Situación Nacional de Ciberseguridad - Junio 2026 - Brasil
Brazil ended June with 23 incidents, a false national alert, and two regulatory moves in a month dominated by ransomware.
Key findings
- Brazil ended June with 23 incidents and 16 ransomware or extortion cases, with cross-sector pressure on the public sector, education, logistics, and manufacturing.
- The Defesa Civil false alert was the month’s most sensitive event because of its mass reach and its exposure of weaknesses in the national alert system.
- The month showed active exploitation or warnings of seven critical CVEs, several in software widely deployed across Brazilian companies and public agencies.
- Regulation advanced through rules from Anatel, TSE, CJF, ANAC, and federal guidance, increasing the overlap between technical response and compliance.
- There was no prior comparative baseline for this format, so trend reading should be based on the relative weight of the verified events in June.
- The highest risk for July is ransomware, phishing, and abuse of critical infrastructure with low tolerance for operational error.
- Exposure of personal data in monitoring tools and ERP systems can trigger LGPD obligations much faster than in previous months.
Monthly reference modules
These modules are completed automatically with verified facts and sources from the period. They are the recurring monthly read, while the later analysis develops the cases without repeating this summary.
Executive monthly roundup in Brazil
The most visible episode in June was the intrusion that triggered fake "Extreme Alert" messages in the national Defesa Civil system. On June 20, the platform was taken offline preventively around 1:30 a.m., after an unauthorized notice reached phones in several states and led to a Federal Police investigation. Reuters, Bloomberg, CNN and other outlets agree that the content had not been issued by the legitimate system and that authorities ruled out, at that point, a confirmed structural impact on the core infrastructure.
The scale of the episode was significant. Coverage cites "millions" of affected phones and, in some journalistic tallies, a potential reach of tens of millions of people. The spread began in Paraná and then reached São Paulo, Rio de Janeiro, Brasília, Bahia, Pará, Mato Grosso do Sul and Acre. That reach explains why the incident dominated the month’s agenda and delivered a clear operational message, the public warning chain depends on technical components that cannot fail or be compromised without massive consequences.
At the same time, the month showed sustained ransomware and extortion activity. Daniel Donda’s weekly radar recorded five Brazilian organizations exposed in the week of June 15 to 22, with attributions to Payload, WorldLeaks, Krybit and LockBit5. This was joined by the case of MHE9 Logística Ltda, flagged by Gunra, and by continued public warnings about ransomware pressure in Brazil, with references to a 25% year-over-year increase in attacks and an average of 3,736 weekly attacks per organization in a survey cited by Dinamio and Valor Econômico.
The risk surface was not limited to extortion. June was also marked by critical vulnerabilities in widely used products, with at least seven CVEs mentioned in sources from the period. These include CVE-2026-20245 in Cisco Catalyst SD-WAN Manager, CVE-2026-20253 in Splunk Enterprise, CVE-2026-46817 in Oracle Payments and CVE-2026-41091 in Microsoft Defender, several with active exploitation or already included in risk catalogs. For Brazilian organizations, the practical value of these alerts is not abstract, because several of those technologies appear in corporate, industrial and government environments in the country.
The regulatory front also moved. Anatel established its Artificial Intelligence Governance Policy, the TSE approved an Information Security Policy and the CJF published guidelines on incident communication, access-to-information requests and the LGPD. In the same vein, the Secretaria de Governo Digital released a privacy notice guide and Gov.br published a reference guide to prevent and respond to ransomware. The result is a month with more operational pressure on security and compliance teams, not from a single cause, but from the accumulation of incidents, extortion campaigns, credential exposure and regulatory changes.
National overview for Brazil this month
Brazil’s risk reading for June is high. The reason is not just the number of documented incidents, but the mix of severity and public exposure. There were 23 documented incidents, 16 documented ransomware or extortion cases, and one clear documented fraud or phishing case, along with two regulatory moves and seven critical CVEs mentioned. That combination points to a month of broad pressure on the digital attack surface, with visible impact across public sector, private companies, education, logistics, and health.
The dominant threat was the set of incidents, but within that volume, ransomware remained the form with the greatest persistent damage potential. The weekly radar cited by Daniel Donda showed five Brazilian organizations affected in a single observation window, while other sources from the same period described campaigns with names already familiar in the extortion ecosystem. Added to that is the GSI figure, which reported 6,774 cyber incidents in the systems of Brazil’s federal government through early June, a reference that, although not limited to ransomware, helps show the sustained pressure on public agencies.
