CiberLATAMbywhalemate

Mexico Ranks Second in LATAM Ransomware Cases

Mexico ranks second in Latin America for ransomware victims, with more than 270 public cases by late July and services among the main targets.

Whalemate Labs · AI-assisted researchPublished:Updated 4 min read

Mexico stands out in 2026 as one of the hardest-hit ransomware targets in Latin America. The Ransomware.live map shows more than 270 public victims through late July, while Ransomware Response places LockBit 3.0, Qilin and LockBit5 among the groups with the most cases in the country.

Mexico emerged in 2026 as one of the most active ransomware targets in Latin America. An EITMedia analysis, based on a report from an international security firm, places the country second in the region by victim count, behind Brazil, in a half-year period when global attack volume rose 16.5%.

Which groups are operating in Mexico?

Ransomware Response’s monitoring for Mexico shows the most active groups by recorded victims are LockBit 3.0, with 31 cases, Qilin with 20, LockBit5 with 12, Cl0p with 11 and RansomHub with 8, according to Ransomware Response for Mexico. That snapshot aligns with other measurements pointing to sustained double-extortion activity in the country.

Ransomlook.io also records recent leak-site posts attributed to LockBit, Akira and Qilin with victims in several Latin American countries, including Mexico, during June and July 2026, according to Ransomlook.io. Meanwhile, BreachSense’s July 2026 report places TheGentlemen and Qilin in the global top spot for listed victims, with 119 each, out of 811 companies affected by 66 groups across 78 countries, according to BreachSense.

Computerworld España, using data from NCC Group and Comparitech, ranks Qilin and The Gentlemen first and second worldwide by number of attacks in the second quarter of 2026, while Akira, DragonForce and LockBit round out the top six, according to Computerworld España, NCC Group and Comparitech. EITMedia adds that Qilin has 722 confirmed attacks in the half-year, The Gentlemen about 550 and Akira more than 300, figures that frame the activity seen in Mexico within broader campaigns, according to EITMedia.

Which sectors are most exposed?

In Mexico, the sectors most affected by ransomware are Business Services, with 40 victims, Manufacturing with 30, Technology with 21, Public Sector with 19 and Healthcare with 14, according to the sector monitoring cited. The pattern leaves business services and manufacturing as the main targets.

That focus fits Blackpoint Cyber’s profile of The Gentlemen, which describes it as a RaaS operation that emerged in August 2025, specialized in double extortion and particularly focused on industrial and manufacturing sectors, according to Blackpoint Cyber. The same source also says the most frequent victim headquarters regions include Asia and South America, which reinforces its presence in markets like Mexico.

Veeam places Akira at 9% of the market share of observed payment variants in the second quarter of 2026 and The Gentlemen at 8%, according to Veeam. That keeps both among the core of the most profitable extortion operations globally.

What pressure are they putting on corporate defenses?

The technical analysis cited by Computerworld España says The Gentlemen adopted a framework called GentleKiller, with variants that use vulnerable drivers and utilities to disable EDR solutions and target a wide range of endpoint security products, according to Computerworld España. That capability increases the likelihood of operational disruption in organizations with advanced controls.

Ransomware.live’s map shows Mexico with more than 270 publicly identified victims through the end of July 2026, according to Ransomware.live. The figure exceeds some regional reports and suggests undercounting in earlier estimates, as well as a real exposure higher than the "almost 80" cases cited by other media.

Sources

View all