CiberLATAMbywhalemate
Intelligence reportAug 1, 202618 min read

Bolivia: cybersecurity landscape, July 2026

Bolivia logged 20 extortion cases, 15 fraud cases, and 13 regulatory actions. SEPREC remained the month’s clearest incident.

Bolivia: cybersecurity landscape, July 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are automatically completed with the verified dated facts within the period. Each one states its basis and counting criterion, so the figures reconcile across modules. They are the recurring month-to-month reading, and the later analysis develops the cases without repeating this summary.

Indicator window: 92 dated facts in July 2026 · 4 from previous months (comparative frame, not monthly volume). Facts from previous months are used only as a comparative frame in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Verified Signal Monthly Dashboard July 2026 · Bolivia Predominant threat: Unclassified (25 of 92 events). Coverage: 92 dated events in July 2026 · 4 of prior months… VERIFIED EVENTS 92 period base: all counts measured from the bottom on this total RANSOMWARE / EXTORTION 20 3 encrypted assets confirmed · 3 exfiltration no encryption (simple extortion) UNCLASSIFIED INCIDENTS 17 breaches or outages without declared threat type FRAUD / PHISHING 15 documented fraud campaigns REGULATION 13 rules, resolutions, or sanctions UNIQUE CVEs 1 CVE-2026-58644
Verified Signal Monthly Dashboard — Base: 92 verified dated events in the period for Bolivia.
MONTHLY FIXED MODULE Threat-axis distribution July 2026 · Bolivia Each incident is counted on only one axis, so the total is exactly 92. "Unclassified incidents" is the remainder. Unclassified 25 Ransomware 20 Incidents 17 Fraud 15 Regulation 13 Vulnerabilities 2
Threat-axis distribution — Each incident is assigned to one axis based on its classification; the total reconciles to the 92 incidents in the period.
MONTHLY FIXED MODULE Sectoral distribution of signals July 2026 · Bolivia Base: 92 events in the period · total 116 because 20 events are classified in more than one sector. Public sector / OIV 47 Others / sector unidentified… 26 Telecom 16 Health 11 Finance 7 Energy 5 Technology 3 Education 1
Sectoral distribution of signals — Heuristic sector classification by victim sector. One event may affect more than one sector, so the total may exceed the base.
MONTHLY FIXED MODULE Critical infrastructure in Bolivia July 2026 · Bolivia 23 of 92 facts in the period involve critical infrastructure. A fact may appear in more than one category. Public sector / government 45 Explicit critical infrastructure 2 Energy / utilities 1 Telecom / connectivity 12
Critical infrastructure in Bolivia — Verified facts on public sector, utilities, and essential services

Monthly executive summary for Bolivia

July gave Bolivia a clear dual front. On one side, the SEPREC case, attributed to the Krybit group, was the clearest sign of ransomware and extortion in the period, with consistent indicators of data exfiltration and publication on leak sites. On the other, digital fraud became far more visible than in previous months, with a sustained campaign against mobile users, fake apps, identity spoofing, and fund diversion through mobile banking.

The period’s indicators show 92 verified incidents, with 17 unclassified incidents and 20 cases in which ransomware or extortion was the primary focus. Within that group are three cases with confirmed encryption, three involving exfiltration without encryption, six where only the victim appeared on a leak site, and eight where the material does not allow the exact operational impact to be determined. That mix explains why the month’s leading threat category ended up as unclassified, with 25 of 92 incidents.

The other major shift was in the regulatory layer. Bolivia moved forward with 13 documented developments, including the discussion over bringing USDT into the payment system, the consolidation of the flexible exchange-rate regime, and new invoicing rules tied to the official exchange rate. Measures and statements also continued to appear on access to public information, money laundering, and institutional security controls, suggesting a month with significant rulemaking activity around payments, traceability, and state oversight.

