CiberLATAMbywhalemate

Uruguay Appears in Section9 Case

The domain ********.com.uy was listed by Section9 on breach trackers, but there is no official confirmation of the affected entity.

Whalemate Labs · AI-assisted researchPublished:Updated 2 min read

Uruguay appears in a case attributed to the Section9 ransomware group through the domain ********.com.uy. Several trackers list it as a breach incident, but there is no public confirmation of the affected organization or Uruguayan authorities.

The domain ********.com.uy, linked to Uruguay, was listed as a ransomware victim claimed by the Section9 group in at least two breach-tracking portals, RecentBreaches and Galaxy Warden. In both cases, it appears as an incident attributed to the actor, but there is no public confirmation from the affected organization or from Uruguayan authorities.

What did RecentBreaches show about ********.com.uy?

RecentBreaches recorded two separate entries on July 26, 2026, one for ********.com and another for ********.com.uy, both tagged "Listed by Section9 Ransomware Group" and marked high severity. That suggests a simultaneous campaign against multiple domains, although the available material does not make it possible to determine whether the Uruguayan target is a municipality or another local government entity.

What did Galaxy Warden report about the case?

Galaxy Warden also documented the case "********.com.uy Listed by Section9 Ransomware Group" as part of a list of 12 incidents linked to Section9. It describes the event as a data breach related to ransomware, but does not identify the institutional nature of the victim.

The ransomware.live portal shows Uruguay with a victim associated with Section9 on its ransomware map and publicly lists the entry "Victim: ********.com.uy, Section9." The record does not specify whether it is a public, private, or municipal entity, and it also offers no verifiable details about a local government organization.

Darkfield, in Orizon One, adds a different data point. It classifies the domain ********.com.uy under the Agriculture and Food Production sector in Uruguay, with a listing date of July 26, 2026. In the same Section9 panel on ransomware.live, Uruguay appears with one victim tied to this actor, and the group is shown with 18 total victims and its most active sectors as technology, financial services, agriculture and food, retail, and others.

How should these Section9 claims be read?

Hookphish documented a Section9 attack against an organization in the United States titled "And where does the newborn go from here? The net is vast and infinite.", described as a data breach, with breach and discovery dates. Breach House and Darkfield/Orizon One consolidate that case as a data leak attributed to the group, with a publication and leak timeline.

That material reinforces that Section9’s claims on its leak site are usually treated as alleged extortion incidents until independent verification exists. Under that same standard, the listing for ********.com.uy remains unconfirmed.

So far, the available material does not show explicit records from CERTuy or AGESIC documenting confirmed ransomware attacks against municipal governments in Uruguay.

Sources

View all