Brazil leads Latin America in hospital ransomware
Brazil accounted for 51% of ransomware attacks on health care in Latin America. Brazil’s ANPD opened a case over data from 500,000 patients.
Brazil accounted for 51% of the ransomware attacks recorded against the health care sector in Latin America and ranked among the three main targets worldwide for that threat. In that context, the ANPD opened a case against Instituto Saúde e Cidadania, or Isac, after an attack exposed data from 500,000 patients.
Brazil becomes a regional ransomware hotspot in health care
Reports released in 2026 show that Brazil accounted for 51% of the ransomware attacks recorded against [the health care sector](/en/news/paraguay-three-private-clinics-hit) in Latin America. With that volume, the country ranked among the three main global targets for this threat, according to IT Section and CISO Advisor reports published in July.
The same analysis points to an operational pattern that helps explain the impact of these incidents. In 96% of the monitored events in 2026, attackers copied sensitive information before encrypting systems. That pattern increases patient data exposure and raises the consequences for hospitals, clinics, and public health units.
The Isac case and the ANPD response
In Brazil, the case involving Instituto Saúde e Cidadania, or Isac, became one of the clearest examples of this trend. The ANPD opened a case against the organization after the hacking incident exposed data from 500,000 patients, according to Cybersec Brazil and material shared by specialists on social media.
Posts about the case say the ANPD sanction process focuses on possible LGPD violations tied to the protection of those personal data. They also indicate that the regulator is reviewing how the organization handled the information before and after the incident, including governance and the security measures in place.
According to content shared by privacy and cybersecurity professionals, the Brazilian authority could impose significant administrative penalties, including fines and limits on data processing. At the same time, the case is being used as a reference to reinforce guidance and best practices on incident response, notification to data subjects and authorities, and risk assessment in public and private health institutions.
A recurring pattern in health care
Posts aimed at data owners describe the attack on Isac as an example of the greater sophistication these groups have been showing against Brazil’s health sector. The focus on exfiltrating sensitive data before encryption appears to worsen the operational damage and may also open the door to regulatory sanctions and civil lawsuits.
In the same vein, IBSEC material on the attack against Hospital São José adds context on the lessons incidents leave for hospitals, in an environment where the focus is no longer only on restoring systems, but also on the exposure of clinical and personal information.
Sources
- Post sobre ataque de ransomware ao Instituto Saúde e Cidadania (Isac)instagram.com· Instagram (conteúdo jornalístico sobre cibersegurança)
- ANPD sanciona a Isac por filtrar 500 mil datos de pacienteses.linkedin.com· LinkedIn (Consejo de Seguridad de la Información y Ciberseguridad)
- Análisis del caso Isac y enfoque de la ANPD en gobernanza de datosinstagram.com· Instagram (perfil profesional sobre LGPD y seguridad de la información)
- Profissão Encarregado de Dados – comentário sobre caso Isacinstagram.com· Instagram (perfil profesional sobre LGPD y seguridad de la información)
- ANPD abre processo contra Isac após ataque hacker expor dados de 500 mil pacientescybersecbrazil.com.br· Cybersec Brazil
- Elytron aponta alta de ransomware na saúde no Brasilitsection.com.br· IT Section
- Brasil é epicentro de ransomware em saúde na América Latinacisoadvisor.com.br· CISO AdvisorUnverified URL
- Segurança Cibernética em Hospitais: Lições do ataque ao São Joséibsec.com.br· IBSEC



