Bolivia: cybersecurity landscape, July 2026
Bolivia logged 20 extortion cases, 15 fraud cases, and 13 regulatory actions. SEPREC remained the month’s clearest incident.
Key findings
- SEPREC was the month’s strongest incident, with consistent attribution to Krybit and evidence of exfiltration and extortion pressure.
- Digital fraud dominated public discussion, with fake apps, identity theft, WhatsApp, and mobile banking as recurring vectors.
- Bolivia moved from 1 to 15 documented fraud or phishing incidents compared with the previous month.
- Regulatory actions rose to 13 and centered the agenda on USDT, a flexible exchange rate, invoicing, and financial traceability.
- Bolivia’s CGII issued an alert for a Redis PoC, the only critical CVE mentioned in the July material.
- The dominant threat shifted to uncategorized, reflecting thematic dispersion and several incomplete classifications.
- The public sector, telecommunications, health, and finance concentrated the most relevant signal in the period.
Monthly reference modules
These modules are automatically completed with the verified dated facts within the period. Each one states its basis and counting criterion, so the figures reconcile across modules. They are the recurring month-to-month reading, and the later analysis develops the cases without repeating this summary.
Indicator window: 92 dated facts in July 2026 · 4 from previous months (comparative frame, not monthly volume). Facts from previous months are used only as a comparative frame in the analysis, never as volume for this period.
Monthly executive summary for Bolivia
July gave Bolivia a clear dual front. On one side, the SEPREC case, attributed to the Krybit group, was the clearest sign of ransomware and extortion in the period, with consistent indicators of data exfiltration and publication on leak sites. On the other, digital fraud became far more visible than in previous months, with a sustained campaign against mobile users, fake apps, identity spoofing, and fund diversion through mobile banking.
The period’s indicators show 92 verified incidents, with 17 unclassified incidents and 20 cases in which ransomware or extortion was the primary focus. Within that group are three cases with confirmed encryption, three involving exfiltration without encryption, six where only the victim appeared on a leak site, and eight where the material does not allow the exact operational impact to be determined. That mix explains why the month’s leading threat category ended up as unclassified, with 25 of 92 incidents.
The other major shift was in the regulatory layer. Bolivia moved forward with 13 documented developments, including the discussion over bringing USDT into the payment system, the consolidation of the flexible exchange-rate regime, and new invoicing rules tied to the official exchange rate. Measures and statements also continued to appear on access to public information, money laundering, and institutional security controls, suggesting a month with significant rulemaking activity around payments, traceability, and state oversight.
On the technical front, the only critical CVE mentioned was the Redis vulnerability family that prompted a CGII de Bolivia advisory. The event does not describe mass exploitation in the country, but it does confirm that the national response team received and distributed alerts about an attack surface with a circulating PoC. In terms of source maturity, 67 percent of the incidents had direct source confirmation, a reasonable level to support operational analysis, although a relevant tail of reports or publications remains unverified.
Bolivia monthly threat overview
Bolivia's qualitative risk reading for July is medium. The volume of events is high, but not all of that volume carries the same operational weight. Most of the useful signal is concentrated in digital fraud, extortion and regulation, while incidents with confirmed technical impact are fewer and much more contained. Even so, the SEPREC case, the circulation of a PoC for Redis and the continued mobile scam campaigns show that the real attack surface remained active and able to cause concrete harm.
The predominance of unclassified events also deserves careful reading. It does not mean there was no risk, but rather that the available material mixed market news, alerts, dark web posts, regulatory notes and police reports with different levels of verification. In practice, that leaves July as a month in which public conversation about cybersecurity was intense, but technical attribution in several cases remained incomplete.
Compared with the region, Bolivia did not show an isolated profile. Fraud campaigns involving fake apps, messaging and credential theft fit a trend seen in other Latin American countries, where mobile and digital banking remain the most profitable entry vector for opportunistic actors. At the same time, the regulatory debate on digital assets and financial traceability reflects a broader regional agenda, although in Bolivia it appeared tied to the dollar shortage, the exchange-rate regime and the search for formal payment mechanisms.
