CiberLATAMbywhalemate
Intelligence report

Energy, Electricity and Utilities Critical Infrastructure

September saw more coordinated action and less ransomware, with outages, nuclear alerts, and utility fraud across Latin America.

Oct 1, 202629 min read
Energy, Electricity and Utilities Critical InfrastructurewhalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are completed automatically with verified dated facts within the period. Each one states its basis and counting criterion, so the figures reconcile across modules. They are the recurring month-to-month reading; the analysis that follows develops the cases without repeating this summary.

Indicator window: 66 dated facts in September 2026 · 2 from prior months (comparative frame, not month volume). Facts from prior months are used only as a comparative frame in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Verified Signal Monthly Dashboard September 2026 · Latin America Leading threat: Unclassified (33 of 66 events). Coverage: 66 dated events in September 2026 · 2 months… VERIFIED EVENTS 66 period base: all counts measured from the bottom over this total RANSOMWARE / EXTORTION 1 1 unclassifiable classification with the material UNCLASSIFIED INCIDENTS 23 breaches or outages without threat type declared FRAUD / PHISHING 2 documented fraud campaigns documented REGULATION 2 standards, regulations, or penalties UNIQUE CVEs 2 CVE-2026-73807 / CVE-2026-82567
Verified Signal Monthly Dashboard — Base: 66 verified, dated events for Latin America.
MONTHLY FIXED MODULE Distribution by threat axis September 2026 · Latin America Each event counts in only one axis, so the total is exactly 66. "Unclassified incidents" is the remainder. Unclassified 33 Incidents 23 Vulnerabilities 5 Fraud 2 Regulation 2 Ransomware 1
Distribution by threat axis — Each event is assigned to a single axis based on its classification; the total reconciles to the 66 events in the period.
MONTHLY FIXED MODULE Sectoral Distribution of Signal September 2026 · Latin America Base: 66 incidents in the period · total 92 because 20 incidents are classified in more than one sector. Public sector / OIV 28 Energy 25 Other / unidentified sector… 13 Telecom 11 Retail / Consumer 6 Technology 6 Healthcare 2 Finance 1
Sectoral Distribution of Signal — Heuristic sector classification by victim. One incident may affect more than one sector, so totals may exceed the base.
MONTHLY FIXED MODULE Geographic Signal Distribution September 2026 · Latin America Each item is assigned to a single country or to regional coverage, so the total is exactly 66 of 66 items… Brazil 21 Regional 16 Mexico 9 USA 9 Colombia 6 Uruguay 5
Geographic Signal Distribution — Verified items from the period grouped by country or regional coverage; each item is counted only once.

Monthly executive summary

September closed with a more scattered signal than in prior months, but one that was no less significant for energy, electricity, and utilities in Latin America. The month combined service disruptions in Mexico, Argentina, Cuba, and Venezuela with a visible increase in cyber defense exercises, regulatory alerts, and fraud activity tied to a Uruguayan utility. Across the material reviewed, the dominant threat remained unclassified, reflecting coverage that leaned more toward resilience, operational continuity, and compliance than toward campaigns with firm technical attribution.

The core picture is twofold. On one side, there were operational incidents that affected users and power networks, with particular weight in Mexico and Cuba. On the other, an increasingly active institutional agenda took shape around critical infrastructure, especially in Brazil, where the Guardião Cibernético 8.0 exercise brought together energy, water, telecommunications, defense, and nuclear regulation entities. That deployment was not ceremonial, the material presents it as training for prevention, response, recovery, and cross-sector coordination against cyber incidents.

In volume terms, the month was dominated by events not classified as breaches or outages, with 23 such cases out of 66 verified incidents during the period. That points to a broad risk surface, but not always one attributable to confirmed cyber incidents. One case was also recorded with ransomware or extortion as the primary focus, although the source does not allow a precise determination of whether assets were encrypted, data was exfiltrated without encryption, or the item only appeared on a leak site. In parallel, there were two fraud or phishing cases and two documented regulatory moves.

The regulatory block deserves attention because it goes beyond formal compliance reporting. The public consultation opened by the Autoridade Nacional de Segurança Nuclear in Brazil, together with ANEEL's entry into Sisbin, shows a clear trend toward integrating intelligence, sector-specific regulation, and operational security. In the same country, the nuclear sector took part in unprecedented cyber crisis simulations, expanding the preparedness perimeter from power generation and distribution to radiological and nuclear facilities.

