Argentina Led Ransomware Victims in July
Bitdefender logged 21 claimed ransomware victims in Argentina in July, with The Gentlemen, Qilin and DragonForce among active groups.
Bitdefender reported 21 claimed ransomware victims in Argentina in July, with The Gentlemen, Qilin and DragonForce among the actors claiming cases in the country. The report also showed sector shifts, with construction losing ground while technology and health gained share.
Bitdefender reported 21 claimed ransomware victims in Argentina in July. Among the groups claiming cases in the country were The Gentlemen, Qilin and DragonForce, a snapshot that links local activity with several names that have appeared repeatedly in recent Latin American reports.
What did Bitdefender show about the most affected sectors?
Bitdefender said that in July, construction fell to fifth place among the sectors hit hardest by ransomware, while technology and health moved up to second and third, respectively, and financial services saw more victims. The data points to a shift in pressure from groups toward activities with different operational and data profiles, although the report does not detail in this summary which campaigns explain each change.
What do other sources say about the region's weight?
Kaspersky, cited by Tecknow News, said Latin America was a ransomware hotspot and that attacks in the region rose 78% in 2025, with more than 450 incidents compared with more than 250 in 2024. That same coverage attributed to Kaspersky the identification of 79 ransomware variants targeting the region in 2025, nearly double the 48 variants seen in 2024, and placed Brazil at about 30% of all ransomware victims in Latin America that year.
Infosertecla added that Latin America had the highest proportion of organizations affected by ransomware detections in 2025, at 8.13%, above other regions. At the same time, Cyble said that within South America, The Gentlemen was the dominant actor, a reading that separates that regional strength from Qilin's weight in the global conversation.
What tactics and targets are attributed to Qilin and The Gentlemen?
Security Arsenal described a technical sequence for Qilin that includes initial access through edge or RMM, staging with LOLBins, credential dumping, lateral movement with PsExec and WMI, shadow copy deletion and pre-encryption preparation. In its recent sample, it also said Qilin kept a preference for manufacturing as a primary target and increased attention on government and defense, as well as transport and logistics.
The Gentlemen, according to Intel 471, targets manufacturing, insurance, construction and consumer services, and has also hit critical services such as health care. The same source described it as a recurring threat to financial services, a profile that matches the group's presence in the victim claims in Argentina collected by Bitdefender.
Sources
- The Gentlemen: Kaspersky alerta sobre su expansión en ransomwareinfosertecla.com· Infosertecla
- Threat Hunting Case Study: The Gentlemenintel471.com· Intel 471
- Ransomware Threats In The Americas H1 2026: Deep Divecyble.com· Cyble
- Bitdefender Threat Debrief | August 2026bitdefender.com· Bitdefender
- La sofisticación de "The Gentlemen": Kaspersky alerta sobre ransomware con backdoors a medida que impacta Latamtecknow.news· Tecknow News
- La sofisticación de "The Gentlemen": Kaspersky alerta sobre ransomware con backdoors a medida que impacta Latamtecknow.news· Tecknow News
- QILIN Ransomware Gang: 26 New Victims Posted in 100- Posting Window, APAC Expansion, Government Targeting and Detection Rulessecurityarsenal.com· Security Arsenal



