Mexico, Argentina hit by ransomware wave
The Gentlemen hit a Mexican organization, while BlackFog reported an attack on Argentina’s Oldelval and other incidents were cited in Colombia.
The Gentlemen reached a Mexican organization, while BlackFog reported an attack on Oldelval in Argentina that affected administrative systems. Separately, ACSec logged Mexico’s MCM Telecom as a Qilin-listed victim, and other reports mentioned incidents in Colombia and Peru without official confirmation.
The Gentlemen hit a Mexican organization, and according to reporting cited by El Economista, an affiliate brought an AI assistant into compromised systems through MCP to carry out actions inside them. The same report says the campaign affected more than two dozen organizations across the United States, Mexico, France, the United Kingdom, India and the United Arab Emirates.
What is known about the use of AI in The Gentlemen?
El Economista’s coverage says an affiliate integrated an AI assistant through MCP to operate inside compromised environments. Cybernews, citing CloudSEK researchers, added that an affiliate identified as Azazel may have used the Model Context Protocol together with reverse PowerShell to connect AI tools to malicious infrastructure and interact with compromised systems.
That technical line fits a broader pattern of double extortion in recent campaigns. In this case, the available material does not allow independent confirmation of every operational detail, but it does place Mexico within the campaign’s reach and points to an unusual use of automation in criminal activity.
What other cases appeared in Latin America?
BlackFog reported that Oldelval, the operator of Argentina’s main oil pipeline network, suffered a cyberattack that affected its administrative systems. The same source said The Gentlemen claimed responsibility, although the company did not confirm the specific attack vector.
BlackFog also reported a ransomware attack on Colombia’s Ministry of Justice that encrypted files and affected part of its technology infrastructure. In that case, the source said no group publicly claimed responsibility, so it should be read as a reported but not officially attributed incident.
IntelFusions, meanwhile, said RansomHouse named a public psychiatric hospital in Lima on a leak site, although it could not confirm the incident at the time of publication. The same report mentioned that 3AM listed the Colombian health insurer Coosalud EPS and that Aurora said it had taken records from Laboratorios Roemmers in Argentina, again with the caveat that the incidents could not be verified.
What did the technical follow-up say about other groups?
ACSec’s Ransomware Observatory recorded MCM Telecom of Mexico as a victim listed by Qilin, with the Technology sector and a discovery date of October 8, 2026. At the same time, Security Affairs reported that Warlock, or Longlegs, hit four organizations in Spanish- or Portuguese-speaking countries spread across Europe, Africa and Latin America, using old SharePoint flaws.
Sherer.io detailed an attack chain tied to Warlock and Longlegs that reportedly began with the likely exploitation of Microsoft SharePoint Server on-premises and the deployment of an ASPX web shell in a LAYOUTS directory. The analysis also attributes domain reconnaissance, DLL side-loading, MSI payload downloads from public cloud or file-sharing services, concealed VS Code tunnels, NetExec use for password spraying and remote execution.
The same report said the ransomware was stored in SYSVOL to help it spread across the domain, along with abuse of a signed but vulnerable driver, K7RKScan.sys, to disable AV and EDR tools. Sherer.io linked that component to CVE-2025-1055. In parallel, The Hacker News said Longlegs, also associated with Warlock and Storm-2603, used web shells and ASP.NET machine keys from SharePoint to forge signed payloads and gain remote execution.
Sources
- Gentlemen ransomware affiliate caught diverting victimscybernews.com· CybernewsUnverified URL
- Ransomware — Latest News, Reports & Analysisthehackernews.com· The Hacker News
- The State of Ransomware: September 2026blackfog.com· BlackFog
- qilin | ACSec Observatorio Ransomwareransomware.academia-ciberseguridad.com· ACSec Observatorio Ransomware
- Ciberdelincuentes usan IA para atacar con ransomware a una organización mexicanaeleconomista.com.mx· El Economista
- Warlock/Longlegs SharePoint-to-SYSVOL Ransomware Huntsherer.io· Sherer.io
- Drugmaker Roemmers tops a week of health leak-site claimsintelfusions.com· IntelFusions
- Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructuresecurityaffairs.com· Security Affairs