The [Defesa Civil](https://www.semana.com/tecnologia/articulo/ataque-hacker-pudo-comprometer-sistemas-de-defensa-de-brasil-defensa-civil-explico-los-mensajes-no-autorizados/202637/) episode was the month’s most sensitive event from a social and operational standpoint. It was not a typical data theft or a quiet extortion attempt, but a disruption of the state alert channel, with the potential to trigger real panic. The investigation itself pointed to a broader technical problem, because specialists quoted by tech media questioned the lack of robust authentication mechanisms in Cell Broadcast systems. If a forged message can reach millions of phones, the risk is no longer only about unavailability, it is also about manipulating public trust.
At the regional level, Brazil again stood out as a significant target within Latin America. Several month-end reports place it among the countries most exposed to ransomware, and Check Point analyses cited by Dinamio indicate that the region was the most attacked in the world during the period in question. That fits a pattern in which Brazil combines economic scale, sector diversity, and a heterogeneous installed base, which multiplies opportunities for extortion groups and for exploitation of known vulnerabilities.
Brazil period indicators
| Indicator | Value |
|---|---|
| Documented incidents | 23 |
| Documented ransomware or extortion cases | 16 |
| Documented fraud or phishing cases | 1 |
| Documented regulatory actions | 2 |
| Critical CVEs mentioned | 7 |
| Sectors with at least one documented event | 8 |
| Predominant threat of the month | Incidents (23 events) |
| Events with direct source confirmation | 67% |
| Comparison with the previous month | No comparative baseline, this is the first archived period with this indicator format for Brazil |
Relevant incidents in Brazil
National Civil Defense alert system
On June 20, the Defesa Civil cell alert system was temporarily shut down after an unauthorized message classified as "Extreme Alert" was sent. Reuters reported that the notice, which included the word "misanthropy," was transmitted remotely to multiple states and that the case was handed over to the Federal Police. Bloomberg and Bloomberg Línea added that the suspension was carried out around 1:30 a.m. and that the government had not set a date to restore the platform. CNN traced the initial spread from Paraná to São Paulo and Rio de Janeiro, while The Next Web said the same content later reached at least seven states.
What stands out most in this incident is not just the intrusion, but the breach of trust it exposed. The system was designed to automatically deliver risk messages to anyone located in potentially affected areas. Exame explained that normal operating model and, precisely for that reason, an unauthorized broadcast alters the logic of the entire system. The episode sent a clear signal about Brazil's dependence on an emergency communication framework that needs redundancy, strong access controls and continuous operational verification.
MHE9 Logística Ltda, threat attributed to Gunra
Dexpose reported on June 12 that the Gunra group claimed to have attacked MHE9 Logística Ltda, a logistics firm based in Brazil, and threatened to publish a full data dump if negotiations did not begin. The report did not show public confirmation from the affected company, but it did reflect a classic double-extortion play, with pressure aimed at forcing contact and increasing reputational costs.
iFood, confirmed December 2025 breach disclosed in June
HackRead reported on June 4 that iFood confirmed a breach that occurred in December 2025 and exposed data from approximately 1.2 million users. The compromised information included names, phone numbers, addresses and CPF, but not passwords, banking data or credit cards. The company said it acted in line with ANPD regulations and chose not to notify users individually, arguing that the incident did not represent relevant risk or harm under the applicable regulatory criteria.
Federal government and cumulative incident exposure
Folha de S.Paulo, citing the GSI, reported that Brazilian federal government systems recorded 6,774 cyber incidents through early June. This is not a single campaign, but an institutional snapshot that reinforces the broader picture for the month. At the same time, several security ecosystem sources listed Brazilian organizations on leak sites or ransomware trackers, suggesting distributed exposure across ministries, private companies and service entities.
Threats and active campaigns in Brazil
Ransomware and extortion
The month’s dominant pattern was ransomware and extortion. Daniel Donda’s weekly radar for June 15 to 22 listed five Brazilian organizations among 100 affected worldwide. The names include Editora Irmãos Vitale, Super Finishing, mupras.com, coemi.com.br and saude.mt.gov.br, tied to Payload, WorldLeaks, Krybit and LockBit5. Although several entries rely on leak-site posts rather than victim statements, the pattern matches campaigns designed to increase pressure through public exposure of data.
Another case flagged during the month was Gunra against MHE9 Logística Ltda. That was followed by outside references to a Brazilian victim on BreachSense, META, linked to BravoX, although the available coverage did not allow that point to be treated as direct confirmation. The editorial takeaway is different, the extortion ecosystem did not slow in June and reached multiple sectors, from education and manufacturing to logistics and occupational health.