The available evidence also points to a shift in the regional conversation. Instead of a sequence of major ransomware cases, September was marked by service continuity, sabotage or vandalism on transmission lines, fraud campaigns that exploited utility support channels, and high-level exercises for critical infrastructure. The region did not show a drop in risk, but rather a reconfiguration of the type of risk visible in coverage.

Regional overview for the month

September’s regional signal was medium to high in operational severity, but geographically scattered and thematically uneven. No single campaign shaped the month, but several signs of fragility did emerge, including large-scale blackouts, a complete grid collapse in Cuba, severe fluctuations in Venezuela, fraud using a utility brand in Uruguay, and a more robust regulatory framework in Brazil for the nuclear and power sectors.

Mexico was home to one of the month’s most sensitive events, with a power outage that affected hundreds of thousands of users in the southeast and later became the subject of public debate over vandalism, sabotage, and damage to high-voltage lines. Cuba recorded the most significant systemic episode, with the collapse of its national power grid on September 18 and a partial recovery afterward. Argentina also reported a major outage in Buenos Aires, although the cited source attributed it to a failure in a system outside the utility’s control.

Brazil, by contrast, did not contribute a mass outage to the overall period, but it did show the highest density of preventive and regulatory activity. There, the maturation of the critical infrastructure approach is especially clear. Guardião Cibernético 8.0 brought together public agencies, private companies, regulators, and operators in strategic sectors to test complex attacks against basic services. The interaction between ANSN, CNEN, ANEEL, ANA, the Defense Ministry, and sector actors suggests a broader cooperation framework than is usually seen in other countries in the region.

Fraud activity appeared clearly in Uruguay, where police and local media reported a scheme that impersonates UTE employees to capture WhatsApp codes and take over victims’ accounts. That pattern does not point to an attack on the power grid, but it does show how trust in a utility company can be exploited to enable fraud and possible follow-on scams. In terms of attack surface, it is a concrete sign of social engineering applied to the energy ecosystem.

By country, the most concerning picture was Mexico, because of the impact on customers and the dispute over the cause; Cuba, because of the national grid collapse; and Brazil, because of the breadth of institutional coordination. If volume and severity are weighed together, the regional risk for the month can be classified as high, but not because of a single threat family. It is driven by the coexistence of large-scale outages, causal uncertainty, and a defense and compliance agenda that already treats critical infrastructure as a target that must be tested continuously.

Period indicators

Indicator Value Prior month comparison Base / window
Verified events in the period 66 52, +14 Base: 66 events dated in September 2026. Time window: 66 events dated in September 2026 and 2 from prior months, for context only, not monthly volume.
Unclassified incidents (breaches or disruptions) 23 15, +8 Base: 66 verified events in the period.
Cases with ransomware or extortion as the primary focus 1 21, -20 Base: 66 verified events in the period.
Ransomware breakdown by impact type, classification cannot be determined from the material 1 N/A Base: 66 verified events in the period.
Documented fraud or phishing cases 2 1, +1 Base: 66 verified events in the period.
Documented regulatory moves 2 3, -1 Base: 66 verified events in the period.
Critical CVEs mentioned 2 No comparable data from the prior month Base: 66 verified events in the period.
Sectors with at least one documented event 7 6, +1 Base: 66 verified events in the period.
Dominant threat of the month Unclassified (33 of 66 events) Ransomware (21 of 52 events) Base: 66 verified events in the period.
Events with direct source confirmation 86% N/A Base: 66 verified events in the period.
TIMELINE Verified events for the period 1/9 Procesoreportedthat CFE 1/9 The FederalCommission of 1/9 The localnewspaperYucatán 1/9 Latinus reportedthat the 1/9 An independentanalysis of 1/9 BNamericasreportedthat,accordingto
Verified events timeline, September 2026 — Milestones with confirmed dates within September 2026. Events from earlier months are excluded from the timeline and used only as comparative context.

Relevant Incidents

Power outage in southeastern Mexico and dispute over the cause

The electric disruption that affected Yucatán, Quintana Roo, Campeche and Chiapas was one of the month’s broadest events, both in the number of users affected and in the way its origin was debated. According to Bloomberg Línea, CFE filed a complaint with Mexican prosecutors for vandalism after an outage left more than 745,000 customers without power on the night of August 31 and the early hours of September 1. Coverage from La Jornada reported 171 medium-voltage circuits affected and two 400 kV lines in Hecelchakán, Campeche.