Bolivia period indicators
| Indicator | Value | Note |
|---|---|---|
| Verified facts in the period | 92 | Base for all indicators, only facts dated within July 2026 |
| Indicator time window | 92 facts dated in July 2026 · 4 from earlier months (comparative frame, not monthly volume) | Comparative frame, not monthly volume |
| Unclassified incidents (breaches or outages) | 17 | Facts with impact not classified in the source material |
| Cases with ransomware or extortion as the primary focus | 20 | Exclusive primary-focus category, does not add up subtypes |
| Confirmed asset encryption | 3 | Ransomware breakdown by impact type |
| Exfiltration without encryption (simple extortion) | 3 | Ransomware breakdown by impact type |
| Mention on leak site only | 6 | Ransomware breakdown by impact type |
| Type could not be determined from the material | 8 | Ransomware breakdown by impact type |
| Documented fraud or phishing cases | 15 | Digital fraud, phishing, and impersonation campaigns and reports |
| Documented regulatory moves | 13 | Regulatory changes, technical assessments, and public measures |
| Critical CVEs mentioned | 1 | Critical CVE mentioned in the material analyzed this month |
| Sectors with at least one documented fact | 7 | One fact can affect more than one sector |
| Dominant threat of the month | Unclassified (25 of 92 facts) | Most frequent category in the period |
| Facts with direct source confirmation | 67% | Direct confirmation across the total verified facts |
Relevant incidents in Bolivia
SEPREC and the Krybit case
The strongest episode of the month was SEPREC, the Plurinational Service of Business Registry. Ransomware.live, Galaxy Warden, HookPhish and Darkfield all identified the agency as a Krybit victim on 7 July. DExpose and other analyses added the threat component on the leak site, while Galaxy Warden detailed that internal files were exfiltrated, including company records, owner identities, addresses and corporate documentation. The material does not confirm system encryption, but it does make clear that there was a leak and extortion pressure.
The significance of the case is not only the affected entity. SEPREC holds data of legal and economic value, so an exfiltration can affect both the agency and natural and legal persons that have processed commercial acts. That exposure makes the incident especially sensitive for the public sector and for the business registry and compliance ecosystem.
Digital scam campaign against mobile users
ATT reported that between 1 January and 17 July 2026, the Bloquea la Estafa platform received 16,821 complaints about alleged digital scams, with 13,516 IMEIs blocked and 10,846 lines cut off. That figure should not be read as attack telemetry, but as the volume of complaints and administrative measures. At the same time, FELCC and several media outlets described a consistent pattern of fake apps, sponsored links and trojans that end up accessing mobile banking and credentials.
The material also provides two operational signals. First, the campaign moved with considerable success on Facebook through deceptive advertising. Second, the fraud was not limited to apps, because in Cochabamba a WhatsApp-based variant appeared with fake Transit fines. The combination suggests an adaptable operation, with a low barrier to entry and the ability to keep monetizing through multiple channels.
BGP and the brief route control disruption
Telecom Observer recorded a brief interruption in Bolivia's BGP control plane on 16 July, with route visibility degradation between 17:45 and 18:25 UTC. No public cause or specific operator was identified. The episode is not classified as an intrusion, but as a sign of infrastructure instability that warrants close monitoring because of its potential impact on availability and network observability.
Defacement against a Bolivian state site
Kalir.io reported on 13 July the detection of a defacement on a Bolivian state website attributed to TurkHackTeam. The available material does not allow for much more, since it does not detail the vector, persistence or internal scope. Even so, it adds to the picture of exposed public-facing infrastructure and opportunistic activity against government portals.
Threats and active campaigns in Bolivia
Ransomware and extortion, with shades of impact
In ransomware and extortion, July was not a uniform month. The SEPREC case fits exfiltration with extortion pressure and publication on a leak site. The material on Krybit also describes the group as ransomware-as-a-service with double extortion, Tor-based negotiation and data leakage, and support for multiple platforms. However, in the specific Bolivian case there is no evidence in the material of confirmed asset encryption, so it should be treated as exfiltration with an extortion threat, not as proven encryption.
