Qilin and Fortinet Exploitation Keep Pressure on Chile as
Chile faced 8.8 billion cyberattack attempts in 2025, and between January and June 2026
Chile came under 8.8 billion cyberattack attempts in 2025, according to a regional report cited by G5 Noticias and La Tercera. That figure did not stand alone. The same SEK study, summarized by G5 Noticias and Zoom Tecnológico, recorded 58 incidents affecting or exposing Chilean organizations between January and June 2026. Of those, 18 ended up as data posts on ransomware leak sites and 40 appeared in dark web cybercrime forums. Within that ransomware subset, Qilin accounted for 61 percent of the leak-site posts, with 11 of 18 victims, making it the most active actor targeting Chile in that period.
Executive summary
Chile faced 8.8 billion cyberattack attempts during 2025, according to SEK’s regional report cited by G5 Noticias and La Tercera. That number does not by itself describe a specific intrusion, but it does show the scale of pressure on Chilean organizations. The same SEK research, also summarized by Zoom Tecnológico, recorded 58 incidents affecting or exposing Chilean organizations between January and June 2026. Of those, 18 became data posts on ransomware leak sites and 40 appeared in dark web cybercrime forums. Within the ransomware slice, Qilin accounted for 61 percent of the leak-site posts, with 11 of 18 victims, and was identified as the most active actor against Chile during that period.
The technical picture is consistent across several sources. Qilin, also known as Agenda, has operated as ransomware-as-a-service since 2022, encrypts Windows, Linux and VMware ESXi environments, and uses double extortion. Its initial access chain combines phishing, stolen credentials and exposed remote services, with a clear preference for VPN gateways and edge devices. The consolidated material repeatedly points to two Fortinet flaws, CVE-2024-21762 and CVE-2024-55591, as initial access vectors tied to Qilin campaigns. The first affects FortiOS and FortiProxy in SSL VPN, allows remote code execution and has been in CISA’s KEV catalog since February 2024. The second is an authentication bypass in FortiOS and FortiProxy, disclosed in Fortinet’s PSIRT advisory FG-IR-24-535 and also listed as actively exploited.
The exploitation pattern is not theoretical. Scrutex.ai, Paubox, Viakoo, The Hacker News, Arctic Wolf, Hispasec, Devel Group and the Canadian Centre for Cyber Security describe mass credential-compromise campaigns against FortiGate devices exposed to the internet. Estimates range from more than 30,000 to 86,644 compromised devices, with references to tens of thousands of additional systems affected or exposed. Bitsight details the use of legacy SHA-256 hashes and an offline cracking infrastructure built around 45 GPUs. The Hacker News adds that Fortinet attributed the activity to credential reuse from earlier incidents, along with brute force against devices with weak passwords and no MFA. Devel Group, meanwhile, reported a custom tool, FortiGateSniffer, that abuses the native diagnose sniffer packet command to silently intercept authentication and maintain persistence.
The regional dimension shows the Chile case is not isolated. Ransomware.live records 74 victims linked to Chilean organizations and lists Qilin victims on multiple dates in 2026, including Valbifrut, Graneles de Chile, Noi Hotels, SAAM Towage, Calidra and Comercial Echave Turri Limitada. Paraguay appears in Ransomware.live and Legal-ISAC dashboards as a jurisdiction with at least one victim associated with Qilin, while Bolivia appears in Scrutex.ai’s tally and Brazil shows up as a regional exposure and activity hub, with parallel phishing campaigns and compromised emergency alerts. Taken together, the data point to a ransomware ecosystem that shares infrastructure, affiliates and access vectors, and where Fortinet functions as a repeated entry point.
Context and background
The material paints a scenario in which the threat does not depend on a single malware family, but on a mix of actors, affiliates and RaaS brands that share techniques and infrastructure. Qilin emerges as the dominant actor in ransomware leak-site posts against Chilean organizations, but it does not operate alone. Ransomware.live lists Chilean incidents also attributed to LockBit5, Incransom and Anubis. Red Piranha places Securotrop inside Qilin’s affiliate network, with confirmed infrastructure overlap and use of Qilin software without code changes. ESET, Group-IB and Securonix place The Gentlemen in the same leak-site ecosystem, with operators largely drawn from Qilin’s affiliate network.
