CiberLATAMbywhalemate

Brazil Leads Regional Ransomware Attacks

Brazil logged 23 ransomware attacks in June 2026, with 96% involving exfiltration before encryption, according to cited reports.

Whalemate Labs · AI-assisted researchJul 22, 20262 min read

Brazil recorded 23 ransomware attacks in June 2026, according to a Cohesity assessment cited by Direto Notícias. Another report from Brasilia é Aqui says the country accounts for 51% of attacks on one sector in Latin America, and in 96% of cases attackers first exfiltrated data and then encrypted systems.

June ended with 23 recorded attacks

A Cohesity data security report cited by Direto Notícias counted 23 ransomware attacks against Brazilian targets in June 2026. The figure points to elevated activity by ransomware groups in the country and was reported in a note published on July 18, 2026.

According to that same review, the main targets were medium and large companies, especially in services and industry. The report’s reading is that criminal groups are prioritizing victims with a greater ability to pay ransom.

Brazil’s regional weight

In another report, Brasilia é Aqui said in July 2026 that Brazil accounts for 51% of ransomware attacks against a certain sector in Latin America, based on data presented in a study by a data security company that was not identified in the available excerpt. That concentration points to a sustained presence of campaigns in the Brazilian market.

The same article added a detail about the most common tactics. In 96% of the monitored incidents, attackers first copied sensitive information from victims and only then encrypted systems. The sequence matches double-extortion schemes, where data theft is added to the pressure to regain access to infrastructure.

What the reviews suggest

Direto Notícias attributes Brazil’s prioritization by ransomware gangs, according to specialists consulted, to factors such as lower security maturity in some companies and a high rate of ransom payments. That framing does not come from consolidated official statistics, but from a technical interpretation based on the Cohesity assessment and expert statements.

Taken together, the two reports published in July paint a picture of a country with high regional exposure, medium and large companies in the crosshairs, and a widespread pattern of data exfiltration before encryption. That combination underpins the operational and financial pressure described by the sources consulted.

Sources

View all