On the technical front, the only critical CVE mentioned was the Redis vulnerability family that prompted a CGII de Bolivia advisory. The event does not describe mass exploitation in the country, but it does confirm that the national response team received and distributed alerts about an attack surface with a circulating PoC. In terms of source maturity, 67 percent of the incidents had direct source confirmation, a reasonable level to support operational analysis, although a relevant tail of reports or publications remains unverified.

Bolivia monthly threat overview

Bolivia's qualitative risk reading for July is medium. The volume of events is high, but not all of that volume carries the same operational weight. Most of the useful signal is concentrated in digital fraud, extortion and regulation, while incidents with confirmed technical impact are fewer and much more contained. Even so, the SEPREC case, the circulation of a PoC for Redis and the continued mobile scam campaigns show that the real attack surface remained active and able to cause concrete harm.

Bolivia, July 2026SEPRECKrybitBGPdisruptionFELCCfake appsUSDTunder reviewRedisCGII noticeMilestonesselected for theperiod, withoutattributingadditionalvolume.
Bolivia, July 2026, timeline of key events — Selected highlights from the month, focused on fraud, ransomware, regulation, and infrastructure.

The predominance of unclassified events also deserves careful reading. It does not mean there was no risk, but rather that the available material mixed market news, alerts, dark web posts, regulatory notes and police reports with different levels of verification. In practice, that leaves July as a month in which public conversation about cybersecurity was intense, but technical attribution in several cases remained incomplete.

Compared with the region, Bolivia did not show an isolated profile. Fraud campaigns involving fake apps, messaging and credential theft fit a trend seen in other Latin American countries, where mobile and digital banking remain the most profitable entry vector for opportunistic actors. At the same time, the regulatory debate on digital assets and financial traceability reflects a broader regional agenda, although in Bolivia it appeared tied to the dollar shortage, the exchange-rate regime and the search for formal payment mechanisms.

Bolivia period indicators

Indicator Value Note
Verified facts in the period 92 Base for all indicators, only facts dated within July 2026
Indicator time window 92 facts dated in July 2026 · 4 from earlier months (comparative frame, not monthly volume) Comparative frame, not monthly volume
Unclassified incidents (breaches or outages) 17 Facts with impact not classified in the source material
Cases with ransomware or extortion as the primary focus 20 Exclusive primary-focus category, does not add up subtypes
Confirmed asset encryption 3 Ransomware breakdown by impact type
Exfiltration without encryption (simple extortion) 3 Ransomware breakdown by impact type
Mention on leak site only 6 Ransomware breakdown by impact type
Type could not be determined from the material 8 Ransomware breakdown by impact type
Documented fraud or phishing cases 15 Digital fraud, phishing, and impersonation campaigns and reports
Documented regulatory moves 13 Regulatory changes, technical assessments, and public measures
Critical CVEs mentioned 1 Critical CVE mentioned in the material analyzed this month
Sectors with at least one documented fact 7 One fact can affect more than one sector
Dominant threat of the month Unclassified (25 of 92 facts) Most frequent category in the period
Facts with direct source confirmation 67% Direct confirmation across the total verified facts

Relevant incidents in Bolivia

SEPREC and the Krybit case

The strongest episode of the month was SEPREC, the Plurinational Service of Business Registry. Ransomware.live, Galaxy Warden, HookPhish and Darkfield all identified the agency as a Krybit victim on 7 July. DExpose and other analyses added the threat component on the leak site, while Galaxy Warden detailed that internal files were exfiltrated, including company records, owner identities, addresses and corporate documentation. The material does not confirm system encryption, but it does make clear that there was a leak and extortion pressure.

The significance of the case is not only the affected entity. SEPREC holds data of legal and economic value, so an exfiltration can affect both the agency and natural and legal persons that have processed commercial acts. That exposure makes the incident especially sensitive for the public sector and for the business registry and compliance ecosystem.

Digital scam campaign against mobile users

ATT reported that between 1 January and 17 July 2026, the Bloquea la Estafa platform received 16,821 complaints about alleged digital scams, with 13,516 IMEIs blocked and 10,846 lines cut off. That figure should not be read as attack telemetry, but as the volume of complaints and administrative measures. At the same time, FELCC and several media outlets described a consistent pattern of fake apps, sponsored links and trojans that end up accessing mobile banking and credentials.