Fortinet’s relevance in this corpus is not incidental. CVE-2024-21762 is a buffer overflow in FortiOS and FortiProxy SSL VPN that allows remote code execution or denial of service through specially crafted requests. CISA lists it in KEV. CVE-2024-55591, meanwhile, is an authentication bypass in FortiOS and FortiProxy, disclosed in the context of FortiBleed and patched by Fortinet across all affected versions, according to The Network DNA. The combination of both flaws appears in Scrutex.ai, Paubox, Viakoo and The Hacker News coverage as one of the paths Qilin may have used to automate initial access to exposed VPN gateways.
The FortiBleed campaign is not limited to one group, but it does expose a structural problem that helps explain some of Qilin’s success and that of neighboring actors. CSIRT Telconet reported more than 73,932 Fortinet firewall URLs compromised in 194 countries through credentials stolen by infostealers, with a pivot into Active Directory. Arctic Wolf raised the estimate of compromised FortiGate devices to 75,000, while The Hacker News put the figure at 86,644 as of June 19, 2026. Devel Group added operational detail by describing a Russian-origin Initial Access Broker and a Go tool called FortiGateSniffer. In practice, the issue is no longer just the exploitation of a CVE, but the accumulation of credentials, exposed configurations, open external administration and the lack of MFA.
In Chile, that exposure overlaps with sectors that appear repeatedly in the SEK report: Government with 10 combined incidents, Finance with 8, Education with 6, Health with 6, and Energy or Mining with 5. The pressure also reaches tourism through NOI Hotels, and industrial and logistics sectors, considering the Chilean Qilin victims recorded by Ransomware.live. The picture is one of a market hit by volume, but also by target selection. Initial access is sought on vulnerable perimeters and then monetized through data theft, hypervisor encryption and public extortion.
Key facts table
| Date | Event | Source | Confidence |
|---|---|---|---|
| 2024-02 | CVE-2024-21762 enters CISA’s KEV catalog as an actively exploited vulnerability | Jimber, CISA | confirmed |
| 2026-06-08 | Red Piranha describes Securotrop as a Qilin-affiliated brand with infrastructure overlap | Red Piranha | confirmed |
| 2026-06-09 | CISA gives U.S. agencies three days to patch CVE-2024-21762 because of active exploitation linked to Qilin | DiarioBitcoin | confirmed |
| 2026-06-15 | Scrutex.ai identifies CVE-2024-21762 and CVE-2024-55591 as Qilin initial access vectors | Scrutex.ai | confirmed |
| 2026-06-15 | Check Point Research documents exploitation of CVE-2026-50751 and links at least one case to Qilin | Check Point Research | confirmed |
| 2026-06-16 | ProvenData models Qilin’s attack chain and detection signals | ProvenData | confirmed |
| 2026-06-17 | CSIRT Telconet warns about FortiBleed and more than 73,932 compromised URLs | CSIRT Telconet | confirmed |
| 2026-06-18 | Canada issues AL26-014 and urges immediate patches for CVE-2024-55591 | Canadian Centre for Cyber Security | confirmed |
| 2026-06-18 | Bitsight reports offline cracking using 45 GPUs against FortiOS credentials | Bitsight | confirmed |
| 2026-06-19 | The Hacker News counts 86,644 FortiGate devices compromised through FortiBleed | The Hacker News | confirmed |
| 2026-06-23 | Devel Group reports FortiGateSniffer and ghost accounts on Fortinet firewalls | Devel Group | confirmed |
| 2026-06-25 | Hispasec recommends credential rotation, MFA and reduced exposure | Hispasec | confirmed |
| 2026-06-26 | Ransomware.live records 74 victims in Chile and multiple Qilin cases | Ransomware.live | confirmed |
| 2026-07-01 | La Tercera reports that Chile received more than eight billion attack attempts in 2025 | La Tercera | confirmed |
| 2026-07-02 | G5 Noticias and Zoom Tecnológico summarize 58 incidents in Chile between January and June 2026 | G5 Noticias, Zoom Tecnológico | confirmed |
