CiberLATAMbywhalemate

Uruguay Appears in Section9 Case

The domain ********.com.uy was listed by Section9 on breach trackers, but there is no official confirmation of the affected entity.

Whalemate Labs · AI-assisted researchAug 4, 20262 min read

Uruguay appears in a case attributed to the Section9 ransomware group through the domain ********.com.uy. Several trackers list it as a breach incident, but there is no public confirmation of the affected organization or Uruguayan authorities.

Case Listed by Section9

The domain ********.com.uy, tied to Uruguay, was listed as a ransomware victim claimed by the Section9 group on at least two breach-tracking portals, RecentBreaches and Galaxy Warden. In both cases, it appears as an incident attributed to the actor, but there is no public confirmation of the affected organization or of Uruguayan authorities.

RecentBreaches logged two separate entries on July 26, 2026, one for ********.com and another for ********.com.uy, both tagged "Listed by Section9 Ransomware Group" and marked high severity. That points to a simultaneous campaign against multiple domains, although the available material does not allow a determination of whether the Uruguayan target was a municipality or another local government body.

Galaxy Warden also documented the case "********.com.uy Listed by Section9 Ransomware Group" as part of a list of 12 incidents linked to Section9. It describes the event as a data breach related to ransomware, but does not identify the institutional nature of the victim.

What the Other Trackers Say

The ransomware.live portal shows Uruguay with a victim associated with Section9 on its ransomware map and publicly lists the entry "Victim: ********.com.uy, Section9". The record does not specify whether the entity is public, private, or municipal, and it does not provide verifiable data about a local government organization.

Darkfield, in Orizon One, adds a different detail, classifying the domain ********.com.uy under the Agriculture and Food Production sector in Uruguay, with a listing date of July 26, 2026. In the same Section9 panel on ransomware.live, Uruguay appears with one victim linked to the actor, and the group is shown with 18 total victims and its most active sectors as technology, financial services, agriculture and food, retail, and others.

Context Around Section9 Claims

Hookphish documented a Section9 attack against a U.S. organization titled "And where does the newborn go from here? The net is vast and infinite.", described as a data breach, with breach and discovery dates. Breach House and Darkfield/Orizon One also consolidate that case as a data leak attributed to the group, with a publication and leak timeline.

That material reinforces that Section9 claims on its leak site are generally treated as alleged extortion incidents until they are independently verified. By that standard, the listing for ********.com.uy remains unconfirmed.

So far, the available material does not show explicit records from CERTuy or AGESIC documenting confirmed ransomware attacks against municipal governments in Uruguay.

Sources

View all