Peru logs 83 victims on ransomware.live
ransomware.live lists 83 Peru-linked victims, without attribution to any group. VECERT also reported unconfirmed activity.
ransomware.live shows 83 victims linked to Peru, but the view does not identify a specific incident or group. At the same time, VECERT reported unconfirmed activity tied to cybercrime posts mentioning Peruvian organizations, including an alleged impact on Gobierno Regional de C.A.F.E.D.
ransomware.live shows 83 victims for Peru in the view consulted, but the record does not identify a specific incident or attribute the activity to any particular group. At the same time, VECERT published on August 18, 2026, a monitoring summary of posts linked to alleged compromises, privileged access, databases, and exposed information involving organizations in several countries, including Peru, although all of it was classified as unconfirmed activity.
What did VECERT show about Peru?
VECERT said its centralized monitoring system detected new posts on August 18 tied to alleged compromises and data exposure, with regional scope. Within that set, it specifically mentioned a supposed impact on a Peruvian government entity identified in the notice as Gobierno Regional de C.A.F.E.D., but clarified that the post was still under review and that the classification remained unconfirmed.
The radar also said the monitored posts came from different sources, including government bodies, technology companies, and private organizations. In that same report, it placed activity related to Peru alongside Australia, the United States, Rwanda, Ukraine, and India, situating the possible Peruvian exposure within a broader environment of transnational cybercrime that remains unverified.
What does the ransomware.live count add?
ransomware.live provides an aggregated count, not operational attribution. The Peru view shows 83 victims and lists 12 CISRTs or CERTs for the country, but it does not let the reader link that number to a specific incident or a named actor in the information provided.
Based on the available data, what can be verified here is the existence of an aggregated record for Peru on ransomware.live and, separately, VECERT monitoring of cybercrime posts that include mentions of Peruvian organizations, always under the label of unconfirmed activity. The material available does not confirm a recent ransomware campaign in Peru or provide specific local TTPs.
Sources
- Alerta de monitoreo sobre publicaciones de cibercrimen con menciones a organizaciones de Perú (actividad no confirmada)x.com· VECERT (radar público en X/Twitter)
- 83 victims for Peruransomware.live· ransomware.live