| 2026-07-02 | Comparitech ranks Qilin as the most prolific group in H1 2026 | Comparitech | confirmed |
| 2026-07-06 | G5 Noticias reports 8.8 billion attempts in Chile during 2025 and 61% of DLS posts for Qilin | G5 Noticias | confirmed |
Operation timeline
| Date | Event | Actor/vector | Verified source |
|---|---|---|---|
| 2024-02 | CVE-2024-21762 is treated as an actively exploited vulnerability | Fortinet, CISA | Jimber, CISA |
| 2026-06-08 | Securotrop is described as a Qilin affiliate with overlapping infrastructure | Qilin ecosystem | Red Piranha |
| 2026-06-09 | CISA gives U.S. agencies three days to patch a critical Fortinet flaw associated with Qilin | CVE-2024-21762 exploitation | DiarioBitcoin |
| 2026-06-15 | Scrutex.ai identifies CVE-2024-21762 and CVE-2024-55591 as entry points used by Qilin | Fortinet SSL VPN, FortiProxy | Scrutex.ai |
| 2026-06-15 | Check Point Research confirms active exploitation of CVE-2026-50751 with one case linked to Qilin | Remote access VPN | Check Point Research |
| 2026-06-16 | ProvenData summarizes Qilin’s attack chain, with compromised VPNs, phishing and ESXi | Ransomware-as-a-service | ProvenData |
| 2026-06-17 | Telconet publishes on FortiBleed and large-scale compromise of Fortinet URLs | Stolen credentials, SSL VPN | CSIRT Telconet |
| 2026-06-18 | Canada, Bitsight and Fortinet describe the scope of the compromise and offline cracking | FortiOS credentials, CVE-2024-55591 | Canadian Centre for Cyber Security, Bitsight, The Network DNA |
| 2026-06-19 | The Hacker News reports 86,644 FortiGate devices compromised through FortiBleed | Automated two-stage attack | The Hacker News |
| 2026-06-23 | Devel Group publishes on FortiGateSniffer and fake administrative accounts | Persistence, authentication sniffing | Devel Group |
| 2026-06-25 | Hispasec stresses password rotation and MFA as defensive priorities | FortiGate hardening | Hispasec |
| 2026-06-26 | Ransomware.live consolidates 74 Chilean victims on its map | DLS and multiple attributions | Ransomware.live |
| 2026-07-01 | La Tercera describes attack volume and Qilin and The Gentlemen activity in Chile | RaaS, poorly managed cloud, double extortion | La Tercera |
| 2026-07-02 | G5 Noticias and Zoom Tecnológico summarize 58 incidents in Chile and Qilin’s 61% share of DLS posts | DLS, dark web, targeted sectors | G5 Noticias, Zoom Tecnológico |
| 2026-07-02 | Comparitech quantifies 4,217 global ransomware attacks in H1 2026 and says Qilin leads the ranking | Leak sites worldwide | Comparitech |
| 2026-07-06 | SEK, via G5 Noticias, places Chile at 8.8 billion attempts and Qilin as the main DLS actor | Regional pressure and ransomware | G5 Noticias |
Attack chain and TTPs
The Qilin attack chain described in the consolidated material follows a repeated structure. Initial access comes first. The sources do not show a single method, but rather a hybrid pattern built on phishing, stolen credentials, exposed remote services and exploitation of edge appliances. In the Fortinet case, Scrutex.ai, Paubox and Viakoo place CVE-2024-21762 and CVE-2024-55591 among the most relevant entry points. The first allows remote code execution through SSL VPN. The second enables authentication bypass. Together, they create a path for large-scale automation against FortiGate and FortiProxy firewalls that remain exposed or out of date.
After entry, the sources describe internal reconnaissance and lateral movement. LinkedIn’s June 9, 2026 analysis of Qilin mentions RDP, SMB and WMI as mechanisms used to move across networks. ProvenData adds anomalous VPN or RDP authentications, domain admin activity from non-administrative workstations, mass LSASS access correlated with lateral movement, bulk deletion of shadow copies and simultaneous service termination as high-value signals. The end goal is to reach higher-impact systems, especially VMware ESXi hypervisors, because encrypting the hypervisor can take down multiple workloads at once.