Another set of incidents fell into the category of being mentioned only on a leak site. That includes references to listed victims, but without enough detail to confirm operational harm. There is also a separate block where the source does not specify whether encryption occurred, which leaves the classification open. That distinction matters, because not every ransomware claim has the same impact on continuity, recovery, or legal exposure.
SEPREC, Krybit and confirmed exfiltration
The technical profile of Krybit published by OT Security Wire and Malware News helps explain the risk in the Bolivian case. The group uses AES-256, RSA-4096, deletes shadow copies with vssadmin, and leaves ransom notes with the .KRYBIT extension. It also operates over Tor and runs a double extortion model. In SEPREC, the most relevant point in the material is the exfiltration of internal files with commercial and administrative data, plus the explicit threat of publication.
Fraud, phishing and identity theft
The digital fraud campaign was probably the most visible signal for everyday users. Urgente.bo reported free applications with computer viruses, Vision360 detailed seven recent cases, La Patria described trojans spread through deceptive advertising, and Red Uno added the use of fake fines via WhatsApp. The pattern is clear, because it combines social engineering, abuse of sponsored distribution, and credential theft, with a focus on mobile banking.
The televised report on the theft of 8.000 bolivianos through computer manipulation fits the same vector. In that case, the attacker installed a trojan that enabled remote access to the banking app. This was not an isolated case, but a concrete example of how a digital scam ends in direct financial fraud.
APT or hacktivism
Based on the available material, there is no sustained APT campaign attributed to a state or proxy actor in Bolivia during July. There was a defacement attributed to TurkHackTeam, which fits opportunistic hacktivism better than persistent intrusion. There were also interpretations involving disinformation and fake content, but that is not enough to classify it as an APT operation.
Critical vulnerabilities affecting Bolivia
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| CVE-2026-25243 | Redis OSS/CE, Redis Software, Redis Cloud, RedisTimeSeries and RedisBloom | Bolivia's CGII issued an alert over circulating PoC material, with risk of memory corruption and RCE through RESTORE; the material does not confirm active exploitation in Bolivia | CGII de Bolivia, CyberPress, The Hacker News, Rescana |
| CVE-2026-25588 | Redis OSS/CE, Redis Software, Redis Cloud | Bolivia's CGII issued an alert over circulating PoC material; exploitation is possible with an authenticated account and RESTORE commands or replication scenarios | CGII de Bolivia |
| CVE-2026-25589 | RedisBloom | Bolivia's CGII issued an alert and external technical analysis describes it as a heap-based buffer overflow; the material suggests functional PoCs but no confirmed exploitation in the country | CGII de Bolivia, CyberPress, Stingrai |
| CVE-2026-23479 | Redis OSS/CE, Redis Software | Use-after-free in handling waiting clients and in master-replica processes; Bolivia's CGII classified it as high risk | CGII de Bolivia |
| CVE-2026-23631 | Redis OSS/CE, Redis Software | Use-after-free tied to master-replica synchronization and Lua scripts; Bolivia's CGII warned of possible RCE with an authenticated account | CGII de Bolivia |
July's material gives a very clear picture of Redis. PoCs are circulating, Bolivia's CGII issued a formal alert, and outside technical sources say some initial fixes did not fully close the attack surface. That does not mean Bolivia saw confirmed widespread exploitation, but it does mean exposed Redis services without hardening remain a plausible risk.
Regulation and compliance in Bolivia
Regulation was one of the month’s most active fronts. The government evaluated the possible integration of USDT into the payment system, amid a dollar shortage and a strategy to bring digital assets into the formal banking system. There are still no implementation rules, launch date, provider selection, or declaration of legal tender. This is a technical review stage, not a finalized policy.
The flexible exchange rate regime kept consolidating, with a direct impact on financial and tax operations. Central Bank Resolution 88/2026 and Ministerial Resolution 245/2026 opened the new framework, and the SIN later adjusted invoicing to record the official exchange rate in foreign currency operations. At the same time, the regulatory framework for payroll deductions in the public sector was reorganized through Supreme Decree 5654, with narrower rules and express authorization for voluntary contributions.
