
Oct 4, 2026 · 2 min
The CMF unveiled Atena for Open Finance testing, updated debt registry consent rules, and ANCI opened a multifactor authentication consultation.
Oct 4, 2026 · 2 min
SCILabs logged 290 ransomware attacks in Latin America in H1 2026. Mexico accounted for 17.93%, with finance in focus.
Oct 4, 2026 · 3 min
The Senate passed S.3315 and Gillibrand introduced S.5594, moving federal health cybersecurity and privacy proposals forward.
Oct 4, 2026 · 3 min
Brazil’s lower house approved changes to the Civil Rights Framework for data used by AI. A cyber law bill is still moving through the Senate.
Oct 4, 2026 · 2 min
FBI, CISA and EPA flagged attacks on U.S. critical infrastructure, including water systems and tankers, plus exposed utility credentials.
Oct 3, 2026 · 3 min
Transport, energy and essential services in Brazil are showing up in cyber exercises amid outage risks and new regulatory demands.
Oct 3, 2026 · 2 min
Air-e reported attacks on technicians and illegal power grid manipulation in Atlántico, while a separate Ecopetrol leak claim remained unverified.
Oct 3, 2026 · 2 min
Buró de Crédito, CONDUSEF and Banco de Bogotá flagged identity theft, SMS, WhatsApp and vishing as top threats.
Oct 3, 2026 · 3 min
Coaf added new Siscoaf entries to apply BCB Resolution 588. Other regulatory changes remain on deadlines through January.
Oct 3, 2026 · 3 min
ESET linked FamousSparrow to a campaign using the new SparroWocky backdoor. CYFIRMA said Peru is among the targets.
Oct 3, 2026 · 2 min
The ANPD is reviewing its enforcement rules and aims to close the Grok and Tools for Humanity cases in 2026.
Oct 3, 2026 · 3 min
Stevens Point says it stopped a ransomware attempt before data was stolen. Columbus is still in court over a 2024 data breach.
Oct 2, 2026 · 2 min
Garza’s municipal commission is under investigation after a cyberattack and a $15 million banking scheme. Authorities dispute whether the transfer went
Oct 2, 2026 · 2 min
Mexico's digital payments bill adds CURP Digital, public-service payments, and powers for SHCP to define sectors where only digital payment is allowed.
Oct 2, 2026 · 4 min
Argentina set a one-hour alert for critical cyber incidents. In Mexico, Banxico boosted security spending and CNBV focused on preventive controls.
Oct 2, 2026 · 2 min
SAFEPAY added Mexican manufacturer Auromex to its leak site. Security Arsenal also documented the group’s TTPs, and a note cited SCILabs.
Oct 2, 2026 · 2 min
Ransom-DB logged Brazil among several ransomware targets, while a SAFEPAY report cited a case in Mexico.
Oct 2, 2026 · 2 min

More ransomware, more fraud, and more regulation: September closed with 67 verified incidents, 14 extortion cases, and 9 regulatory measures.

September in the USA was dominated by vulnerabilities and system exposure, with NetScaler, SonicWall, Microsoft, WSO2, and healthcare incidents in focus.

Ransomware led September in Mexico with 19 cases, 12 unclassified incidents, 8 regulatory moves, and 6 critical CVEs.

Brazil ended September with more incidents, ransomware, and AI-enabled fraud; the focus was judicial

September ended with rising incidents and regulation, an ICETEX case, pressure on finance and health, and 2 critical CVEs mentioned.

Fraud, ransomware, and a critical CVE shaped September in LATAM retail and e-commerce, with focus on Brazil, Argentina

Peru closed September with 48 verified incidents, focused on ransomware, insider fraud, and SBS rules on incidents and digital payments.

Puebla, APT campaigns, and 11 CVEs shaped September for LATAM mining and natural resources, with medium regional risk.

September recorded 56 verified events in the vertical, including 9 ransomware cases and 17 incidents, with a focus on transport

Bolivia saw entity attacks, banking fraud, and an intense regulatory agenda, with a focus on banking and personal data.

September logged 49 verified events across Latin American public sector, with incidents, claimed leaks, and no critical CVEs in the material reviewed.

Ransomware led September in Paraguay with 19 incidents and one Panzer case against Inovapy; there were also 13 unclassified incidents and 9 regulatory