Extortion happens on two tracks. The technical track uses encryption across Windows, Linux and ESXi. The public pressure track relies on prior data theft, threats to publish or sell the data, contact through email and Tor chats, and a price increase after 72 hours, according to the Qilin material on LinkedIn. That double-extortion component explains why leak sites are central to the ecosystem. The damage is measured not only in downtime, but also in exposure risk and the secondary monetization of stolen information.
FortiBleed adds a second tactical layer. This is no longer just about exploiting a perimeter vulnerability, but about mass credential compromise followed by reuse. Bitsight describes legacy SHA-256 hashes and offline cracking with 45 GPUs. The Hacker News explains an automated two-stage approach: first testing known username and password combinations, then passively observing authentication traffic crossing the firewall to collect new credentials. Devel Group adds the use of FortiGateSniffer, a Go tool that abuses the diagnose sniffer packet command, and the creation of ghost administrative accounts with names that mimic legitimate Fortinet components.
| TTP | Description | Source |
|---|---|---|
| T1190 | Exploitation of exposed applications, including gateways and vulnerabilities such as CVE-2024-55591 | Securonix |
| T1133 | Abuse of external remote services such as SSL VPN and RDP | Securonix |
| T1078 | Use of valid accounts obtained through brute force or credential theft | Securonix |
| Initial access | Phishing, stolen credentials, exposed remote services, unpatched Fortinet systems | ProvenData, Scrutex.ai, Paubox, Viakoo |
| Persistence | Fraudulent administrative accounts, passive traffic inspection with FortiGateSniffer | Devel Group |
| Lateral movement | RDP, SMB, WMI, domain admin activity, LSASS | LinkedIn, ProvenData |
| Impact | Encryption of Windows, Linux and VMware ESXi, service termination and shadow copy deletion | ProvenData, LinkedIn |
| Extortion | Data theft, DLS publication, Tor and email contact, 72-hour time pressure | LinkedIn, Comparitech |
The relationship between Qilin and Fortinet is also structural. Fortinet coverage, CISA, the Canadian Centre for Cyber Security and Arctic Wolf show the issue has grown beyond a single incident. Credentials are compromised, configurations are exposed, firewalls remain unpatched, and initial access ecosystems are bought and sold. That helps explain why different groups, including linked brands such as The Gentlemen and Securotrop, converge on the same attack surface.
Regional impact
Regional overview
The available material does not allow for one unified metric across Latin America, but it does show a broadly consistent pressure pattern. Chile is the most measured case, with 8.8 billion cyberattack attempts in 2025 and 58 incidents logged in just the first six months of 2026. Brazil appears as one of the regional centers for ransomware victims and for exposure to phishing and public-sector compromise campaigns. Paraguay and Bolivia appear in ransomware monitoring panels, though with less public detail on the names of affected organizations. Colombia and Peru have no additional verifiable facts in the material provided, which does not mean there is no risk, only that the corpus contains no consolidated evidence for those countries.
Argentina
There are no additional verifiable facts in the research for Argentina. The material does not provide victims, campaigns or confirmed attributions for the country within the corpus supplied.
Chile
Chile has the densest set of data and therefore serves as the best gauge of the phenomenon. SEK, according to G5 Noticias, recorded 58 incidents affecting or exposing Chilean organizations between January and June 2026. Of those, 18 were posts on ransomware leak sites and 40 were posts in dark web cybercrime forums. That split matters because it shows the problem is no longer limited to attempts or detections, but to actual public exposure of data and to extortion processes that end on leak sites. Leak-site posts also increased 50 percent versus the same period in 2025.
Qilin was the most visible actor in that subset. G5 Noticias assigns it 11 of the 18 ransomware leak-site posts, or 61 percent of the total. La Tercera reaches the same general conclusion: Chile was identified as one of the countries where international data hijacking and credential theft groups operate actively, affecting the public sector, critical infrastructure, financial services and major companies. The article also describes Qilin as an RaaS group specialized in automated campaigns and abuse of poorly managed cloud configurations, and The Gentlemen as another active actor in Chile, focused on double extortion.