There was also movement on access to public information. The Senate approved a bill in general terms, although journalist organizations warned of risks due to the lack of broad public participation. This matters for cybersecurity because greater state transparency is usually accompanied by new obligations for document management, traceability, and data handling.
Another regulatory focus was the national priority against money laundering, aimed at complying with the FATF and exiting the gray list. The material also recalls the enactment of Law 1741 to authorize undercover agents and controlled deliveries in investigations into laundering of illicit gains and terrorist financing. That context helps explain why the discussion about USDT, payments, and financial traceability surfaced so strongly in July.
Most affected sectors in Bolivia
The public sector again sat at the center of the monthly signal. SEPREC holds the clearest extortion case with exfiltration, and the report also picked up references to a defaced state site, regulatory discussions, and agencies that had to respond publicly to security alerts. That does not mean the state was the only affected sector, but it was the most visible in the highest-impact editorial events.
The second most exposed block was telecommunications and connectivity, not because of large-scale attacks but because of a brief BGP disruption and the role of the mobile network in digital scams. The ATT, the FELCC, and the messaging incidents themselves show that the communications layer is critical both for operations and for fraud monetization.
Public health appeared through the alleged leak of the SSSRO system from the Ministry of Health and Sports. That case has not been independently verified, so it should be read with caution. Even so, it points to a type of exposure that in Bolivia is no longer limited to commercial or financial data, but also reaches sensitive personal information tied to health services and training.
Finance and commerce, finally, were affected by several different events. There was mobile banking fraud, debate over USDT, exchange-rate changes, and the SEPREC incident. The combined signal suggests pressure on financial digitization and on the records that support economic formality.
Trends and signals to watch in Bolivia
The month-over-month comparison shows several clear shifts. The most visible was the jump in documented fraud or phishing, from 1 incident in the previous month to 15 in July, an increase of 14. That does not by itself prove a structural deterioration, but it does point to greater public visibility, more reporting, and better identification of impersonation campaigns and mobile trojans.
Regulatory activity also increased, from 9 to 13, with four additional incidents. In Bolivia, that change is not minor, because the agenda around payments, exchange rates, access to information, and financial oversight intersected with practical cybersecurity. The debate over USDT and the official exchange rate widened the area of interest for banks, fintechs, retailers, and compliance teams.
On the technical front, the critical CVEs mentioned went from 0 to 1. Again, that does not mean critical vulnerabilities did not exist in the region before, only that the July material included a specific family with an official Bolivian advisory. The presence of the CGII in that advisory is a useful data point, because it shows the institutional response is monitoring PoC and publishing mitigation recommendations.
The dominant threat shifted from ransomware to unclassified. That likely reflects greater topic diversity rather than improvement. In June, according to the available comparison, ransomware accounted for 13 incidents. In July, the material split across extortion, fraud, regulation, disinformation, infrastructure, and context notes, diluting the dominant theme without reducing the seriousness of the clearest cases.
Security guidance for teams in Bolivia
First, harden any exposed Redis deployment, especially if it uses modules such as RedisTimeSeries or RedisBloom. The CGII warning in Bolivia makes it clear that public exposure and use of RESTORE increase the risk. It is worth reviewing versions, restricting network access, limiting authenticated accounts with restore privileges, and checking whether replication is configured in ways that reduce read-only protection.
Second, treat mobile fraud as an operational threat, not just an end-user problem. This month’s campaigns combine fake apps, sponsored links, WhatsApp messages, and credential theft. Security teams in banking, telecom, and customer support should align blocking, verification, and session revocation messages with simple playbooks, because response speed matters more than retrospective analysis.
Third, review the exposure of public portals and services, especially those containing commerce, health, or citizen-service records. SEPREC showed that extortion can combine data leakage, public pressure, and reputational risk. In that type of case, the priority is not only containment, but also preserving evidence, defining messaging, and confirming whether sensitive data was accessed.
