CiberLATAMbywhalemate
Intelligence reportAug 1, 202618 min read

Brazil: cybersecurity landscape, July 2026

Brazil closed July with ransomware as the dominant theme, greater regulatory pressure, and three critical CVEs under active exploitation.

Brazil: cybersecurity landscape, July 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are completed automatically with the verified, dated facts within the period. Each one states its basis and counting criterion, so the figures reconcile across modules. They are the recurring month-to-month reading; the later analysis develops the cases without repeating this summary.

Indicator window: 66 dated facts in July 2026 · 1 from earlier months (comparative frame, not monthly volume). Facts from earlier months are used only as a comparative frame in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Monthly verified signal dashboard July 2026 · Brazil Dominant threat: Ransomware (25 of 64 incidents). Coverage: 66 dated incidents in July 2026 · 1 of prior months… VERIFIED INCIDENTS 64 period base: all counts measured from below is based on this total RANSOMWARE / EXTORTION 25 5 asset encryption cases confirmed · 20 classified cannot be determined with the UNCLASSIFIED INCIDENTS 10 breaches or disruptions without declared threat type FRAUD / PHISHING 0 documented fraud campaigns documented REGULATION 13 rules, resolutions, or penalties UNIQUE CVEs 5 CVE-2026-332201 / CVE-2026-45659
Monthly verified signal dashboard — Base: 64 verified dated incidents in the period for Brazil.
MONTHLY FIXED MODULE Threat Axis Distribution July 2026 · Brazil Each event is counted under only one axis, so the total is exactly 64. "Unclassified incidents" is the remainder. Ransomware 25 Regulation 13 Unclassified 12 Incidents 10 Vulnerabilities 4
Threat Axis Distribution — Each event is assigned to one axis based on its classification; the total reconciles to the 64 events in the period.
MONTHLY FIXED MODULE Sectoral Breakdown of Signals July 2026 · Brazil Base: 64 incidents in the period · total 84 because 16 incidents are classified in more than one sector. Public sector / OIV 29 Other / no sector ident… 16 Financial Services 11 Telecom 9 Healthcare 6 Energy 6 Technology 6 Retail / Consumer 1
Sectoral Breakdown of Signals — Heuristic sector classification by victim. One incident may affect more than one sector, so the total can exceed the base.
MONTHLY FIXED MODULE Critical infrastructure in Brazil July 2026 · Brazil 13 of 64 incidents in the period involve critical infrastructure. An incident may appear in more than one category. Public sector / government 29 Energy / utilities 2 Telecom / connectivity 8
Critical infrastructure in Brazil — Verified incidents in public sector, energy, telecom, and essential services

Monthly executive summary in Brazil

July 2026 painted a harsher picture for Brazil on two fronts that feed into each other. On one side, ransomware became the month’s dominant threat, with 25 verified incidents out of 64, and at least five episodes in which asset encryption was confirmed. On the other, the regulatory front accelerated with 13 documented moves, almost all tied to the ANPD, the Marco Civil da Internet, and the new perimeter of requirements for platforms, banks, and fintechs.

The clearest signal came from the health sector. The Isac Tecnología em Saúde case led to an ANPD sanctioning process over the exposure of nearly 500,000 patients, while SPDM and Reni Farmácias Associadas appeared in public ransomware records during the second half of the month. At the same time, Brazil continued to rank among the countries under the heaviest regional ransomware pressure, and healthcare again stood out as a particularly targeted sector, though it was not the only one hit by digital extortion.

The other notable development was in the prudential layer. The Central Bank advanced a restriction scheme for institutions with cybersecurity weaknesses in Pix, with limits on hours, amounts, and the registration of new keys, along with the possibility of temporary exclusion from the system. That shift did not stem from a confirmed July intrusion, but from an accumulated risk reading of the payments ecosystem and earlier attacks on the technology supply chain.

On the technical exposure side, the month added five critical CVEs mentioned in Brazilian and official material, all with active exploitation or elevated risk classification. The pattern is consistent, VPNs, content managers, and web components were at the center of the attack surface. For a country with 81% direct confirmation in the sources and 7 sectors with documented incidents, the problem was not a lack of signal, but the simultaneity of criminal pressure, exploited vulnerabilities, and tougher regulatory demands.

Brazil’s National Snapshot for the Month

Brazil’s risk reading for July 2026 is high. Not because of a single incident, but because of the mix of volume, recurrence, and severity. The month ended with ransomware as the dominant theme, a base of 64 verified events, 10 unclassified incidents, and 13 regulatory moves. That mix points to an environment in which the criminal market kept finding exposed attack surface, while the state responded with tighter oversight and more concrete obligations for digital and financial actors.

The pressure was not limited to one sector. Healthcare was the most visible front because of its social impact and the sensitivity of the data exposed, but the material also shows activity across energy, technology, consumer services, real estate, agriculture, and corporate services. In several cases, the public source only allows confirmation that the victim was named on a leak site; in others, such as Isac or msgas.com.br, there were firmer indicators of exfiltration or encryption. That unevenness matters, because it forces a distinction between claim, leak, and confirmed encryption.

Compared with the rest of Latin America, Brazil continued to occupy a disproportionate place. The sources cited in July place it as the regional ransomware epicenter in healthcare, among the countries with the most claimed victims by extortion groups, and also among the most exposed to campaigns that abuse legitimate infrastructure, from government domains to trusted email channels. The country appears not only as a target, but also as an environment where criminal activity, regulation, and uneven control maturity converge.

The operational picture changes when the financial front is examined. Pix was at the center of the debate as infrastructure that the Central Bank can condition to raise cybersecurity standards. The regulatory message is clear, institutions with weak controls face not only fraud or disruption, but also functional restrictions. That raises the cost of noncompliance and brings cybersecurity closer to traditional prudential supervision.