Ransomware.live adds operational context. Its Chile page reports 74 victims linked to organizations in the country, all aggregated from leak-site posts. Among the victims attributed to Qilin in 2026 are Valbifrut, Graneles de Chile, Noi Hotels, SAAM Towage, Calidra and Comercial Echave Turri Limitada. Their discovery dates cluster between January and May 2026, reinforcing the idea of sustained activity rather than an isolated event. Ransomware.live also tracks other actors such as LockBit5, Incransom and Anubis, confirming that the local environment is fragmented across several extortion families and brands.
There are also sector signals. SEK’s report summary, cited by G5 Noticias, places Government at the top with 10 combined incidents, followed by Finance with 8, Education with 6, Health with 6 and Energy or Mining with 5. That not only identifies high-value sectors, it also points to where exposed systems may be located and where the operational impact could be most severe if encryption or exfiltration occurs. NOI Hotels expands the picture into tourism and hospitality, a segment that depends heavily on operational uptime and guest data protection.
A Care Telecom reference mentions a clinic in Chile among 15 new victims claimed by Qilin during a 72-hour window in the first week of June 2026. The source does not identify the clinic by name, so the claim cannot go beyond an indication of health-sector exposure. Even so, it fits the broader regional pattern, where Qilin targets organizations that do not always have strong controls over remote access, segmentation or incident recovery.
Paraguay
Paraguay appears in the corpus in two ways. The first is institutional. Check Point Research reports active exploitation of CVE-2026-50751 in remote access gateways and says at least one case was linked to Qilin ransomware activity. The indexed excerpt of the report also includes Paraguay in that context, although the material does not let us attribute a specific victim or determine whether the country was hit by the same campaign or simply referenced in the document.
The second appearance is operational. Ransomware.live’s Mexico panel includes an entry associated with Qilin that mentions Healthcare S.A. as a victim and describes it as a Paraguayan family-founded company, with the case discovered on June 15, 2026. The material does not clarify whether the incident affected operations in Paraguay, Mexico or a transnational corporate structure. What can be verified is the entity’s presence in the tracker and its association with Qilin.
Legal-ISAC, for its part, shows at least one Qilin-associated victim in Paraguay on its RansomWatch dashboard, classified in the information technology sector. That confirms the country is already appearing on ransomware tracking radars with activity attributed to the group. Added to that is an unconfirmed Instagram post describing an attack against the private clinics Migone, Grupo Británico and Reyva, with interruptions in medical records, appointments and billing. That information is not corroborated by an institutional source, so it should be treated as an indicator, not as a settled fact.
La Tribuna Paraguay also reported a ransomware attack attributed by a group calling itself CyberTeam against InfoCheck, linked to Equifax Paraguay. That item is confirmed in the corpus, although it does not establish any link to Qilin. Paraguay, then, shows ransomware activity, but the material does not support the conclusion that all of it belongs to the same actor.
Bolivia
Bolivia appears with less volume, but with clear thematic relevance. Scrutex.ai reported that Qilin led the posts on its leak site during the week under analysis with 25 victims, equal to 13 percent of the total. Within that universe, Bolivia is listed among the countries with between one and three affected organizations, although the report does not publish specific names. The same report identifies Qilin as an actor that mainly exploits edge vulnerabilities, remote management tools and hypervisors, and explicitly highlights Fortinet flaws CVE-2024-21762 and CVE-2024-55591 as entry points.
The value of that reference is not only Bolivia’s presence, but the technical similarity with what was seen in Chile and elsewhere in the region. Scrutex.ai cites PRODAFT and ReliaQuest in saying that tens of thousands of Fortinet devices remained exposed months after patching. If the perimeter stays open, the spillover effect in countries with less public visibility becomes difficult to measure but no less real. Orbital Laika reinforces that reading by explicitly mentioning threats in Bolivia in the context of Fortinet’s global FortiGuard report.
The material also includes two LinkedIn posts that, unconfirmed, say Krybit may have affected Bolivia’s Agency for Health Infrastructure and Medical Equipment, AISEM. Both posts describe a disruption to health and medical equipment infrastructure, but there is no official statement or technical detail on the access vector. They should therefore be read as signs of possible exposure, not as conclusive attribution.
Peru
There are no additional verifiable facts in the research for Peru. The corpus provides no confirmed victims, attributed campaigns or specific technical data for the country.
