Cybersecurity radar on
Point-in-time cybersecurity signals across Latin America detected on X (Twitter): breaches, CVEs, ransomware, regulation, fraud, phishing, and APT activity. Updated every 4 hours.
Activity by country
Tap a country to filter the feed
Latest signals
Live- ArgentinaBreach18hData leak at Argentine fintech Credicuotas
Threat actor claims to sell 14.7 million records including DNI, CUIT and personal data.
- ChileOther18hSuspicious site tecnomaxchile.com suspended after Namecheap alert in ChileSources:@chum1ng0
- BoliviaBreach19hBolivia prosecutor investigates possible Roma system leak
Investigation opened after suspected leak of reserved information to Uruguayan drug trafficker Sebastián Marset.
Sources:@UltimaHoracom - United StatesRansomware19hThreat actor BYOD claims ransomware attack on T-Mobile in US
Listed on dark web leak site on October 7, 2026.
- MexicoRansomware19hMCM Tech-Co victim of Qilin ransomware in Mexico
Qilin group claims to have stolen data and plans to publish it in 9-10 days.
- Latin AmericaOther20hPNP arrests alleged members of “Los Terribles del Cambiazo” for aggravated fraud in Chosica
Intervention with seizure of 22 bank cards, 5 cell phones and 2 vehicles; case handled by Depincri Chosica-Chaclacayo.
Sources:@LimaRegion - BrazilRansomware20hDIPECARR victim of Eclipse ransomware in Brazil
Eclipse actor claims attack on Brazilian manufacturing company.
- BoliviaBreach21hThreat actor claims leak of Mi Teleférico data in Bolivia
Alleged publication of about 11,000 records (180 MB) of customers and employees, including names, ID documents, contacts and salaries. Unverified.
- PeruBreach21hRENIEC DNI photos quickly leaked to doxing sites in Peru
Post denounces that photos taken for DNI are leaked within minutes to multiple doxing sites in Peru.
Sources:@alconsombra - ParaguayRegulation21hBCP reports 7 banks with 11 sanctions for regulatory breaches
Sanctions for failures in anti-money laundering prevention, risk management and compliance at entities like Itaú, Atlas and Visión Banco.
- MexicoRegulation22hSanctions up to 2.4 million pesos for banks over privacy violations in MexicoSources:@C21Noticias__
- Latin AmericaAPT22hCVE-2026-88772 in Citrix NetScaler exploited by state actors weeks before patch
State actors deployed tunneler malware across gov, finance & telecom in NA/Europe — dozens compromised.
Sources:@morphisec - Latin AmericaBreach22hCyber attacks reported against SSPC and C4/C5i in Oaxaca
Sensitive information leak and attacks against SSPC systems and Oaxaca C4/C5i infrastructure.
Sources:@victor_ruiz - Latin AmericaRegulation1dDOJ and FBI seize vulnerability scanning and spear phishing tools from China-backed hackers
Enforcement action against Flax Typhoon infrastructure operated by China state-sponsored actors.
Sources:@DOJNatSec - Latin AmericaCVE1dHigh priority CVEs: SonicWall CVSS 10, Cisco, IBM Langflow
List includes CVE-2026-102255 SonicWall CVSS 10, CVE-2026-76482 Cisco, CVE-2026-104334 IBM Langflow.
Sources:@exploitgrid - ParaguayCVE1dCERT-PY warns on vulnerabilities in VMware products
CVE-2026-59347 and CVE-2026-59346 reported in VMware products.
Sources:@CERTpy - MexicoBreach1dGuanajuato suspends public service kiosks due to IT incident
147 kiosks offline since October 2. Fifth incident in Guanajuato institutions this year.
Sources:@Spaceprogrammer - BrazilBreach1dClaim of 7.34 TB breach at Brazil's UNINTER education platform
Actor Kazu publishes first 100 GB batch and threatens more every 48 hours until October 20.
- BrazilBreach1dConfirmed breach at Brazil Federal Botanical Research Institute
Open directories exposed on Malaysian VPS with intrusion kit in state government network.
- ColombiaRansomware1dNightSpire group posts possible ransomware victim: Sociedad Portuaria Mardique in Cartagena, Colombia
NightSpire group blog post indicates possible ransomware attack against the port company in Colombia.
Sources:@_venarixES_ - ArgentinaBreach1dAlleged sale of 15 million Credicuotas and Mi ANSES records by PampaLeaks
PampaLeaks group (KOIII) offers databases from Argentine fintech and social security system.
Sources:@VECERTRadar - MexicoBreach1dClaims of Mexican government databases for sale
Cybercrime channel ad offers alleged databases from SSPC, LOCATEL, Edomex, Baja California, SEP Puebla and other states.
Sources:@CyberPulse56 - ArgentinaBreach1dTucumán government: actor threatens to leak 90,000 citizen records
Group Cyberagentsss posts on underground forum database with DNI, names, addresses and phones; status unconfirmed by authorities.
- BrazilRansomware1dRansomware attack claimed on Tec Imports in Brazil
Threat actor dragonforce lists Petrosul Distribuidora, Transportadora e Comércio de Combustíveis Ltda. as victim on leak site.
- ColombiaBreach1dAlleged leak of 34,410 medical records in Amazonas, Colombia
Actor: nuevaeps. Threat of additional exposure of over 1 million records from Santander. Not officially confirmed.
- Latin AmericaBreach1dClaimed leak of 29,018 Nueva EPS records in Vaupés, Colombia
Threat actor claims 29,018 records from Vaupés department allegedly from Nueva EPS; insurer states no evidence of unauthorized access found.
