CiberLATAMbywhalemate

Mexico Ranked Second in LATAM Ransomware

Mexico logged about 52 ransomware attacks in the first half of 2026, ranking second in Latin America, according to SCILabs.

Whalemate Labs · AI-assisted researchPublished:Updated 4 min read

Mexico registered around 52 ransomware attacks in the first half of 2026 and ranked second in Latin America, with 17.93% of regional cases, according to SCILabs cited by El Economista. Activity across the region remained concentrated in services, government and financial sectors.

Update October 2, 2026: SCILabs kept Mexico among the Latin American countries with the most ransomware activity and said it accounted for 17.93 percent of regional cases in the first half of 2026. The updated material also adds context on KillSec, Europol’s police operation against the group, and a recent global picture based on separate measurements from Cyble and NCC Group.

Mexico was reported as the second Latin American country with the highest number of ransomware attacks in the first half of 2026, with around 52 attacks against Mexican companies and institutions, according to coverage citing the Ransomware in LATAM report. The story also said the country accounted for 17.93 percent of regional attacks, and that the most affected sectors were financial services, manufacturing and public institutions.

Which Mexican sectors saw the most attacks?

The services sector was the most targeted in Mexico, with 19.66 percent of attacks, according to La Jornada’s coverage. Government accounted for 11.72 percent, while the available material also places financial services and manufacturing among the hardest hit.

What regional data did the cited report provide?

Tribuna de la Bahía, citing the Ransomware in LATAM report, said it observed 290 ransomware incidents in Latin America during the period, up 25.54 percent from the previous half-year. The same coverage said the analysis identified 50 ransomware variants in the region.

In that tally, The Gentlemen recorded at least 49 attacks, Qilin 46, and LockBit 5.0, 43. Together, those three variants represented 47.59 percent of observed regional activity, according to the same source.

The coverage added that SCILabs based its figures on incidents observed through its intelligence sources and analyzed cases, and that the numbers do not represent the total number of ransomware attacks or attempts in Latin America. The data should therefore be read as a snapshot of observed activity, not a full count for the region.

What changed in KillSec activity?

Computer Weekly reported that KillSec favored financial services and health care organizations, especially technology companies whose products were used by clinics and hospitals. The same source added that its victims included large companies and government agencies.

Europol said law enforcement authorities made arrests and seized servers and the leak site associated with KillSec. The agency said the group obtained sensitive data by exploiting vulnerabilities and poorly secured access points.

Coverage of the Europol-linked operation said KillSec had been active since 2024 and may have carried out at least 500 successful attacks, with a possible figure close to double that, according to Infosecurity Magazine. That source did not tie those numbers specifically to Latin America.

What did August’s global measurements show?

Cyble said August’s rise in ransomware was linked, among other factors, to the recruitment of more affiliates and the exploitation of internet-facing systems. It also recorded extortion cases based only on data theft, without file encryption.

Cyble’s regional coverage said the Americas recorded 603 publicly claimed victims in August 2026, while Asia-Pacific recorded 143 and Europe 270. The methodology is based on public claims and does not necessarily equal the total number of confirmed intrusions.

NCC Group, for its part, recorded 1,073 publicly reported ransomware attacks in August 2026, about 12 percent more than in July, and ranked Qilin as the leading operation with 15 percent of recorded attacks. That measurement differs from Cyble’s publicly claimed victim count because it uses a different methodology.

Which regional case remained only a suspected victim?

VenariX en Español identified Hospital Hermilio Valdizán in Peru as a possible victim of a ransomware attack attributed by the account to the RansomHouse group, but the publication itself presents it as a possible victim and not an independently confirmed case.

Sources

View all