The material also provides two operational signals. First, the campaign moved with considerable success on Facebook through deceptive advertising. Second, the fraud was not limited to apps, because in Cochabamba a WhatsApp-based variant appeared with fake Transit fines. The combination suggests an adaptable operation, with a low barrier to entry and the ability to keep monetizing through multiple channels.

BGP and the brief route control disruption

Telecom Observer recorded a brief interruption in Bolivia's BGP control plane on 16 July, with route visibility degradation between 17:45 and 18:25 UTC. No public cause or specific operator was identified. The episode is not classified as an intrusion, but as a sign of infrastructure instability that warrants close monitoring because of its potential impact on availability and network observability.

Defacement against a Bolivian state site

Kalir.io reported on 13 July the detection of a defacement on a Bolivian state website attributed to TurkHackTeam. The available material does not allow for much more, since it does not detail the vector, persistence or internal scope. Even so, it adds to the picture of exposed public-facing infrastructure and opportunistic activity against government portals.

Threats and active campaigns in Bolivia

Ransomware and extortion, with shades of impact

In ransomware and extortion, July was not a uniform month. The SEPREC case fits exfiltration with extortion pressure and publication on a leak site. The material on Krybit also describes the group as ransomware-as-a-service with double extortion, Tor-based negotiation and data leakage, and support for multiple platforms. However, in the specific Bolivian case there is no evidence in the material of confirmed asset encryption, so it should be treated as exfiltration with an extortion threat, not as proven encryption.

Another set of incidents fell into the category of being mentioned only on a leak site. That includes references to listed victims, but without enough detail to confirm operational harm. There is also a separate block where the source does not specify whether encryption occurred, which leaves the classification open. That distinction matters, because not every ransomware claim has the same impact on continuity, recovery, or legal exposure.

SEPREC, Krybit and confirmed exfiltration

The technical profile of Krybit published by OT Security Wire and Malware News helps explain the risk in the Bolivian case. The group uses AES-256, RSA-4096, deletes shadow copies with vssadmin, and leaves ransom notes with the .KRYBIT extension. It also operates over Tor and runs a double extortion model. In SEPREC, the most relevant point in the material is the exfiltration of internal files with commercial and administrative data, plus the explicit threat of publication.

Fraud, phishing and identity theft

The digital fraud campaign was probably the most visible signal for everyday users. Urgente.bo reported free applications with computer viruses, Vision360 detailed seven recent cases, La Patria described trojans spread through deceptive advertising, and Red Uno added the use of fake fines via WhatsApp. The pattern is clear, because it combines social engineering, abuse of sponsored distribution, and credential theft, with a focus on mobile banking.

Bolivia, July 2026, documented alertsFraud or phishing15Regulation13Ransomware20Critical CVEs1
Bolivia, July 2026, fraud and phishing alerts — Visual comparison of the documentary weight of fraud versus other categories for the month.

The televised report on the theft of 8.000 bolivianos through computer manipulation fits the same vector. In that case, the attacker installed a trojan that enabled remote access to the banking app. This was not an isolated case, but a concrete example of how a digital scam ends in direct financial fraud.

APT or hacktivism

Based on the available material, there is no sustained APT campaign attributed to a state or proxy actor in Bolivia during July. There was a defacement attributed to TurkHackTeam, which fits opportunistic hacktivism better than persistent intrusion. There were also interpretations involving disinformation and fake content, but that is not enough to classify it as an APT operation.

