LATAM Ransomware Targets Health
Kazu, Qilin and other groups are expanding in Latin America, with victims in health care, government and corporate services.
Recent ransomware activity in Latin America shows a broader map of victims and tactics. Flare found that Kazu, which emerged in mid-2025, shifted from mainly targeting government and public-sector victims to adding health care victim postings in the region, after an initial attack on an Italian telemedicine provider.
Flare found that Kazu, a ransomware and extortion group that emerged in mid-2025, has shifted from focusing mainly on government and public-sector victims to posting new cases tied to health care in Latin America, after an initial attack against an Italian telemedicine provider.
Most exposed sectors
In Flare's analysis, government remains the main victim group attributed to Kazu, while health care ranks second among the most affected verticals. The work was based on 848 records collected from ransomware sites, hacker forums and messaging platforms.
That focus on health care also appears in the ESET Security Report 2026, based on surveys of 1,563 professionals from 962 organizations across 10 Latin American countries. The report says 52.7% of companies experienced at least one cyberattack attempt in the past 12 months, and that malware infections, including ransomware, hit the health care sector especially hard, where 52.9% of organizations reported incidents through that vector.
Tactics seen in the region
Alongside pressure on health care, researchers are seeing techniques that are becoming more visible in the region. Experts warned about ransomware attacks on organizations in Colombia and Mexico in which attackers used the victims' corporate printers to print ransom notes after encrypting systems with BitLocker. TrendTIC described that behavior as a growing tactic in Latin America, although it did not publicly attribute those cases to any specific group.
Pulse's Ransomware Wing panel also places Brazil and Mexico among the countries with the highest number of victims claimed by ransomware groups. In Latin America, the most affected sectors include business services, health care, manufacturing, technology, consumer services, agriculture and the public sector.
Groups and claims under watch
Devel Group reported on July 22, 2026, a Qilin post in which the group claimed a suspected extortion attack against a professional services company in Costa Rica, under a ransomware-as-a-service and double extortion model. The incident has not been officially confirmed by the victim.
Pulse also tracks claims tied to groups such as Deadlock, TheGentlemen, Qilin, Incransom, Akira, MedusaLocker, DragonForce and Play in Brazil and Mexico, although its database is fed by leak sites and does not always mean each incident has been independently confirmed.
In parallel, Kaseya and regional media reported that Ecopetrol, Colombia's largest oil company, confirmed a ransomware attack that led to the leak of data from 3,300 user accounts. In that case, the attackers did not manage to encrypt systems or disrupt operations, so the extortion relied on stolen information rather than a direct hit to business continuity.
Sources
- Ransomware gangs go after EMEA healthcare's supply chainhelpnetsecurity.com· Help Net Security
- Expertos alertan sobre una creciente táctica de ransomware: hackers imprimen demandas de rescate durante ataques en América Latinatrendtic.cl· TrendTIC
- Emergence and Operations of The Gentlemen Ransomwaremallory.ai· Mallory AI
- Brasil lidera ataques de ransomware na América Latina em 2026 e expõe falhaslucasalcaraz.com· LucasAlcaraz.com
- Ransomware Wing — víctimas, grupos y patronespulse.kalir.io· Pulse (Kalir.io)
- Ransomware in 2026: Same Business, New Rulesgroup-ib.com· Group-IB
- Kaspersky alerta sobre una creciente táctica de ransomware: hackers imprimen demandas de rescate durante ataques en América Latinalatam.kaspersky.com· Kaspersky
- Prints of darkness: Hackers printing demands during ransomware campaigns across Latin Americakaspersky.com· Kaspersky
- Presunto Ataque del Grupo 'Qilin' en el Sector de Servicios Profesionales en Costa Ricadevel.group· Devel Group
- ESET: 4 de cada 10 empresas en América Latina operan a ciegas ante los ciberataquescanalnews.ec· ESET / CanalNews EC
- Vulnerabilidades y ransomware elevan el riesgo operativo para industrias estratégicas, advierte Kaseyaitwarelatam.com· ITware Latam / Kaseya