The key point for this report is that the verified information describes a service interruption and a hypothesis of intentional damage, but not a confirmed cyber incident. Proceso said the company first changed its explanation and later blamed vandalism, without publicly detailing the exact point of damage, its nature or the status of the investigation. Infobae, meanwhile, reported that Claudia Sheinbaum declined to confirm sabotage and said there were no conclusive reports supporting that theory.

The event therefore remained in a gray zone between operational outage, criminal complaint and dispute over the cause. That matters analytically for the sector because public narratives can shift quickly when a blackout of this scale affects several states and hundreds of thousands of users. It also shows that, even without technical attribution to cybersecurity, the operational and political pressure around a power grid can push the conversation toward sabotage, resilience and critical infrastructure monitoring.

Total collapse of Cuba’s power grid

Cuba’s event was the most severe of the month because of its systemic nature. Reuters reported that the national power grid suffered a total collapse on September 18, 2026, leaving the island without electricity, and that Cuban authorities blamed a failure in transmission lines in the western part of the country. Associated Press confirmed that the system collapsed again and that the western failure then disconnected the eastern sector.

AFP added operational context, noting that the later reconnection did not mean an immediate return to normal service because outages continued due to a generation deficit. The agency also said recovery prioritized hospitals and other essential facilities, and that by the day after the collapse, power had been restored to nearly half of Havana’s customers. Xinhua also reported that state-owned Unión Eléctrica said the grid had fully disconnected while the cause remained under investigation.

There is no attribution to a cyberattack in the material reviewed, and it would be wrong to invent one. Even so, the episode matters for cybersecurity readers because the collapse of a national power grid changes the exposure threshold for any response plan, including communications, emergency logistics and continuity of essential services. In a vertical like this, the boundary between technical failure, energy crisis and physical security risk is especially narrow.

Outage in Buenos Aires affected 600,000 customers

Buenos Aires recorded another significant outage, though on a smaller scale than the Mexican or Cuban cases. The Rio Times reported that roughly 600,000 customers lost service and that Edesur said the outage was caused by a failure in a system outside the company. The cited source did not attribute the event to a cyberattack or malicious tampering, so the case should be read as an operational continuity incident rather than a confirmed intrusion.

The significance of this event lies in its urban scale and in the dependence on external systems for power delivery. For a technical audience, that distinction matters because it shows that part of supply resilience depends on components and services that are not always under the final operator’s direct control. When that link fails, the impact can be broad even if the failure has no malicious digital component.

Severe fluctuation in Venezuela’s electrical system

The Rio Times also reported a severe fluctuation in Venezuela’s National Electric System, with service interruptions and voltage drops in Caracas and several states. The material does not attribute the episode to a cyberattack or provide a definitive technical explanation, but it does confirm another episode of grid instability in a country where power continuity is a critical variable for multiple services.

The analytical value of this event is structural rather than isolated. Severe fluctuations are not the same as a cyber incident, but they do make it harder to distinguish among technical degradation, generation crisis, transmission failures and possible malicious interference. For security and operations teams, that environment requires close coordination with engineering and continuity management, because the first public explanation for a blackout rarely captures the real cause.

Guardião Cibernético 8.0 exercise and nuclear sector protection

Brazil concentrated the month’s main preventive activity with the Guardião Cibernético 8.0 exercise. According to the Ministry of Defense, it brought together about 1,300 participants, 300 organizations and representatives from 14 countries, with strategic sectors including energy, water, telecom, communications, biosecurity and the economy. Coverage by Capital S/A and Banda B added that more than 240 institutions participated and that the goal was to simulate complex attacks against critical infrastructure.

The most relevant development for this vertical was the explicit inclusion of the nuclear sector. ANSN said it tested the ability to prevent, respond to and coordinate action against cyber incidents in unprecedented scenarios, while CNEN said it took part in simulations aimed at strengthening prevention, response and recovery against incidents that could affect critical infrastructure and the continuity of essential services. LRCA Defense Consulting detailed that the nuclear component worked through four scenarios in Brasília, involving a land-based nuclear plant, a hospital, a laboratory and a vessel transporting nuclear material to a floating plant.

