Chile cyber resilience focus shifts to energy
Chile is weighing controlled degradation in energy as Rutify, Direwolf and Kaspersky data point to pressure on critical systems.
Chile’s critical infrastructure debate is now centered on operational resilience in energy, public sector exposure and attacks on health systems. At Industrial Cyber Summit 2026, speakers discussed controlled degradation to keep services running during incidents, while recent cases such as Rutify, a ransomware case at a university hospital and a Kaspersky survey highlighted growing pressure on agencies and companies.
Chile’s critical infrastructure debate has been shaped by operational resilience in energy, exposure in public systems and attacks against the health sector. At Industrial Cyber Summit 2026, the discussion turned to controlled degradation as a way to keep services running during incidents. In recent weeks, warning signs have also piled up with Operation Rutify, a ransomware case at a university hospital and a survey that attributes a meaningful share of attacks against Chilean organizations to artificial intelligence.
What did Industrial Cyber Summit 2026 put on the agenda?
In energy, the focus was on how to keep operating even if part of the infrastructure fails, so service outages do not become total interruptions. TECNAUTAS said that was one of the main themes in Chile, along with supply chain security as a central challenge for critical industries because vendors and third parties can access sensitive processes.
The same report recalled the blackout that affected much of Chile on February 25, 2025, as a lesson in the vulnerability and interdependence of essential services, including energy and telecommunications. That reading fits with Colbún’s account of the Canutillar hydroelectric plant, which showed its strategic role by returning to autonomous operation without power from the grid and helped make Puerto Montt one of the first cities to regain supply.
What do the recent cases show about exposure and ransomware?
In Chile, Operation Rutify ended with the arrest of one alleged participant in a network that is said to have breached systems tied to Fonasa, Servel, the Treasury and Sernac, according to CronUp. Prosecutors accuse an 18-year-old student of leading the group linked to the mass leak, which reportedly reached websites belonging to public and private institutions, including Fonasa, Sernac, the Treasury, IPS, the Digital Government Secretariat and the Municipality of Las Condes.
Lunmas also reported that the case describes a technical method based on automated web scraping, using flaws in institutional site code to extract large volumes of data. In that file, the attack vector appears more tied to design weaknesses and information exposure than to a classic CVE-type vulnerability.
CronUp added another health sector case, with the Hospital Clínico Universidad de Chile listed as a Direwolf victim amid a historic rise in ransomware victims observed in Chile during August 2026. Tech-Insider.org said that on August 30, 2026, the group posted three new victims in 24 hours, including that hospital and another health center in Turkey, reinforcing its pattern of coordinated campaigns against healthcare infrastructure.
What do the data say about AI use in attacks?
A Kaspersky survey cited by Infobae said 76% of organizations believe artificial intelligence was present in about half or more of the cyberattacks they received in the last 12 months, including Chilean companies. The figure adds to concerns about the attack surface facing agencies and critical service providers in a setting where law enforcement operations, data exposure and health sector attacks are connected by the same problem, essential services under growing pressure.
Sources
- Colbún S A : Consejeros Regionales visitan la Central Canutillar para conocer su rol estratégico en el sistema eléctrico nacionales.marketscreener.com· MarketScreener / Colbún S.A.
- Sistema Eléctrico Nacional | Gobierno respalda sanciones del SEC por mega corte 25 feb y apuesta por Kimal-Loperiodismo2.cl· Periodismo2
- Direwolf-Ransomware trifft THQ Nordic: 335 GB gestohlen ...tech-insider.org· Tech-Insider.org
- Industrial Cyber Summit 2026 reunió a más de 400 asistentes y abordó los desafíos del phishing y la IA para las industriastecnautas.cl· TECNAUTAS
- Panorama De Ciberseguridad: Semana Del 31 De Agosto Al 04 De Septiembre De 2026cronup.com· CronUp Ciberseguridad
- Feed De Noticias De Ciberseguridad [04/09/2026]cronup.com· CronUp Ciberseguridad
- La IA ya está detrás de la mitad de los ciberataques que sufren las empresas chilenasinfobae.com· Infobae
- Acusan a estudiante de 18 años de masiva filtración de datos personaleslunmas.cl· Lunmas
- Ojo con estas dos plataformas que no están registradas ni autorizadas para operar en Chile (sección relacionada: Operación Rutify)chocale.cl· Chócale