Colombia
There are no additional verifiable facts in the research for Colombia. The material contains no confirmed victims or campaigns tied to the country within the consolidated sources.
Brazil
Brazil is the other major regional reference point alongside Chile. La Tercera, citing a Fortinet study, says the country accounted for about 30 percent of ransomware victims in the region and saw 309 million phishing attempts in 2025, equal to 588 attacks per minute. That data is paired with a broader claim in the same article: Brazil is one of the countries where international data hijacking and credential theft groups operate actively against the public sector, critical infrastructure, financial services and major companies.
On the technical side, Check Point Research published a phishing campaign in Brazil that abuses the legitimate NinjaOne agent to install a signed agent on corporate devices, using Portuguese-language portals and social engineering phone calls. Although the case is not directly tied to Qilin, it does confirm heavy use of legitimate remote access to compromise endpoints in the country. The same report also mentions active exploitation of CVE-2026-50751 with one case linked to Qilin, reinforcing the idea that the group is following remote-access flaws closely.
CM Alliance adds another element. On June 22, 2026, Brazil was investigating a possible cyberattack against Defesa Civil Alerta, a platform under the National Secretariat for Protection and Civil Defense, after false emergency warnings were sent to thousands of mobile phones and the system was temporarily disconnected. The source does not attribute the event to Qilin, but it places the incident within a particularly active June for high-impact events in the country.
In terms of ransomware, Red Piranha places Brazil within a weekly report where The Gentlemen leads global activity and Qilin ranks second. The same document describes Securotrop, a Qilin-affiliated brand, and records activity in Brazil and Chile. Care Telecom also mentions a food-sector company in Brazil among the alleged victims claimed by Qilin during a 72-hour window in the first week of June. That reference is unconfirmed, but it fits the regional leak-site expansion pattern.
United States
There are no additional verifiable facts in the research for the United States within this regional section. There is, however, an indirect relevant reference: several technical analyses of Qilin and FortiBleed mention campaigns or victim clusters in U.S. law firms and consultancies, but the corpus provided here did not develop a country-specific block with concrete events for that jurisdiction.
Technical indicators
No classic IOCs, such as hashes, domains, IPs or file paths, were published in the consolidated material. There are, however, behavior indicators, vulnerable versions and operational artifacts that are useful for defense and hunting.
| Type | Value | Source |
|---|---|---|
| CVE | CVE-2024-21762 | Scrutex.ai, CVE Program, CISA, Tech Insider |
| CVE | CVE-2024-55591 | Scrutex.ai, Canadian Centre for Cyber Security, The Network DNA, Paubox, Viakoo |
| CVE | CVE-2026-50751 | Check Point Research |
| Tool | FortiGateSniffer | Devel Group |
| Abused command | diagnose sniffer packet | Devel Group |
| Fraudulent account | forticloud | Devel Group |
| Fraudulent account | fortiuser | Devel Group |
| Fraudulent account | fortinet-support | Devel Group |
| Fraudulent account | fortinet-tech-support | Devel Group |
| Operational vector | Fortinet SSL VPN | Scrutex.ai, ProvenData, Securonix, Gurucul |
| Operational vector | VMware ESXi | ProvenData, LinkedIn |
| Operational vector | RDP, SMB, WMI | LinkedIn, Securonix, ProvenData |
Security team analysis
The defensive priority that emerges from the material is not ambiguous. Initial access remains the point of failure, and in this campaign initial access is closely tied to the perimeter. If an organization exposes FortiGate, FortiProxy or remote-access gateways without enough hardening, the attack surface matches the pattern seen in Qilin and the FortiBleed ecosystem. The fact that CISA, the Canadian Centre for Cyber Security and other national teams issued alerts within a narrow time window suggests the issue has moved beyond a single vulnerability.
At the operational level, the first step is to stop treating the firewall or VPN as just a transit point. In the material reviewed, those devices appear as compromise targets, persistence points and credential collection points. Devel Group describes ghost administrative accounts. The Hacker News describes an automated attack that first tests credentials and then captures authentication traffic. Bitsight adds that theft can continue offline through hash cracking. For that reason, hardening has to include not just patching, but also account hygiene, secret rotation and review of historical configuration.
