Uruguay appears in Section9 ransomware case
Breach House lists a .com.uy domain as a claimed Section9 attack, but there is no public confirmation from the victim
Breach House logged a ransomware attack attributed to Section9 against the domain ********.com.uy, with Uruguay linked to the victim, but there is no public confirmation from the affected organization or Uruguayan authorities.
A Section9 case, with no official confirmation
Breach House logged a ransomware attack attributed to the Section9 group against the domain ********.com.uy. In that post, the case is tied to Uruguay and classified as a "ransomware attack claimed", meaning a claim posted by the leak site operator, not something publicly confirmed by the affected organization or by Uruguayan authorities.
The reference also appears on Recentbreaches, which says ********.com.uy was listed by Section9 on July 26, 2026. That portal describes the alleged exfiltration of internal files and presents the episode as a "data breach" linked to Uruguay, although it does not specify whether the target was a municipality or another local government body, and it does not provide official validation of the incident.
What the public records show
In the public view on ransomware.live, the entry "Victim: ********.com.uy, Section9" and the "Country statistics" for Uruguay show that the country has 19 victims associated with its ransomware map. That metric, however, does not break down how much corresponds to national government entities, municipalities, or other local public agencies.
Based on the information available, the case stands out more as an attribution published on leak sites than as a corroborated incident involving the parties named. In the material provided, there are also no statements from CERTuy, AGESIC, or the supposed victim that would allow the affected entity to be identified with certainty or the scope of the intrusion to be confirmed.
CERTuy's documentation on information security incident statistics for the first half of the year, along with AGESIC's institutional site, provides a framework for placing the episode within the country's digital governance and response ecosystem, but the material received does not include data connecting those records to a confirmed attack against a municipality or a local government agency.
Sources
- ********.com.uy — Section9 Ransomware Attackbreach.house· Breach House
- Estadísticas de incidentes de seguridad de la información – Primer semestregub.uy· Centro Nacional de Respuesta a Incidentes de Seguridad Informática (CERTuy)
- Agencia de Gobierno Electrónico y Sociedad de la Información y del Conocimientogub.uy· Agencia de Gobierno Electrónico y Sociedad de la Información y del Conocimiento (AGESIC)
- ********.com.uy Data Breach (2026) — What Leaked & Am I Affected?recentbreaches.com· Recentbreaches
- Country statistics – Uruguaymobile.ransomware.live· ransomware.live