Brazil also appeared in context reporting that did not describe a specific incident, but did point to a market trend. Dinamio noted that in March 2026 the country ranked eighth globally among the most affected by ransomware, with 1.8% of reported attacks worldwide. Valor Econômico, meanwhile, cited SonicWall data and reported a 25% increase in ransomware attacks in Brazil. Operationally, that points to an environment where defense teams must deal with active campaigns and a broad underlying technology exposure.
Fraud and phishing
The only case in this category in this month’s material was G1’s reference to 553 million phishing attempts in Brazil during 2025, citing Kaspersky data. It does not describe a specific June attack, but it does show the structural level of pressure still affecting users and small and midsize businesses. The same content says 43% of cyberattacks mapped in Latin America targeted SMEs, a useful indicator of the region’s most likely victim profile.
APT, intrusion and infrastructure abuse
The consolidated material did not show a classic APT campaign with strong attribution for Brazil during June. It did, however, show abuse of critical public infrastructure, especially in the case of the Defesa Civil alert system, which can be read as intrusion, message diversion and sabotage of trust. Technically, the harm did not come from encryption or confirmed large-scale exfiltration, but from the malicious use of a state emergency channel.
Critical vulnerabilities affecting Brazil
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| CVE-2026-20245 | Cisco Catalyst SD-WAN Manager | Active exploitation reported by Cisco | Daniel Donda, 08/06/2026 |
| CVE-2026-20253 | Splunk Enterprise | Limited active exploitation, included in KEV | Dolutech, 20/06/2026 |
| CVE-2026-46817 | Oracle Payments, Oracle E-Business Suite | Already exploited in real-world attacks | Pasquale Pillitteri, 30/06/2026 |
| CVE-2026-41091 | Microsoft Defender | Active exploitation at the time of patching | Jornal Capital, 16/06/2026 |
| CVE-2026-41089 | Windows Netlogon | Active exploitation reported by the CCB | TecMundo, 01/06/2026 |
| CVE-2026-35273 | Oracle PeopleSoft | Active exploitation in ransomware campaigns, according to technical coverage | Tec do Saber, 21/06/2026 |
| CVE-2026-28318 | Not specified in the source | Included in KEV with signs of active exploitation | Daniel Donda, 08/06/2026 |
The operational read of this table is straightforward. June's critical flaws were not confined to a single vendor or a single type of environment. Exposure appeared in networking, collaboration, ERP, endpoint protection, and domain controllers. For Brazil, where sectors with different levels of maturity coexist, the priority is not abstract CVE monitoring, but identifying which platforms are actually deployed and which ones face internet exposure or elevated privileges.
Regulation and compliance in Brazil
June brought two clearly documented regulatory moves and several supporting administrative instruments. Anatel established the Artificial Intelligence Governance Policy through Internal Resolution No. 554, the TSE approved Resolution No. 23.763 on Information Security Policy, the CJF published rules on incident reporting and LGPD, and the Secretaria de Governo Digital released a guide for privacy notices aligned with Brazilian rules. Added to that is ANAC's Resolution No. 806 on unmanned aircraft, which is not a cybersecurity standard in the strict sense, but is part of the sector's technological control framework.
The other key document was the "Guia de Referência para Prevenção e Resposta a Ransomware" published by Gov.br. Its practical value lies in organizing a response that many organizations still handle ad hoc, especially when an attack crosses the lines between IT, legal, privacy, and operational continuity. The release of that material in the same month as a wave of extortion and an intrusion into the public alert system was no coincidence. It shows that the Brazilian state is trying to establish a methodological baseline for response and prevention.
The month's legal relevance also appeared in Dolutech's comment on CVE-2026-20253. The source notes that a successful exploitation of Splunk that stores personal data can trigger notification obligations under the LGPD before the ANPD. That kind of observation matters because it turns a technical vulnerability into a compliance issue, especially for organizations that concentrate logs, monitoring, and sensitive data.
Most Affected Sectors in Brazil
At least eight sectors had documented incidents during June. The strongest signal appeared in the public sector, driven by the Defesa Civil incident and by the ransomware radar that includes saude.mt.gov.br. There was also activity in education, with Editora Irmãos Vitale; in manufacturing, with Super Finishing; in business services, with mupras.com; in logistics, with MHE9 Logística Ltda; and in health, both because of the regional ransomware context and the reference to META as an occupational health provider in an aggregator source.
