Brazil Tightens Alerts After Ransomware Surge
Brazil logged 27 ransomware attacks in August 2026, its monthly high for the year. GSI and CISC issued new official alerts.
Brazil recorded 27 ransomware attacks in August 2026, the highest monthly total of the year to that point, while GSI issued ALERT 81/2026 and CISC published its September 8 vulnerability bulletin. The surge hit energy and utilities especially hard, doubling cases in the period analyzed.
Brazil recorded 27 ransomware attacks in August 2026, its highest monthly total of the year to that point, according to Sky.One and China Brazil Insight. The increase came alongside a string of official warnings, including CISC's Vulnerability Bulletin of September 8 and ALERT 81/2026 issued by GSI through CTIR/GSI.
What do recent data show about the country?
Available data point to an acceleration in incidents in Brazil and across the region. SCILabs reported 290 ransomware attacks in Latin America between January and June 2026, and the coverage reviewed said Brazil accounted for 25.17% of those incidents. On the local front, Sky.One's analysis using Ransomware.live data placed August as the most active month of the year, with 27 cases compared with 26 in July.
That same review shows growth remained steady through 2026. China Brazil Insight, based on recent statistics, also reported 27 attacks in August and warned about rising risks to data and operational continuity for companies with Chinese capital in the country. The piece did not add another figure, but it reinforced August's peak as the highest monthly mark of the year up to that point.
Which sectors appear most exposed?
Energy stands out as one of the hardest-hit sectors in Sky.One's analysis. The report says ransomware cases in that vertical rose from 16 to 33 incidents in the 2026 period analyzed, leaving energy and utilities as a particularly exposed segment.
That sector view aligns with the regulatory and technical framework Brazil has been building for critical infrastructure. A resolution cited by Atlas Público says GSI set guidelines for sector-specific security plans across 14 priority sectors, including electric power and oil, natural gas and biofuels, with requirements for risk management, interdependencies and resilience in plans that run for four years.
UFJF also provides the broader regulatory context. Its analysis of the National Policy for Critical Infrastructure Security, backed by Decree No. 9,573/2018, explains that these are infrastructures whose disruption can cause social, economic or state-security impacts, and it explicitly includes systems tied to electricity and water supply.
Which cases and alerts illustrate that risk?
A case reported by Ransomware.live adds a concrete episode tied to the energy industrial chain. The platform identifies Tuboaços da Amazônia Ltda. as a victim of the Nightspire group, with an attack estimated for August 11, 2026 and about 150 GB of data exfiltrated.
At the same time, GSI in the Presidency issued ALERT 81/2026 through CTIR/GSI, directed at national entities as part of the official cyberthreat warning system. On the technical side, Border Cyber Group reported, citing Siemens ProductCERT, vulnerabilities in Reyrolle 7SR5 protection relays used in electrical substations, including the critical flaw CVE-2026-62645, with a CVSS score of 9.8 and risk of session prediction or hijacking without authentication.
Taken together, the signals point to a Brazilian environment where more incidents, sensitive verticals and official vulnerability monitoring are converging. CISC's September 8 bulletin adds to that institutional response, as the country combines technical alerts, sector guidance and growing exposure in energy and other critical infrastructure.
Sources
- Victim: Tuboaços da Amazônia Ltda.ransomware.live· Ransomware.live
- Ransomware no Brasil: ataques batem recorde em 2026skyone.solutions· Sky.One
- ALERTA 81/2026gov.br· GSI - Presidência da República
- Critical Infrastructure Threat Intelligence Briefingbordercybergroup.com· Border Cyber Group
- GSI define diretrizes para planos de segurança de infraestruturas críticasatlaspublico.com.br· Atlas Público
- Boletim do CISC de Vulnerabilidadesgov.br· gov.br
- 巴西8月勒索软件攻击创年内新高,中资企业数据安全风险上升chinabrazilinsight.com· China Brazil Insight
- Alerta por ciberseguridad: crecen un 25% los ataques con secuestro de información y revelan cuáles son los países más afectadoseldestapeweb.com· El Destape Web
- Quando a informação que protege uma cidade passa a ameaçá-lawww2.ufjf.br· Universidade Federal de Juiz de Fora (UFJF)



