CiberLATAMbywhalemate

Brazil appears in daily ransomware log

Ransom-DB logged Brazil among several ransomware targets, while a SAFEPAY report cited a case in Mexico.

Whalemate Labs · AI-assisted researchPublished:2 min read

Ransom-DB observed a daily ransomware log that included Brazil among several countries hit, although the available result did not confirm attribution to a specific group. A separate SAFEPAY report described intrusion techniques, affected sectors and a target in Mexico, not Brazil.

Ransom-DB observed a daily ransomware log that included Brazil among several countries hit, but the available result did not confirm attribution to a specific group. Separately, coverage of SAFEPAY described intrusion techniques and a geographic spread of victims that included a target in Mexico, along with affected verticals such as healthcare, food production and hospitality.

What did Ransom-DB's daily log show?

Ransom-DB published a daily ransomware log in which Brazil appeared as one of several attacked countries, although the material available does not identify the responsible group with certainty. That provides evidence of activity against the country, but not enough to support an attributed campaign.

The available information is limited to the country being mentioned in the daily monitoring. There are no details in that result on volume, initial access vector or the sector affected in Brazil, so any more specific reading would go beyond what was verified.

What does the coverage on SAFEPAY add?

Security Arsenal's coverage of SAFEPAY does spell out concrete TTPs, but the Latin American case it cited was Mexico, not Brazil. Documented techniques included initial access through edge or VPN, phishing macros, lateral movement with PsExec and WMI, credential dumping and data staging before encryption.

The analysis also mentioned a geographic spread of victims and pointed to affected sectors such as healthcare, food production or agriculture, and hospitality. That gives a clearer technical picture than the one available for Brazil in Ransom-DB's log, even though the regional example cited did not focus on the Brazilian market.

What do the sources say about Brazil in 2026?

Tripla says that in 2026 ransomware in Brazil is marked by more active groups, data theft-based extortion before encryption, and attacks that come in through the supply chain. In that same line, it named LockBit and The Gentlemen as active groups targeting Brazilian victims.

That assessment is attributed by the source itself and is not independently confirmed in the material provided, so it should be read as Tripla's characterization rather than a closed attribution. Capital Aberto also cited figures attributed to Kaspersky on 549,000 records of ransomware attempts between August 2024 and June 2025, close to half of the Latin American total, although the publication does not link to the original report or clarify whether those were detections, blocks or confirmed incidents.

Sources

View all