Fourth, strengthen BGP monitoring and connectivity health checks. There was no public attribution for the July event, but route visibility dropped during a brief interval and that justifies observation and escalation rules. Business continuity does not depend only on keeping the service online, but on keeping it routable, observable, and recoverable.
Fifth, maintain coordination among security, legal, and compliance teams on everything related to digital payments and virtual assets. The review of USDT, the new exchange scheme, and invoicing requirements can create process gaps if they are not quickly translated into controls, contracts, claims handling, and transaction traceability.
Material limitations
This report covers only facts dated in July 2026 within the material provided. The four facts from earlier months included as a comparison frame are used only for month-over-month trend analysis and are not part of the period total. No internet was used, and no source outside the authorized list was incorporated.
A zero indicator, especially for critical CVEs, does not mean there were no serious vulnerabilities or exploitation in the region. It means only that none were recorded in this month’s analyzed material. The same applies to any category not observed in the indicators: absence in the document set does not equal real absence in Bolivia.
The 67 percent figure for direct confirmation describes the quality of support for the verified facts, not the full extent of real-world risk. There are also complaints, forum claims, and dark web notes that appear as unverified or are attributed with caution. When a source could not independently corroborate a fact, the text treats it as such.
Consumer social media and sponsored or commercial consumer posts that were not among the permitted sources were excluded from the basis of this report. Aggregated telemetry, such as incidents, blocked attempts, or scans, was also not used as if it were intrusion data. Infrastructure signals and regulatory facts are interpreted as operational context, not as proof of additional attacks.
Technical annex: indicators of compromise and TTPs
The Krybit group, according to OT Security Wire, Malware News and Cyware, operates with a technical chain tied to double extortion, use of Tor for command and control, data transfer and negotiation, deletion of shadow copies with vssadmin.exe delete shadows /all /quiet, and impact on Windows, Linux, VMware ESXi and NAS environments. Its affiliate panels mention typical exfiltration volumes of 10 to 250 GB per victim.
The technical sources also link Krybit to MITRE ATT&CK T1490, T1071, T1105, T1041, T1078 and T1059. In the Bolivian case, these TTPs help frame the threat against SEPREC, although they do not replace local forensic evidence on the exact intrusion, persistence or exfiltration.
Sources
- Kimi K3 AI Agent Finds Redis RCE Vulnerabilities in Just 27 MinutesCyberPress
- Aviso de seguridad: Circulación de pruebas de concepto para el lote de vulnerabilidades que afecta a servidores RedisCentro de Gestión de la Información e Informática (CGII) - Gobierno de Bolivia
- nuevos exploits vuelven a vulnerar la seguridad de RedisSecurityLab
- Kimi K3 Agents Found Redis Zero-Days and Built RCE ...The Hacker News
- Vulnerabilidades Zero-Day Críticas en Redis Permiten Ejecución Remota de CódigoIngeniería Telemática
- Critical Redis Vulnerability CVE-2024-27348 Enables Remote Code Execution via RESTORE Command: Risk Analysis and Mitigation StrategiesRescana
- Redis RCE 2026: Five Patched CVEs and an AI DiscoveryStingrai
- Боливия рассматривает интеграцию USDT в национальную платёжную систему на фоне дефицита долларовCoinalert News
- La Bolivie envisage d’ajouter l’USDT au système national de paiementLider Media
- Gobierno de Bolivia analiza la integración de USDT en el sistema de pagos nacionalCointelegraph en Español