Critical vulnerabilities affecting Bolivia

CVE Software Exploitation Source
CVE-2026-25243 Redis OSS/CE, Redis Software, Redis Cloud, RedisTimeSeries and RedisBloom Bolivia's CGII issued an alert over circulating PoC material, with risk of memory corruption and RCE through RESTORE; the material does not confirm active exploitation in Bolivia CGII de Bolivia, CyberPress, The Hacker News, Rescana
CVE-2026-25588 Redis OSS/CE, Redis Software, Redis Cloud Bolivia's CGII issued an alert over circulating PoC material; exploitation is possible with an authenticated account and RESTORE commands or replication scenarios CGII de Bolivia
CVE-2026-25589 RedisBloom Bolivia's CGII issued an alert and external technical analysis describes it as a heap-based buffer overflow; the material suggests functional PoCs but no confirmed exploitation in the country CGII de Bolivia, CyberPress, Stingrai
CVE-2026-23479 Redis OSS/CE, Redis Software Use-after-free in handling waiting clients and in master-replica processes; Bolivia's CGII classified it as high risk CGII de Bolivia
CVE-2026-23631 Redis OSS/CE, Redis Software Use-after-free tied to master-replica synchronization and Lua scripts; Bolivia's CGII warned of possible RCE with an authenticated account CGII de Bolivia

July's material gives a very clear picture of Redis. PoCs are circulating, Bolivia's CGII issued a formal alert, and outside technical sources say some initial fixes did not fully close the attack surface. That does not mean Bolivia saw confirmed widespread exploitation, but it does mean exposed Redis services without hardening remain a plausible risk.

Regulation and compliance in Bolivia

Regulation was one of the month’s most active fronts. The government evaluated the possible integration of USDT into the payment system, amid a dollar shortage and a strategy to bring digital assets into the formal banking system. There are still no implementation rules, launch date, provider selection, or declaration of legal tender. This is a technical review stage, not a finalized policy.

The flexible exchange rate regime kept consolidating, with a direct impact on financial and tax operations. Central Bank Resolution 88/2026 and Ministerial Resolution 245/2026 opened the new framework, and the SIN later adjusted invoicing to record the official exchange rate in foreign currency operations. At the same time, the regulatory framework for payroll deductions in the public sector was reorganized through Supreme Decree 5654, with narrower rules and express authorization for voluntary contributions.

There was also movement on access to public information. The Senate approved a bill in general terms, although journalist organizations warned of risks due to the lack of broad public participation. This matters for cybersecurity because greater state transparency is usually accompanied by new obligations for document management, traceability, and data handling.

Another regulatory focus was the national priority against money laundering, aimed at complying with the FATF and exiting the gray list. The material also recalls the enactment of Law 1741 to authorize undercover agents and controlled deliveries in investigations into laundering of illicit gains and terrorist financing. That context helps explain why the discussion about USDT, payments, and financial traceability surfaced so strongly in July.

Most affected sectors in Bolivia

The public sector again sat at the center of the monthly signal. SEPREC holds the clearest extortion case with exfiltration, and the report also picked up references to a defaced state site, regulatory discussions, and agencies that had to respond publicly to security alerts. That does not mean the state was the only affected sector, but it was the most visible in the highest-impact editorial events.

The second most exposed block was telecommunications and connectivity, not because of large-scale attacks but because of a brief BGP disruption and the role of the mobile network in digital scams. The ATT, the FELCC, and the messaging incidents themselves show that the communications layer is critical both for operations and for fraud monetization.

Public health appeared through the alleged leak of the SSSRO system from the Ministry of Health and Sports. That case has not been independently verified, so it should be read with caution. Even so, it points to a type of exposure that in Bolivia is no longer limited to commercial or financial data, but also reaches sensitive personal information tied to health services and training.

Finance and commerce, finally, were affected by several different events. There was mobile banking fraud, debate over USDT, exchange-rate changes, and the SEPREC incident. The combined signal suggests pressure on financial digitization and on the records that support economic formality.

The month-over-month comparison shows several clear shifts. The most visible was the jump in documented fraud or phishing, from 1 incident in the previous month to 15 in July, an increase of 14. That does not by itself prove a structural deterioration, but it does point to greater public visibility, more reporting, and better identification of impersonation campaigns and mobile trojans.

Regulatory activity also increased, from 9 to 13, with four additional incidents. In Bolivia, that change is not minor, because the agenda around payments, exchange rates, access to information, and financial oversight intersected with practical cybersecurity. The debate over USDT and the official exchange rate widened the area of interest for banks, fintechs, retailers, and compliance teams.