The sector breakdown does not point to a single front in crisis, but to a cross-sector spread. That is typical of environments where extortion targets quick payment or maximum visibility, and where attacks on public or alerting systems create a disproportionate impact relative to the technical effort required. In Brazil, the public sector was not only a victim, it also issued new rules and guidance, which adds a double burden on security teams: respond to incidents and, at the same time, implement new controls and policies.
The sector view also raises an alert for SMEs and intermediate suppliers. The month’s material insists that phishing and other entry vectors continue to hit small and medium-sized companies, while ransomware takes advantage of exposed surfaces such as RDP, VPN, RDWeb and compromised credentials. In other words, the weakness is not confined to large corporations or the state. It is spread across the service chain.
Trends and signals to watch in Brazil
There is no month-over-month baseline, because this is the first archived period with this indicator format for Brazil. Even so, the June snapshot highlights several signals that merit monitoring in July.
First, abuse of public alert and notification systems. The Defesa Civil case showed that an emergency system can become a panic vector if it is not properly authenticated and segmented. If the incident is confirmed as an intrusion or platform abuse, the country will need to revisit architecture, message validation, and contingency procedures.
Second, the overlap between ransomware and service sectors. The cases observed in June were not limited to one industry, but spread across education, logistics, manufacturing, occupational health, and the public sector. That diversity makes vertical responses harder and pushes attention toward cross-cutting controls, especially identity, backups, and exposed remote services.
Third, the intersection of critical vulnerabilities and compliance. This month’s sources show that a real-world exploitation can quickly trigger regulatory obligations. That is especially relevant in environments that process personal data, where response time is no longer measured only in technical hours, but also in notification deadlines and legal handling.
Fourth, there is no sign of a pause in extortion campaigns. The month left enough evidence to suggest that active groups will keep pressuring Brazilian victims as long as they find exposed systems, reused credentials, or weak controls.
Security recommendations for teams in Brazil
- Review public alert channels and message authentication mechanisms, with failover testing, integrity logs, and safe shutdown procedures.
- Prioritize patches for CVE-2026-20245, CVE-2026-20253, CVE-2026-46817, CVE-2026-41091 and CVE-2026-41089, based on actual exposure in the inventory.
- Audit remote access, especially RDP, VPN and similar services, with emphasis on MFA, privileged account control and closing orphaned access.
- Verify offline or immutable backups and test restoration, not just whether backups exist.
- Review how personal data is handled in observability tools, SIEM and logging, because a breach of those platforms can trigger notification obligations.
- Harden email, browsers and anti-phishing filters for SMB and third-party users, which remain a recurring entry point.
- Map the extortion surface by vendor, because several incidents this month point to mid-sized companies with limited exposure but high operational impact.
- Cross business continuity, legal and privacy in a single playbook, especially in public and regulated sectors.
Material limitations
This report was prepared exclusively from the material provided for June 2026 and without internet access. Several references from the month come from press coverage or aggregators that attribute events to leak sites, so it was not always possible to turn every signal into direct confirmation from the victim or of the impact.
There are also differences across sources regarding the exact scope of some incidents, particularly the Defesa Civil episode and the number of messages or statuses affected. To avoid overstatement, only the data that appears repeatedly or is supported by the available sources in the corpus was consolidated. When a news item described an attribution as likely or alleged, that condition was preserved in the editorial reading.
The critical vulnerabilities section includes only CVEs explicitly mentioned in the sources from the period. No additional flaws were added and no unmentioned products were inferred. The same caution was applied to ransomware cases, where some radar or aggregator entries were treated as source attributions and not as absolute confirmations.