That level of detail shows that the discussion is no longer abstract. Interagency coordination is being tested with scenarios that combine energy, health, logistics and sensitive material. For a security team in the sector, the signal is clear, resilience is now being assessed across functions, not just within silos, and that changes how contingencies, escalation and decision-making are prepared.

ANEEL joins Sisbin and strengthens the regulatory axis

Brazil’s National Electric Energy Agency was added to the Sistema Brasileiro de Inteligência through a portaria published in September 2026, and sector coverage explained that the measure is intended to expand institutional cooperation, strategic data sharing and risk prevention for the security of the national power sector. This is a regulatory and intelligence move, not an incident, but it has direct operational implications for a sector that depends on anticipating threats rather than only responding to them.

ANEEL’s addition to Sisbin is relevant because it formalizes deeper integration among regulation, intelligence and critical infrastructure protection. In the context of the month, that step aligns with Guardião Cibernético 8.0 and with ANSN’s public consultation on cybersecurity requirements for nuclear and radiological facilities. Together, those developments point to an institutional environment in which cybersecurity is treated as part of sector governance, not as a separate function.

Fraud using the UTE brand in Uruguay

Uruguay provided the month’s main fraud signal within this vertical. El Observador reported a scheme in which criminals pose as UTE employees to request a verification code and take control of WhatsApp accounts, then use those accounts to ask the victim’s contacts for money. Telenoche also reported a specific case in Rocha using the same method, while the police headquarters recommended using the Ministry of the Interior’s official "Verificá" service.

La diaria, meanwhile, put the issue in context by noting that reports of fraud and digital scams have increased in Uruguay and that the WhatsApp account takeover example was used to illustrate the trend. For this report, the key point is that the fraud did not target the power grid, but it did exploit the utility’s identity as a trust vector. That makes it a useful signal for communications teams, customer service and social engineering prevention.

CenterPoint and Ecopetrol, signals without operational confirmation for the month

September’s material also included mentions of an alleged leak or extortion tied to Ecopetrol and a claim of stolen records from CenterPoint, but both came with clear limitations. In the Ecopetrol case, several sources cited in the material present it as an allegation from a threat actor, a leak-site entry or an attribution without public confirmation from the company of a successful intrusion. In the CenterPoint case, Fox News reported the attacker’s claim of 7.49 million records, but the article itself presents it as a claim not validated by the company.

For a rigorous analysis, these cases should not be inflated beyond what the material supports. They do show that the utilities ecosystem remains a target for exfiltration pressure and reputational exposure, but they are not enough to build a confirmed operational-impact incident for September. That is why the report treats them as threat or allegation, not as a closed breach.

Active Threats and Campaigns

Ransomware, extortion, and leak site mentions

The month produced only one case in which ransomware or extortion was the main focus, but the source does not let us determine whether the impact involved encrypted assets, exfiltration without encryption, or only a mention of the victim on a leak site. That distinction matters because it changes the operational reading completely. A leak site mention without verified impact is not the same as system downtime, and exfiltration does not necessarily mean encryption.

The Ecopetrol-related material sits squarely in that gray area. VECERTRadar, Kalir, Tornews and Ransomware.live reflect different forms of attribution or exposure, but all remain at the level of allegation or third-party recording, not a public forensic confirmation by the company. BNamericas did confirm in July 2026 that Ecopetrol activated its cybersecurity protocol after detecting that an external actor had stolen corporate information, but that event belongs to the comparative frame of prior months and not to September’s volume.

That time gap matters as well. In September, the ransomware signal in Latin American utilities was much weaker than in July, which does not mean the risk disappeared. It means the month was driven more by preventive activity, disruption cases and leak allegations than by confirmed encryption campaigns within the period.

Fraud and phishing

The clearest fraud scheme of the month was the impersonation of UTE officials to capture WhatsApp codes. It is a classic social engineering technique, adapted to a utility context, with a believable script for the victim and a secondary target that goes beyond the company, taking over the messaging channel to request money from contacts. In impact terms, this combines reputational damage, social engineering and account takeover, although it does not directly compromise power operations.

The value of this campaign for the sector is that it shows how a trusted public brand can be used to open a human breach without exploiting technical vulnerabilities. The response, therefore, is not only technological. It requires customer messaging, verification procedures, staff training and coordination with law enforcement. The material also offers a concrete operational recommendation, use the official "Verificá" system, which should be reinforced in public awareness campaigns.