On the technical front, the critical CVEs mentioned went from 0 to 1. Again, that does not mean critical vulnerabilities did not exist in the region before, only that the July material included a specific family with an official Bolivian advisory. The presence of the CGII in that advisory is a useful data point, because it shows the institutional response is monitoring PoC and publishing mitigation recommendations.

The dominant threat shifted from ransomware to unclassified. That likely reflects greater topic diversity rather than improvement. In June, according to the available comparison, ransomware accounted for 13 incidents. In July, the material split across extortion, fraud, regulation, disinformation, infrastructure, and context notes, diluting the dominant theme without reducing the seriousness of the clearest cases.

Security guidance for teams in Bolivia

First, harden any exposed Redis deployment, especially if it uses modules such as RedisTimeSeries or RedisBloom. The CGII warning in Bolivia makes it clear that public exposure and use of RESTORE increase the risk. It is worth reviewing versions, restricting network access, limiting authenticated accounts with restore privileges, and checking whether replication is configured in ways that reduce read-only protection.

Second, treat mobile fraud as an operational threat, not just an end-user problem. This month’s campaigns combine fake apps, sponsored links, WhatsApp messages, and credential theft. Security teams in banking, telecom, and customer support should align blocking, verification, and session revocation messages with simple playbooks, because response speed matters more than retrospective analysis.

Third, review the exposure of public portals and services, especially those containing commerce, health, or citizen-service records. SEPREC showed that extortion can combine data leakage, public pressure, and reputational risk. In that type of case, the priority is not only containment, but also preserving evidence, defining messaging, and confirming whether sensitive data was accessed.

Fourth, strengthen BGP monitoring and connectivity health checks. There was no public attribution for the July event, but route visibility dropped during a brief interval and that justifies observation and escalation rules. Business continuity does not depend only on keeping the service online, but on keeping it routable, observable, and recoverable.

Fifth, maintain coordination among security, legal, and compliance teams on everything related to digital payments and virtual assets. The review of USDT, the new exchange scheme, and invoicing requirements can create process gaps if they are not quickly translated into controls, contracts, claims handling, and transaction traceability.

Material limitations

This report covers only facts dated in July 2026 within the material provided. The four facts from earlier months included as a comparison frame are used only for month-over-month trend analysis and are not part of the period total. No internet was used, and no source outside the authorized list was incorporated.

A zero indicator, especially for critical CVEs, does not mean there were no serious vulnerabilities or exploitation in the region. It means only that none were recorded in this month’s analyzed material. The same applies to any category not observed in the indicators: absence in the document set does not equal real absence in Bolivia.

The 67 percent figure for direct confirmation describes the quality of support for the verified facts, not the full extent of real-world risk. There are also complaints, forum claims, and dark web notes that appear as unverified or are attributed with caution. When a source could not independently corroborate a fact, the text treats it as such.

Consumer social media and sponsored or commercial consumer posts that were not among the permitted sources were excluded from the basis of this report. Aggregated telemetry, such as incidents, blocked attempts, or scans, was also not used as if it were intrusion data. Infrastructure signals and regulatory facts are interpreted as operational context, not as proof of additional attacks.

Technical annex: indicators of compromise and TTPs

The Krybit group, according to OT Security Wire, Malware News and Cyware, operates with a technical chain tied to double extortion, use of Tor for command and control, data transfer and negotiation, deletion of shadow copies with vssadmin.exe delete shadows /all /quiet, and impact on Windows, Linux, VMware ESXi and NAS environments. Its affiliate panels mention typical exfiltration volumes of 10 to 250 GB per victim.

The technical sources also link Krybit to MITRE ATT&CK T1490, T1071, T1105, T1041, T1078 and T1059. In the Bolivian case, these TTPs help frame the threat against SEPREC, although they do not replace local forensic evidence on the exact intrusion, persistence or exfiltration.

Sources