Chile: Direwolf activity and infrastructure pressure
Direwolf stayed active in September 2026, while a new analysis again highlighted the resilience of Chile’s power and telecom networks.
Direwolf maintained sustained activity in September 2026, with the EMS1R case and a declared 110 GB exfiltration, according to Ransomware.live. At the same time, an analysis of Chile’s Feb. 25, 2025 blackout recalled that a prolonged outage can drain mobile network backups and cut coverage, amid an alleged medical data exfiltration from Clínica Universidad de los Andes that has not been officially confirmed.
Direwolf maintained sustained activity in September 2026, with the EMS1R case and a declared 110 GB exfiltration, according to Ransomware.live records. The data suggests the group is still operating with significant theft volumes, and that its attack pattern is not limited to the surge seen in Chile in August 2026.
What do the records show about Direwolf?
Ransomware.live records place the group in sustained activity during September 2026. In the EMS1R case, the declared leak amounted to 110 GB, a figure that reinforces the actor’s operational continuity beyond the wave observed in August. The available reference does not add further details about the victim or the type of data compromised.
What happened to critical infrastructure in Chile?
An analysis of the Feb. 25, 2025 blackout highlighted the interdependence between energy and telecommunications. According to that study, a prolonged failure can drain mobile network backups and cause a loss of coverage. The finding again puts the spotlight on the operational resilience of services that depend on one another to stay up during an extended outage.
What medical incident remains unconfirmed?
VECERT Analyzer published an analysis of an alleged mass exfiltration of medical and personal data from Clínica Universidad de los Andes in Chile, attributed to an actor identified as Synq1xxs and linked to the Losprimos group. The publication describes samples of structured data with detailed patient information, but says the authenticity, timing and scale of the incident remain unconfirmed.
The available material leaves three signals running in parallel. Direwolf remains active in September 2026. The 2025 blackout continues to serve as a benchmark for measuring the fragility between energy and telecommunications. And in the realm of incidents attributed on intelligence-sharing channels, the Chilean clinic case is still awaiting verification.
Sources
- Del cumplimiento a la acción: los desafíos de ciberseguridad que aún persisten en Chilediarioelheraldo.cl· Diario El Heraldo
- ALLEGED MASS EXFILTRATION OF MEDICAL AND PERSONAL DATA (CLÍNICA UNIVERSIDAD DE LOS ANDES - CHILE)x.com· VECERT Analyzer (X)
- El apagón que encendió una alerta en Chileitsitio.com· itsitio.com
- August 2026 Ransomware Wrap-Upzerofox.com· ZeroFox
- Chile - Cybersecurity Framework Law (21.663)regulations.ai· Regulations.ai
- Ransomware en Chile: agosto marca récord de ataquesitsitio.com· itsitio.com
- Victim: EMS1R – direwolfpro.ransomware.live· Ransomware.liveUnverified URL
- Cybersecurity Law in Chile: Rules and Duties 2026anguitaosorio.cl· Anguita Osorio Abogados
- Ciberseguridad en Chile: leyes, normas y obligaciones 2026anguitaosorio.cl· anguitaosorio.cl