APT and hacktivism

The material did not include a solid case of APT or hacktivism attributed to the energy, electricity and utilities vertical in September. There was, however, public discussion about sabotage, vandalism and intentional damage around the blackout in southeastern Mexico, but the available information did not allow confirmation of a cyber component or a persistent campaign. In Cuba and Venezuela, there was also no attribution to specific actors, and the events remained in the realm of grid crisis and supply stability.

The absence of a closed attribution should not be read as the absence of threat. It shows, instead, that in this month the public evidence available was insufficient to classify persistent or hacktivist campaigns in this vertical. The operational reading should therefore focus on availability, interagency coordination and fraud prevention, rather than forcing an actor label where the material does not support one.

Critical vulnerabilities

No critical CVEs were recorded in the source material with enough technical detail for this report, although the period indicator lists 2 critical CVEs. That figure shows that references to critical vulnerabilities appeared in the coverage, but the available material does not provide enough detail to describe exploitation, scope, or any link to a specific incident in the vertical. That does not mean critical vulnerabilities exploited in the region are absent.

CVE Software Exploitation Source
CVE-2026-82567 mySCADA myPRO Manager / notification gateway The material describes it as an authentication flaw that allows unauthorized SMS messages and privileged functions without proper authentication. SecNora, GitHub Advisory Database, CISA ICS Advisories
Not specified in the material mySCADA myPRO Manager The cited public source describes an ICS advisory about insufficient authentication for privileged functions. Cybersecurity and Infrastructure Security Agency
CVEs and critical advisories citedCVE-2026-82567mySCADAweak authICS advisoryCISA / GitHubfunctionsprivilegedReferences onlyno exploitation
Critical vulnerabilities mentioned — Visual summary of the critical advisories cited in this month’s material.

Regulation and compliance

The month’s regulatory agenda was most active in Brazil, but its effects can extend to other markets in the region. ANSN’s public consultation on cybersecurity requirements for nuclear and radiological facilities sends a clear signal: the sector is no longer focused only on technical boundaries, but on principles, obligations, and response mechanisms aligned with critical risk management. The start date, September 10, and the publication of the edital in the Diário Oficial da União show that the process has formal backing and is not just a policy statement.

ANEEL’s inclusion in Sisbin carries a different weight. This is not a compliance requirement for private operators, but an institutional decision that strengthens data sharing and cooperation with intelligence. For the power sector, that can translate into better threat anticipation, but also into stricter governance requirements for shared information, coordination channels, and the traceability of sensitive decisions.

The Guardião Cibernético 8.0 exercise follows the same logic of practical compliance. ANSN said it tested prevention, response, and coordinated action in the face of cyber incidents, and CNEN said the goal was to strengthen recovery from incidents that could affect critical infrastructure. That kind of drill leaves a direct lesson for utilities and critical infrastructure operators, preparedness is no longer validated only through written plans, but through multi-stakeholder exercises where coordination failure matters almost as much as technical failure.

In Uruguay, the regulatory dimension is more about citizen prevention and police response to fraud. The UTE case was accompanied by specific recommendations for identity verification and by an official tool from the Ministry of the Interior to validate communications. Even if this is not cybersecurity regulation in the strict sectoral sense, it does show an institutional response aimed at reducing the social engineering attack surface around a utility.

Countries and most affected subsegments

Mexico

Mexico recorded the incident with the highest visible impact on users during the period. The outage in the southeast drew attention because of the number of customers involved, the geographic reach, and public debate over vandalism or sabotage. The available reporting does not support placing that case in confirmed cybersecurity territory, but it does frame it as a high-impact operational crisis for the power sector.

For utility readers, the key point is not just the size of the outage. It is also how the cause became a matter of public dispute. When an interruption affects four states, the narrative around origin and responsibility matters almost as much as restoring service, because it shapes which controls, monitoring measures and communications are activated next.

Brazil

Brazil had the highest density of preventive and regulatory developments. Guardião Cibernético 8.0 brought together energy, water, telecom and defense agencies, and the nuclear sector was explicitly presented as a central training participant. ANEEL joined Sisbin, and ANSN opened a public consultation on nuclear cybersecurity. That mix of exercise, coordination and intelligence suggests stronger institutional maturity than in other Latin American markets in this vertical.

