CiberLATAMbywhalemate

Mexico accounted for 52 ransomware cases in Latin America

SCILabs logged 290 ransomware attacks in Latin America in H1 2026. Mexico accounted for 17.93%, with finance in focus.

Whalemate Labs · AI-assisted researchPublished:3 min read

SCILabs logged 290 ransomware attacks in Latin America in the first half of 2026, a 25.5% increase from the previous six months. Mexico accounted for 17.93% of the cases, about 52, while the report says finance and telecommunications remain among the strongest sectors and many SMEs still run unpatched legacy technology.

SCILabs recorded 290 ransomware attacks in Latin America in the first half of 2026, a 25.5% increase from the previous six months. Mexico accounted for 17.93% of those cases, about 52, and the report placed the financial sector and telecommunications among the strongest industries in the country. It also said many small and medium-sized businesses were still using legacy technology without updates or a solid cybersecurity program.

What do the reports say about SMEs in the region?

Kaspersky found that among the Latin American SMEs surveyed, the most damaging incidents included ransomware at 8%, while theft of sensitive information was the main target identified by 29% of respondents. In the same survey, IT security teams were the most affected at 40%, followed by accounting and finance at 36% and IT at 35%, showing that the impact was not limited to a technical function.

How did ransomware move globally in August?

Cyble reported that August 2026 marked a yearly high in ransomware activity, with 1,034 public victims attributed to 88 gangs. In another summary from the same report, [Qilin](/en/news/qilin-posts-victims-mexico-chile) and The Gentlemen were among the most active groups globally, with 145 and 110 victims, respectively.

Symantec said Warlock, also tracked as Longlegs by Symantec and Storm-2603 by Microsoft, was exploiting Microsoft SharePoint vulnerabilities to compromise organizations in Spanish- and Portuguese-speaking countries, including Latin America. Among the victims observed by Symantec were a water utility, a telecom provider, a regional government entity and a university.

The coverage also said Warlock was targeting organizations in Spanish- and Portuguese-speaking countries across Latin America, Europe and Africa. BleepingComputer added that Storm-2603, according to Microsoft’s tracking, was among the actors exploiting the ToolShell SharePoint vulnerability chain, and said those flaws were still viable initial access vectors more than a year after Warlock first emerged.

The Hacker News detailed that Longlegs combined SharePoint access with web shells and forged __VIEWSTATE payloads, and used the signed vulnerable K7RKScan driver to disable security tools before deploying ransomware. CyberPress, meanwhile, recommended applying SharePoint patches, rotating ASP.NET machine keys after a possible intrusion, blocking vulnerable drivers, reviewing SYSVOL and monitoring tunnels, unusual downloads and queries to oastify.com.

Security Affairs said the persistence of the attacks is partly explained by the fact that some organizations had still not applied patches or mitigations for the SharePoint vulnerabilities associated with ToolShell. An independent analysis said the match between Storm-2603 and Longlegs, as well as the broader link to China, should be considered moderately reliable, so that attribution should not be presented as fully confirmed.

Sources

View all