The next layer is detection. ProvenData offers a useful set of signals: anomalous VPN or RDP logins from unusual times, locations or devices, domain admin activity from non-administrative hosts, mass LSASS access, bulk deletion of shadow copies, coordinated service termination and driver loads that do not match the endpoint baseline. In Fortinet environments, Devel Group recommends looking for abnormal executions of diagnose sniffer packet and auditing accounts with names designed to look like legitimate support. If the monitoring stack is not seeing those events, the first objective should be to enable enough telemetry to capture them.
Mitigation guidance is consistent across sources. Rotate administrative and VPN passwords immediately, enforce MFA, update FortiOS to the latest available version, close external administration unless it is truly necessary and restrict access to trusted hosts. When possible, external administration should be eliminated entirely. The Canadian Centre for Cyber Security and Fortinet, according to The Hacker News coverage, also recommend ending compromised administrative and VPN sessions and assuming prior credentials may have been reused from earlier incidents. That assumption matters because FortiBleed does not depend on a single vector, but on the combination of technical exposure and already leaked credentials.
For Chile, the risk reading is even more urgent. The 58 incidents between January and June 2026 and the 50 percent increase in DLS posts compared with the same period in 2025 show that the problem is persistent. The mix of targeted sectors, Government, Finance, Education, Health and Energy or Mining, suggests the adversary understands where operational and reputational impact can be maximized. For organizations that depend on ESXi hypervisors, defense should include segmentation, least privilege on admin tools and tested restoration plans. Qilin targets hypervisors because that speeds up damage across multiple systems. If ESXi is not protected, containment arrives too late.
Source limitations
The available corpus supports a strong technical and regional line of analysis, but it does not justify closing several specific attributions. The mentions of ATCOM Chile, the clinic in Chile, the food company in Brazil, AISEM in Bolivia, Healthcare S.A. in Paraguay and the private Paraguayan clinics appear in sources with varying levels of reliability, several of them using unconfirmed attribution language. For that reason, they are not treated as fully verified incidents in this research.
There are also no classic IOCs in the consolidated sources. No hashes, IP addresses, C2 domains or DLS URLs were provided in a way that offers direct operational value for technical hunting. What is available are tool names, abused commands, vulnerability families and fraudulent accounts observed by the cited researchers.
Another limitation is the geographic imbalance. Chile carries the strongest and most quantifiable evidence. Brazil appears with substantial context, but with less direct attribution to Qilin in specific incidents. Paraguay and Bolivia have signs of exposure and monitoring in intelligence platforms, but without the same density of detail. Argentina, Peru, Colombia and the United States do not contribute additional verifiable facts within the regional block requested.
Finally, the information on FortiBleed is abundant but heterogeneous in its scale estimates, ranging from more than 30,000 devices to 86,644 compromised FortiGate systems. That spread does not invalidate the campaign, but it does mean the numbers should be treated as estimates from different research teams, not as one consolidated total.
Sources
- Reporte SEK Constata Intentos De Ciberataqueszoomtecnologico.com· Zoom Tecnológico
- Enorme ciberamenaza: Chile recibió más de ocho billones de intentos de ataques cibernéticos el año pasadolatercera.com· La Tercera
- Ransomware Roundup: H1 2026 stats on attacks, ransoms, and active gangscomparitech.com· Comparitech
- 74 victims for Chileransomware.live· Ransomware.live