The nuclear subsegment warrants a separate reading. That is true not only because of ANSN and CNEN participation, but also because the exercise included scenarios involving a land-based plant, a hospital, a laboratory and a vessel carrying nuclear material. That places cybersecurity in a hybrid space with physical security, logistics and service continuity. For any critical infrastructure operator, the signal is that planning must already account for cross-dependencies, not just isolated assets.

Cuba

Cuba saw the most severe event for service continuity, with the total collapse of the national power grid. Recovery was partial and slow, with hospitals and essential facilities prioritized and blackouts continuing because of generation shortfalls. The material does not attribute the event to a cyberattack, but it does describe it as a transmission failure with nationwide impact.

From a vertical perspective, Cuba represents the point where the line between an energy crisis and critical infrastructure resilience becomes blurred. A power system that collapses fully or partially forces a reassessment of communication, monitoring and response dependencies. Even without digital attribution, the regional risk reading remains high because it exposes the grid's operational fragility.

Argentina

Argentina contributed a major urban case with the outage in Buenos Aires and about 600,000 customers affected. The cited source pointed to a failure in a system external to the distributor, shifting the analysis toward dependence on shared infrastructure and the need for coordinated continuity among actors. The material shows no evidence of intrusion or a cyber component.

For the distribution subsegment, the case underlines that external systems and operational interconnection can amplify impact even when there is no malicious cause. That puts failover exercises, contingency plans and visibility over suppliers and components that the corporate security team may not always see back at the center.

Venezuela

Venezuela experienced a severe fluctuation in the National Electric System, with voltage drops in Caracas and several states. The material does not provide a closed technical attribution, but it does show a pattern of instability that affects continuity and complicates any causal analysis. In this kind of context, security and operations become tightly linked.

The most prudent reading is to treat the case as an indicator of system fragility and ongoing exposure, not as a cyber incident. Still, from the perspective of a CISO or infrastructure director, the lesson is clear: in volatile supply environments, the ability to maintain visibility, redundancy and prioritization of critical loads is part of the security risk.

Uruguay

Uruguay showed the clearest fraud pattern aimed at a utility. The impersonation of UTE to capture WhatsApp codes affected customer relations and public support more than the power grid. Even so, because it exploits corporate identity, the company becomes central to the problem even if the attack is social rather than technical.

The country also added a more mature discussion of cybercrime overall, with rising complaint figures and the V CIER Symposium on Networks and Smart Cities including cybersecurity in digital power grids and critical infrastructure protection. That suggests the local ecosystem is trying to connect everyday fraud with the broader resilience agenda for the sector.

The most visible change from the previous month was the sharp drop in ransomware as the dominant theme, from 21 of 52 incidents in the prior month to just 1 of 66 in September. That should not be read as a structural improvement. It points instead to a shift in the available material, where operational continuity, institutional coordination, and disruption events weighed more than confirmed encryption campaigns.

At the same time, the number of unclassified incidents rose from 15 to 23. That increase is not minor. It suggests there are more events affecting the sector that do not reach a closed forensic classification, either because the source does not provide enough evidence or because the event does not fit neatly into the usual categories. For sector intelligence, that means more caution and no assumption that limited visibility equals limited risk.

Documented fraud or phishing cases also increased, from 1 to 2. Even though the absolute number remains low, this type of case is highly sensitive because it exploits utility brands and messaging channels that customers use heavily. This vector deserves attention because it can scale quickly without requiring complex technical exploitation. If a spoofing attempt gains credibility, the reputational impact can grow before any internal alarm does.

Regulatory moves fell slightly, from 3 to 2, but their substance was more meaningful than a procedural formality. ANSN's public consultation and ANEEL's addition to Sisbin point to a more integrated governance model. In other words, there are fewer announcements but more institutional depth, especially in Brazil.

The other signal to watch is the persistence of large-scale power continuity events. Mexico, Cuba, Argentina, and Venezuela show that the vertical remains exposed to disruptions that may have different causes but similar impacts on essential services. For security teams, that means the conversation can no longer stop at the digital perimeter.

Recommendations for security teams

First, separate three classes of events in playbooks: service disruptions, confirmed exfiltration, and mention on a leak site or attribution by third parties. September’s material showed several gray areas, especially at Ecopetrol and in outages in southeastern Mexico. If the team does not classify events correctly from the start, it risks overreacting to noise or underestimating a real intrusion.