- Latin AmericaBreach1dActor UmBra lists Four Hands on leak site in US
Unverified claim; no company confirmation.
Sources:@BreachHistoryBH - ArgentinaRegulation1dArgentina advances national cybersecurity plan and SOC for public agencies
Government strengthens critical infrastructure defense; CERT.AR exceeded 700 incidents.
Sources:@Marce_I_P - Latin AmericaCVE1dCisco discloses CVEs for NX-OS and Secure Firewall Management Center
- United StatesRansomware1dRansomware group incransom claims attack on The New Community School in US
Victim listed on the actor's dark web leak site.
Sources:@ThreatAtlas - United StatesRegulation1dEDNY charges Florida ransomware remediation company owner with fraud in US
Indicted for defrauding clients by falsely claiming to decrypt ransomware.
- BrazilBreach1dClaimed massive breach at Cruzeiro do Sul Educacional and 12 Brazilian universities
Threat actor S3r1aL_Br3aCh3R claims compromise of 630M+ records including student, employee, CPF and M365 accounts.
- MexicoBreach1dThreat actors claim leak of San Luis Potosí Government database
Reported data: names, dates of birth, sex, government identifiers, addresses and postal codes. Unverified status.
- Latin AmericaRegulation1dRegulation, fintech, AI and cybersecurity reshaping banking industrySources:@BlankRomeLLP
- ArgentinaRansomware2dArgentina Valores S.A. victim of LOCKBIT 5.0 ransomware in Argentina
Group claims to have obtained data and intends to publish within 14-15 days. Financial services sector.
- ChileBreach2dAlleged data breach in Peñalolén Municipality, Chile
Actor tuiyin reported on underground channels; ~394k alleged records (RUT, emails, phones) unconfirmed by authorities.
- Latin AmericaRansomware2dThe Gentlemen group posts Transportadora de Gas del Norte as possible ransomware victimSources:@_venarixES_
- ArgentinaRansomware2dTransportadora de Gas del Norte (TGN) victim of The Gentlemen ransomware in Argentina
Group claims to have obtained the organization's data and intends to publish it within 9-10 days. Energy & utilities sector.
- ColombiaCVE2dColCERT reports Colombia as seventh most affected country by FortiBleed campaign on Fortinet firewalls and VPNs
FBI warns campaign remains active; ColCERT indicates 2,436 compromised interfaces and 27 confirmed organizations in Colombia.
Sources:@jfernandogg - Latin AmericaOther2dInternational law enforcement cracking down on global scam networksSources:@USA_Patriot_GOP
- Latin AmericaBreach2dULP credential exposure from Venezuelan entities via infostealer
Samples include DIGITEL, Apuestas Royal and INTT. Massive collections of records obtained with malware.
Sources:@Arr3ch0 - MexicoBreach2dGuanajuato Government reports cybersecurity incident in its systems
Incident confirmed by state government; threat actor unknown.
Sources:@_venarix_ - MexicoBreach2dActors threaten to leak Jalisco government database
Claim by actors Frouzenx, Yar1ner, KerberusCroww and H3arth regarding data from gob.mx/jalisco.
Sources:@cyberagentsss - PeruOther2dPeru National Police warns on online shopping scams
Recommendations to verify stores, avoid advance payments and use secure platforms.
Sources:@Policia_Peruana - MexicoRansomware2dThe Gentlemen ransomware affiliate uses AI in attack on organization in Mexico
El Economista post and replications highlight The Gentlemen ransomware affiliate using AI programming assistant in compromised Mexican systems.
- Latin AmericaRansomware2dThe Gentlemen affiliate uses AI in ransomware operation in MexicoSources:@eleconomista
- United StatesRansomware2dPanzer ransomware allegedly targets SweetRush in the United StatesSources:@undercode_news
- PeruOther2dBTS scam alert in Peru: report account 998621328
Users warn about scammer operating with fake account in Peru.
- United StatesBreach2dAlleged FDTech users database sale in the United States
Seller claims 500,000 records with personal data for sale at $500.
Sources:@CyberPulse56 - Latin AmericaCVE2dFortiGate SSL VPN: FortiBleed exposes credentials and hashes; prioritize patch and MFA
Over 86 thousand devices affected in 194 countries. Password rotation insufficient.
- Latin AmericaCVE2dMicrosoft Exchange Server: Elevation of Privilege Vulnerability CVE-2026-96940
Authorization vulnerability allowing authenticated attackers to read other users' mailboxes. Patch available.
- ColombiaRegulation2dCRC Colombia presents resolution to mitigate cyber fraud in mobile services
At the Colombian Internet Governance Forum, CRC details measures against smishing, vishing and spoofing under Resolution 8308.
- ColombiaBreach2dNueva EPS attack reported as data breach in Colombia
Post indicates the incident is already international news on leak portals.
Sources:@hyperconectado - Latin AmericaCVE2dCitrix NetScaler: zero-days CVE-2026-88771, 88772 and 88779 exploited; added to KEV
Patches available but implants persist; CISA requires forensic triage. CVSS up to 9.5.
- United StatesOther2dWave of digital scams with PDF files in Latin America
During the first half of 2026, more than 107,000 phishing attacks were recorded in the region using this format.
Sources:@Diarioccidente - Latin AmericaCVE2dFortinet releases patch for CVE-2026-104286 in FortiMail
Builds 8.0.2, 7.6.7 and 7.4.9 updated. Path traversal flaw without authentication. Listed in CISA KEV.
Sources:@jfernandogg