- USDT considerado para pagos nacionales en BoliviaBitget News
- Noticias – Monitoreo de encargados de datos por la ANPDCiberLATAM
- Bolivia registra 16.821 denuncias de fraude digital en 2026La Patria
- Aplicaciones falsas y suplantación de identidad: así operan las ciberestafas en BoliviaUrgente.bo
- Sophos 2026: deepfakes y robo de identidades impulsan ciberataquesITSeller Bolivia
- seprec.gob.bo Listed by krybit Ransomware GroupGalaxy Warden
- Krybit Ransomware Strikes Bolivia's SEPRECDExpose
- seprec.gob.bo data breach — Krybit ransomware leak (2026)Darkfield (Orizon)
- Victim: seprec.gob.bo - Ransomware.liveRansomware.live
- Ransomware Group krybit Hits: seprec.gob.bo - HookPhishHookPhish
- Bolivia: supuesta filtración expone 41.406 registros de internos de salud ruralDiarioBitcoin
- Bolivia reafirma en Cusco su estrategia de seguridad: soberanía, cooperación y combate al crimen organizadoRed Uno
- KrybitDigitalChk
- Bolivia's Ministry of Health SSSRO Database Allegedly Leaked, 41,406 Records on Rural Health Interns PublishedDark Web Informer
- FELCC alerta por siete casos de estafa digital y recomienda descargar aplicaciones solo de sitios autorizadosVision360
- SIGUEN SUMANDO A CADA DÍA LAS VÍCTIMAS DE ESTAFAS POR DESCARGAS DE APLICACIONESYouTube
- Alerta en Cochabamba: Detectan nueva modalidad de estafa digital por WhatsApp usando falsas multas de TránsitoRed Uno
- Sucre: Policía alerta aumento de estafas en las redes socialeseju.tv
- Dark Web Profile: Krybit RansomwareMalware News
- Cyware Daily Threat Intelligence - July 13, 2026Cyware
- Alerta por robos a través de aplicaciones de fútbol y k-dramasLa Patria
- INVESTIGAN ROBO DE BS 8.000 MEDIANTE MANIPULACIÓN INFORMÁTICAYouTube
- Bolivia Experiences Brief BGP Control Plane DisruptionTelecom Observer
- Aprehenden a joven por presunta estafa en compra de criptomonedasLa Patria
- Presunto hackeador transfiere dinero de cuentas personaleseju.tv
- Terrorismo digitalEl Día
- Bolivia's AI Bill Gives AGETIC Real Teeth | TLYThe Leveraged Years
- Bolivian journalists sound alarm over new information access bill approved without public inputLatAm Journalism Review
- Senado aprueba en grande ley de acceso a la información públicaLa Patria
- Un tutor con 67 niños a cargo: la denuncia que sustenta el registro de bonosEl Post
- Magisterio urbano se declara en “estado de alerta” por Examen de Ascenso y exigen que sea de forma automáticaEju.tv
- Sorteo público asigna plazas para el servicio rural obligatorioLa Patria
- Bolivian State Website Defaced by TurkHackTeamKalir.io
- Bloquean más de 13 mil celulares y cortan 10 mil líneas vinculadas a estafas digitales en BoliviaAhoradigital
- Notas de Prensa - mindefMinisterio de Defensa de Bolivia
- Boletín estadístico de Precios Internacionales junio de 2026 - INEInstituto Nacional de Estadística de Bolivia
- El Gobierno declara prioridad nacional la lucha contra el lavado de dinero para cumplir con el GAFI y salir de la lista griseju.tv
- Cinco nuevos decretos: estas son las medidas que impactarán la economía y los servicios en BoliviaRed Uno
- Artículos escritos en 2026 julioBolivia Legal
- Publicaciones de julio 2026Tribunal Constitucional Plurinacional
- Tax Bulletin July 2026PPO Indacochea
- Régimen cambiario flexible y pago de tributos aduanerosLos Tiempos
- Instituciones exigen aplicar la regulación antisísmica en construccioneseju.tv
- Recomendaciones de viaje a BoliviaMinisterio de Asuntos Exteriores de España
- DS 5647 no autoriza aumentos en tarifas eléctricas, afirma la AETNLa Patria
- ¿Qué establece el Decreto 5654? Estos son los descuentos que seguirán por planillaRed Uno
- Bolivia adopts a Flexible Exchange Rate RegimeDentons
- Tipo de cambio flexible y seguridad jurídica: una exigencia constitucional en tiempos de incertidumbre económicaeju.tv
- Tipo de cambio flexible en BoliviaRatio Legis
