CiberLATAMbywhalemate

Brazil leads Latin America in hospital ransomware

Brazil accounted for 51% of ransomware attacks on health care in Latin America. Brazil’s ANPD opened a case over data from 500,000 patients.

Whalemate Labs · AI-assisted researchJul 13, 20262 min read

Brazil accounted for 51% of the ransomware attacks recorded against the health care sector in Latin America and ranked among the three main targets worldwide for that threat. In that context, the ANPD opened a case against Instituto Saúde e Cidadania, or Isac, after an attack exposed data from 500,000 patients.

Brazil becomes a regional ransomware hotspot in health care

Reports released in 2026 show that Brazil accounted for 51% of the ransomware attacks recorded against [the health care sector](/en/news/paraguay-three-private-clinics-hit) in Latin America. With that volume, the country ranked among the three main global targets for this threat, according to IT Section and CISO Advisor reports published in July.

The same analysis points to an operational pattern that helps explain the impact of these incidents. In 96% of the monitored events in 2026, attackers copied sensitive information before encrypting systems. That pattern increases patient data exposure and raises the consequences for hospitals, clinics, and public health units.

The Isac case and the ANPD response

In Brazil, the case involving Instituto Saúde e Cidadania, or Isac, became one of the clearest examples of this trend. The ANPD opened a case against the organization after the hacking incident exposed data from 500,000 patients, according to Cybersec Brazil and material shared by specialists on social media.

Posts about the case say the ANPD sanction process focuses on possible LGPD violations tied to the protection of those personal data. They also indicate that the regulator is reviewing how the organization handled the information before and after the incident, including governance and the security measures in place.

According to content shared by privacy and cybersecurity professionals, the Brazilian authority could impose significant administrative penalties, including fines and limits on data processing. At the same time, the case is being used as a reference to reinforce guidance and best practices on incident response, notification to data subjects and authorities, and risk assessment in public and private health institutions.

A recurring pattern in health care

Posts aimed at data owners describe the attack on Isac as an example of the greater sophistication these groups have been showing against Brazil’s health sector. The focus on exfiltrating sensitive data before encryption appears to worsen the operational damage and may also open the door to regulatory sanctions and civil lawsuits.

In the same vein, IBSEC material on the attack against Hospital São José adds context on the lessons incidents leave for hospitals, in an environment where the focus is no longer only on restoring systems, but also on the exposure of clinical and personal information.

Sources

View all