CiberLATAMbywhalemate

LATAM Ransomware Targets Health

Kazu, Qilin and other groups are expanding in Latin America, with victims in health care, government and corporate services.

Whalemate Labs · AI-assisted researchJul 28, 20262 min read

Recent ransomware activity in Latin America shows a broader map of victims and tactics. Flare found that Kazu, which emerged in mid-2025, shifted from mainly targeting government and public-sector victims to adding health care victim postings in the region, after an initial attack on an Italian telemedicine provider.

Flare found that Kazu, a ransomware and extortion group that emerged in mid-2025, has shifted from focusing mainly on government and public-sector victims to posting new cases tied to health care in Latin America, after an initial attack against an Italian telemedicine provider.

Most exposed sectors

In Flare's analysis, government remains the main victim group attributed to Kazu, while health care ranks second among the most affected verticals. The work was based on 848 records collected from ransomware sites, hacker forums and messaging platforms.

That focus on health care also appears in the ESET Security Report 2026, based on surveys of 1,563 professionals from 962 organizations across 10 Latin American countries. The report says 52.7% of companies experienced at least one cyberattack attempt in the past 12 months, and that malware infections, including ransomware, hit the health care sector especially hard, where 52.9% of organizations reported incidents through that vector.

Tactics seen in the region

Alongside pressure on health care, researchers are seeing techniques that are becoming more visible in the region. Experts warned about ransomware attacks on organizations in Colombia and Mexico in which attackers used the victims' corporate printers to print ransom notes after encrypting systems with BitLocker. TrendTIC described that behavior as a growing tactic in Latin America, although it did not publicly attribute those cases to any specific group.

Pulse's Ransomware Wing panel also places Brazil and Mexico among the countries with the highest number of victims claimed by ransomware groups. In Latin America, the most affected sectors include business services, health care, manufacturing, technology, consumer services, agriculture and the public sector.

Groups and claims under watch

Devel Group reported on July 22, 2026, a Qilin post in which the group claimed a suspected extortion attack against a professional services company in Costa Rica, under a ransomware-as-a-service and double extortion model. The incident has not been officially confirmed by the victim.

Pulse also tracks claims tied to groups such as Deadlock, TheGentlemen, Qilin, Incransom, Akira, MedusaLocker, DragonForce and Play in Brazil and Mexico, although its database is fed by leak sites and does not always mean each incident has been independently confirmed.

In parallel, Kaseya and regional media reported that Ecopetrol, Colombia's largest oil company, confirmed a ransomware attack that led to the leak of data from 3,300 user accounts. In that case, the attackers did not manage to encrypt systems or disrupt operations, so the extortion relied on stolen information rather than a direct hit to business continuity.

Sources

View all