- Ransomware Alert ATCOM Chile, reportedly fallen victim to Qilin ransomwarex.com· FalconFeeds.io
- Qilin Ransomware Hits ATCOM Outsourcing in Chilelinkedin.com· LinkedIn
- Weekly Ransomware Intelligence Report, June 14, 2026scrutex.ai· Scrutex.ai
- Legacy VPN End-of-Life 2026: The Remote-Access Watchlistjimber.io· Jimber
- AL26-014 – FortiBleed leak of thousands of compromised credentials impacting Fortinet devicescyber.gc.ca· Canadian Centre for Cyber Security
- FortiBleed Cracks 86,644 Fortinet Firewalls [2026]tech-insider.org· Tech Insider
- FortiBleed Security Alert: Fortinet VPN Credentials Exposedbitsight.com· Bitsight
- FortiBleed Campaign: How 75000 Fortinet Firewalls Were ...thenetworkdna.com· The Network DNA
- Two ransomware gangs targeting healthcarepaubox.com· Paubox
- Daily OT Security News: July 04, 2026viakoo.com· Viakoo
- Qilin Ransomware: 338 Victims in Q1 2026, A Pattern Not a Spikelinkedin.com· LinkedIn
- Threat Intelligence Report Jun 2 - Jun 8 2026redpiranha.net· Red Piranha
- 15th June – Threat Intelligence Reportresearch.checkpoint.com· Check Point Research
- June 2026: Biggest Cyber Attacks, Data Breaches, Ransomware Attackscm-alliance.com· CM-Alliance
- CISA da 3 días a agencias de EE. UU. para corregir falla crítica en ...facebook.com· DiarioBitcoin
- FortiBleed pone en el punto de mira a FortiGate para robar credenciales a gran escalaunaaldia.hispasec.com· Hispasec
- Active FortiBleed Campaign Impacting Fortinet Devices Across 194 Countriesarcticwolf.com· Arctic Wolf
- CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devicesthehackernews.com· The Hacker News
- Actualización de campaña “fortibleed”: herramienta fortigatesniffer compromete más de 74000 firewallsdevel.group· Devel Group
- Qilin Ransomware: Operating Model, Attack Chain, and Technical Guideprovendata.com· ProvenData
- The "Gentlemen" RaaS and the GentleKiller EDR-Killer Frameworkconnect.securonix.com· Securonix
- Killing me gently: Inside Gentlemen's EDR killer frameworkwelivesecurity.com· ESET
- Sitio oficial de NOI Hotelsnoihotels.com· NOI Hotels
- Un ataque con ransomware afectó a importantes sanatorios ...instagram.com· Instagram
- Contraseñas de 25+ caracteres aparecieron robadas ...instagram.com· Instagram
- FG-IR-24-015: FortiOS & FortiProxy SSL-VPN heap-based buffer overflow (CVE-2024-21762)fortiguard.com· Fortinet (FortiGuard Labs)
- Un ciberataque masivo mediante ransomware afectó los sistemas ...facebook.com· La Tribuna Paraguay
- Advanced endpoint protection is a must for any ...instagram.com· Instagram
- CVE-2024-21762 Recordcve.org· CVE Program
- Krybit ransomware hits Bolivia's AISEMlinkedin.com· LinkedIn
- Known Exploited Vulnerabilities Catalogcisa.gov· CISA
- krybit ransomware hits Bolivian health agency aisem.gob.bolinkedin.com· LinkedIn
- 2026 Threat Intelligence Trends, Cyber & Ransomware Reportcyble.com· Cyble
- 262 victims for Mexico - Ransomware.liveransomware.live· Ransomware.live
- RansomWatch - Real-Time Ransomware Tracking Dashboardlegal-isac.org· Legal-ISAC
- FortiBleed Campaign Linked to INC, Lynx Ransomware Attacksshow.it· Show.it
- Las amenazas digitales no descansan, pero tampoco quienes trabajan para frenarlasfacebook.com· Orbital Laika
- Campaña masiva de espionaje cibernético 'FortiBleed' compromete más de 73,900 dispositivos Fortinetcsirt.telconet.net· CSIRT Telconet
- Chile recibió 8,8 billones de intentos de ciberataque en 2025 y expertos advierten que las empresas siguen tardando meses en detectar una intrusióng5noticias.cl· G5 Noticias
- The Gentlemen Threat Actor Profile: Tactics and Operationsgurucul.com· Gurucul
- Cyber security of OT networks: A tutorial and overviewarxiv.org· arXiv
- CYBERSECURITY ALERT!!! FortiBleed Campaignfacebook.com· Malawi Computer Emergency Response Team (mwCERT)
- Publicación de Johany Chacon - LinkedInes.linkedin.com· LinkedIn
- Qilin: La Amenaza que Puede Paralizar tu Empresa en 2026caretelecom.com· Care Telecom
- Ransomware Threat Intelligence: A Complete Guidecloudsek.com· CloudSEKUnverified URL
- Qilin publica 539 GB de NOI Hotels – Datos de huéspedessecurity-chu.com· Security-CHU