Second, strengthen coordination among security, operations, and communications when an outage could be confused with sabotage or a cyber incident. In Mexico, public debate over vandalism and sabotage grew almost in step with the blackout. That requires consistent messaging, spokesperson protocols, and traceability of the technical hypothesis to prevent a provisional cause from becoming the official narrative without support.

Third, review identity verification mechanisms in customer service and support channels. The fraud that used the UTE brand shows that a utility can be abused as a trust anchor even when its systems have not been technically compromised. Staff should be trained not to request or validate codes through unauthorized channels, and simple verification procedures should be published for users.

Fourth, treat interagency exercises as real operational input, not as ceremony. Guardião Cibernético 8.0 left useful signals on coordination across energy, water, telecom, defense, and regulators. Regional teams can use that reference to test cross-dependencies, escalation, recovery, and communications in scenarios that mix IT, OT, and business continuity.

Fifth, keep monitoring OT vulnerabilities and ICS advisories even if the month did not bring a long chain of public exploitation. The material does mention CVEs and an advisory about mySCADA myPRO Manager, and in critical infrastructure, environments with weak authentication or poorly protected privileged functions deserve quick review. The priority is to assess local exposure, not wait for the vulnerability to appear tied to a press incident.

Sixth, build unstable supply scenarios into security planning. Cuba and Venezuela show that a network outage or severe fluctuation can affect monitoring, backups, communications, and recovery. For utilities and critical operators, that means checking power autonomy, contingency routes, telecom backup, and prioritization of essential assets.

Frequently Asked Questions

What changed between September and the previous month in the risk signal for the sector?

The visible pattern changed the most. In September, ransomware lost ground as the primary focus, while unclassified incidents increased, along with operational continuity events and resilience exercises, especially in Brazil. The contrast with the previous month is covered in the Trends and signals to monitor section.

Was there a confirmed cyberattack behind the month’s largest blackouts?

Not in the material reviewed. The outage in southeastern Mexico was linked to vandalism or intentional damage, but there was no cyber confirmation, and Cuba’s collapse was attributed to a transmission failure. Country-by-country detail is in Relevant incidents, and the comparative view is in Countries and subsegments most affected.

What was the strongest fraud signal for utilities?

The impersonation of UTE officials in Uruguay. Police and local media described a scheme to capture WhatsApp codes and then request money from the victim’s contacts. That case connects the Threats and active campaigns section with Countries and subsegments most affected and Recommendations for security teams.

What does Brazil add that other countries did not this month?

It adds the highest level of institutional coordination. ANSN, CNEN, ANEEL, ANA, and the Ministry of Defense converged in Guardião Cibernético 8.0, while ANEEL joined Sisbin and ANSN opened a public consultation on nuclear cybersecurity. The mix of exercises, regulation, and intelligence is analyzed in Regulation and compliance and in Relevant incidents.

Does the mention of two critical CVEs mean there was a wave of exploitation in the region?

Not necessarily. The indicator shows that two critical CVEs were mentioned in the material, but that is not enough to claim a regional exploitation wave or to tie them to a specific incident. In addition, the available material does not allow either case to be developed in technical detail. That is explained in Critical vulnerabilities and in Material limitations.

Material limitations

This report was built exclusively from the material provided for September 2026 and the two prior-month items that reached the archive only as comparative context. The time window for the indicators is limited to 66 dated items from September 2026, plus 2 prior-month items used only for month-over-month contrast. No external sources were added.

A zero indicator, or a lack of technical detail, does not mean the event did not exist in the region. In particular, if a CVE indicator were zero, that would only mean none were recorded in the material reviewed, not that there were no critical vulnerabilities exploited in Latin America. This month the critical CVE indicator was not zero, but the material did not allow for a full exploitation breakdown.

The coverage excluded aggregate telemetry as background signal, and it did not treat attempts, blocks, or automated scans as confirmed incidents. Consumer social media and sponsored or commercial content that is not among the available sources for citation were also left out. When there were allegations of a leak site, data sale, or third-party attribution without corporate or forensic confirmation, they were treated as allegations, not as closed breaches.

Finally, several notes from the period mix operational continuity, energy crisis, alleged sabotage, fraud, and cybersecurity without offering a single causal line. In those cases, the report prioritized the category the material could actually support. If the source did not confirm a cyber component, the event was not artificially elevated to a cybersecurity incident.

Sources