CiberLATAMbywhalemate

Argentina’s Education Ministry named in n0n ransomware

A weekly ransomware roundup listed Argentina’s Education Ministry among victims, while Brazil references tied to n0n remain unconfirmed.

Whalemate Labs · AI-assisted researchPublished:4 min read

A weekly ransomware roundup listed Argentina’s Ministry of Education among the victims for Sept. 14 to 20, 2026. At the same time, several posts pointed to the emerging group n0n, with secondary references to possible victims in Brazil, but not enough primary support to treat that as confirmed.

A weekly ransomware roundup listed Argentina’s Ministry of Education among the victims in the Sept. 14 to 20, 2026 window. At the same time, several posts described activity from an emerging group called n0n, but references to Brazil and other countries appear only as secondary mentions or remain unconfirmed in the sources available.

What is known about the n0n case?

Sources consulted describe n0n as an emerging ransomware group that had posted more than a dozen victims on its leak site through Sept. 22, according to Infosecurity Magazine. Tetmo, citing CyberXTron, added that initial access may have come through compromised credentials from infostealer malware, followed by privilege escalation and access to administrative tools.

That same line of reporting, according to Tetmo, points to threats against shadow copies and backup infrastructure. Cyware also described it as a double extortion group that threatens to destroy backups to increase pressure on victims.

What regional reach appears in the material?

The only confirmed regional data in the material is the victim in Argentina mentioned by ScrutecX, which placed Argentina’s Ministry of Education among those affected from Sept. 14 to 20, 2026. The rest of the Latin America references do not have the same level of support.

Infosecurity Magazine noted that secondary coverage included victims in Brazil, but said that point was not corroborated by a primary source in the results. Minuto da Segurança repeated the Brazil reference and said the group had allegedly published 13 organizations in 10 countries, although it also did not provide additional primary evidence for a specific Brazilian victim.

How many victims and in which countries?

The available figures do not fully match across sources, so they should be read as estimates from different roundups rather than a single consolidated count. NCSA Thailand said n0n had allegedly posted 13 victims in 10 countries, with 11 already in leak phase and two still under active payment deadlines.

Cyware, for its part, mentioned victims in Brazil, Vietnam, Uzbekistan, Sweden, Luxembourg, and the United States. It also attributed 23% of victims to the financial sector, and 15% each to technology, retail, and education, within its own weekly summary.

Data Value Source
Victim in Argentina Argentina’s Ministry of Education ScrutecX / Scrutex.ai
Victims posted by n0n More than a dozen through Sept. 22 Infosecurity Magazine, via CyberXTron
Victims reported by NCSA Thailand 13 in 10 countries NCSA Thailand Webboard
Victims in leak phase 11 NCSA Thailand Webboard
With active payment deadlines 2 NCSA Thailand Webboard
Financial sector 23% of victims Cyware
Technology, retail and education 15% each Cyware

What remains unconfirmed?

What is still missing, for now, is solid primary confirmation of any specific Brazilian victim and a single consolidated total of those affected. The available sources do agree that n0n is active and expanding, but the verifiable regional development in Latin America is limited to the already recorded Argentine case and secondary mentions of Brazil that are not yet strong enough to treat as definitive.

Sources

View all