Sources
- O falso alerta que revelou uma vulnerabilidade realUFJF – Grupo de Pesquisa em Políticas de Defesa Civil
- Radar Semanal de Ransomware — 22/06/2026Daniel Donda
- Ciberataque contra sistema nacional de alertas de BrasilPeople’s Daily (español)
- Ataque hacker pudo comprometer sistemas de defensa de Brasil: Defensa Civil explicó los mensajes no autorizadosSemana
- Brasil investiga un presunto ataque cibernético luego de que millones de personas recibieran una falsa alerta de emergenciaInfobae
- Brasil investiga posible ciberataque a su sistema de alertas de emergencia: falsa alarma despertó a miles de personas en la madrugadaEl Universal
- Ransomware no Brasil em 2026: o que mudou e como agirDinamio
- Brasil registra aumento de 25% nos ataques de ransomware e empresas enfrentam lacunas críticas em planos de recuperaçãoValor Econômico / Pressworks
- El grupo de ransomware más activo del mundo llegó a LatinoaméricaEl Heraldo de Puebla
- Ransomware en mayo de 2026: 95 ataques, Qilin lidera y la sanidad es el sector más golpeadoRevista Ciberseguridad
- Suspected hacker sends unauthorized alert across BrazilReuters
- Gunra Ransomware Group Targets MHE9 Logística Ltda in BrazilDexpose
- June 2026 Data Breaches: List Major Incidents & Latest ...SharkStriker
- The State of Ransomware: June 2026BlackFog
- Millions in Brazil Get Fake Government Mobile Alert After HackBloomberg
- Misanthropy: Millions In Brazil Get Fake Government Mobile Alert, Hack SuspectedNDTV
- Brazil: Hackers suspected to be behind unauthorized alertCNN
- Hackers hijacked Brazil's emergency alert system and sent "misanthropy" messagesThe Next Web
- O que é alerta extremo da Defesa Civil? Veja quando avisos aparecem no celularExame
- Brazil Cyberattack: False Alert Causes Panic Among CitizensYouTube
- Brazil begins investigating emergency alert system breachThe Register
- Suspected Cyberattack Triggers False Emergency Alerts Across BrazilSecurity Boulevard
- Brazil probes possible cyberattack on alert systemThe Star
- 'Hackers' send fake alert to thousands of phones in Brazil: What the officials saidThe Times of India
- "Provável ciberataque" na origem de falsos alertas ao público no BrasilRTP
- Milhões recebem alerta falso da Defesa Civil por celular após ciberataqueBloomberg Línea
- Falsos alertas da proteção civil no Brasil com origem em "provável" ciberataqueDiário de Notícias
- Ataque hacker: Imprensa internacional repercute invasão contra sistema de alertas da Defesa CivilO Globo
- PMEs já concentram 43% dos ataques cibernéticos mapeados na América LatinaG1
- Prevenção e Resposta a Ransomware - Guia de ReferênciaGov.br
- Resolução Interna Anatel nº 554, de 1º de junho de 2026Agência Nacional de Telecomunicações (Anatel)
- Resolução nº 23.763, de 9 de junho de 2026Tribunal Superior Eleitoral (TSE)
- DOUInforme 19.06.2026Conselho da Justiça Federal (CJF)
- Guia para Elaboração de Avisos de Privacidade v1.0 – PPSI 2.0Secretaria de Governo Digital – Governo Federal do Brasil
- Resolução nº 806, de 15 de junho de 2026Agência Nacional de Aviação Civil (ANAC)
- CCT debate marco legal da cibersegurança – 30/6/26Senado Federal – TV Senado
- ABIN debate Projeto de Lei que institui Marco Legal da CibersegurançaAgência Brasileira de Inteligência (ABIN)
- Ransomware no Brasil em 2026: o que mudou e como agirDinamio
- GSI registra mais de 6.000 incidentes cibernéticos em 2026Folha de S.Paulo
- Resumo das Notícias de Cibersegurança - 08/06/26Daniel Donda
- Splunk Enterprise: Falha Crítica CVE-2026-20253 RCEDolutech
- Oracle EBS CVE-2026-46817: falha CVSS 9.8 sem senhaPasquale Pillitteri
- 206 vulnerabilidades corrigidas: o Patch Tuesday que entrou para a históriaJornal Capital
- Falha crítica no Windows Netlogon está sendo explorada ativamente, alerta autoridade belgaTecMundo
- Vulnerabilidade Crítica da Oracle PeopleSoft é Explorada em Campanhas de Ransomware: Entenda os Riscos da CVE-2026-35273Tec do Saber
- Nissan Confirms Employee Data Breach Following Oracle PeopleSoft ExploitNational CIO Review
- Nissan Employee Data Breached in Oracle PeopleSoft HackSecurityWeek
- iFood Confirms Data Breach Affecting 1.2 Million Users in BrazilHackRead
- CVE-2026-35273Tenable
- ShinyHunters Hit Oracle PeopleSoft and Your Vendors May Already Be CompromisedBlack Kite
- ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273)The Hacker News
- Data breaches in June 2026BreachSense
- SPORTON International Inc. - Victim | RansomwareRadarSOCRadar
- Nissan Discloses Employee Data Breach Linked to Oracle PeopleSoft Zero-DayInfosecurity Magazine
- O que o ransomware Sorry Worm, o trojan Grandoreiro e a IA têm em comumDiário de Minas