Brazil period indicators

Indicator July 2026 value Previous month Change Scope / note
Verified facts in the period 64 67 -3 Base for all indicators, only dated facts within the period
Indicator time window 66 facts dated in July 2026 · 1 from previous months (comparative framework, not July volume) Same N/A Comparative framework included in the file, not counted as July volume
Unclassified incidents (breaches or outages) 10 25 -15 Breaches or outages not sufficiently classified in the source material
Cases with ransomware or extortion as the primary focus 25 15 +10 Includes cases where ransomware or extortion was the main focus
Confirmed asset encryption 5 Not provided N/A Subset within ransomware, only when confirmed by the source material
Unable to determine classification from the material 20 Not provided N/A Subset within ransomware, exact impact could not be determined
Documented fraud or phishing cases 0 5 -5 No documented cases appeared in July
Documented regulatory moves 13 6 +7 Acts, decrees, consultations, sanctions, and regulatory announcements
Critical CVEs mentioned 5 2 +3 Critical vulnerabilities mentioned in the analyzed material
Sectors with at least one documented fact 7 7 No change One fact can affect more than one sector
Dominant threat of the month Ransomware (25 of 64 facts) Incidents (25 of 67 facts) Shift in focus Dominance by number of facts, not isolated severity
Facts with direct source confirmation 81% Not provided N/A Percentage of direct confirmation across the period facts
Aggregate telemetry figures excluded from volume 2 (aggregate attempts or blocks: not incidents with confirmed impact) Not provided N/A Telemetry, not confirmed intrusions

Relevant Incidents in Brazil

Isac Tecnologia em Saúde and the exposure of 500,000 patients

ANPD opened an administrative sanction proceeding against Isac Tecnologia em Saúde over a ransomware incident that affected about 500,000 patients from public units. The most relevant part of the case is not just the volume, but the sequence of exposure, because the material confirms file encryption that left administrative systems unavailable, although the institution itself said there was no technical evidence of exfiltration or disclosure of personal data.

That distinction matters. For operational and regulatory purposes, the difference between encryption and exfiltration changes the response, the type of notification, and the legal exposure. Here, there was an attack with functional impact, plus a formal investigation by the data authority. In July, this case stood out as one of the few episodes where the source allowed the form of harm to be distinguished.

SPDM on Global Secret Group's leak site

SPDM was publicly listed by Global Secret Group with 847 GB of claimed data and 871,912 files across 76,047 folders. The material confirms the publication on the leak site and the scale of the claim, but does not allow the primary source to show whether encryption was visible or whether the case was limited to extortion with exfiltration. Even so, the fact that a large hospital provider was exposed in this way increases sector-wide risk.

Sinop Energia and pressure on power infrastructure

Sinop Energia, operator of the Sinop hydroelectric plant in Mato Grosso, was listed by Global Secret Group as a ransomware victim with 300 GB of exfiltrated data. The case adds a different piece to July's picture, shifting attention from health to energy infrastructure, with potentially broader impact because of its ties to essential services. The public evidence supports the claim and the leaked volume, but not a detailed public confirmation of greater operational disruption.

msgas.com.br and the Blackwater case

The Brazilian gas company msgas.com.br was documented as a Blackwater victim, with exposure of customer personal data, contracts, and internal data according to independent technical analysis. Unlike other cases that appear only in trackers, this one includes a more concrete description of what was stolen. The public breach record also provides a more useful timeline, with publication on 25 July and earlier disclosure in June.

Reni Farmácias Associadas and Doommageddon

Reni Farmácias Associadas appears in public ransomware records as a Doommageddon victim, with the incident discovered on 19 July. The available material confirms the organization's inclusion in the victim ecosystem and its presence in health care, but does not make it possible to determine whether there was encryption, exfiltration, or both. It is a good example of why the report separates leak site reference from verified impact.

Francisco Imóveis and redeplastrs.com.br in July records

ransomware.live recorded Francisco Imóveis and redeplastrs.com.br as Doommageddon and Blackfield victims, respectively, with attacks estimated for 1 July and discoveries in the first days of the month. These mentions broaden ransomware's footprint in Brazil beyond the sectors that usually draw attention, but the material does not provide enough technical detail to classify them beyond their public inclusion as victims.

Active threats and campaigns in Brazil

Ransomware and extortion, with three levels of evidence

The July material points to three distinct layers. First, cases with confirmed encryption, such as Isac Tecnologia em Saúde. Second, cases with confirmed data exfiltration or theft, such as SPDM and Sinop Energia. Third, mentions on leak sites where the source does not specify the real impact, such as Reni Farmácias Associadas, Francisco Imóveis, or redeplastrs.com.br. That distinction matters, because the overall figure of 25 cases with ransomware or extortion as the primary focus combines related, but not identical, phenomena.

Within that set, extortion showed clear operational maturity. Several attacks against Brazil relied on data publication, reputational pressure and disruption of supply chains, rather than highly visible mass encryption. That logic appears especially in health care and energy. The takeaway for defensive teams is straightforward, backup controls are no longer enough on their own if the organization does not also protect credentials, exposed surfaces and exfiltration paths.

Fraud and phishing, with no documented cases in the period

There were no fraud or phishing cases documented as incidents in the period within the verified July material. That does not mean there was no risk, because the month did bring regulatory and contextual signals around financial fraud, impersonation and platform abuse, but those events are not included in the incident count because they were not presented as individual operational cases with confirmed impact.

APT, hacktivism and abuse of legitimate infrastructure

Brazil also appeared in campaigns that do not fit pure ransomware. PhantomEnigma, for example, abused more than 20 Brazilian government sites to distribute malware and targeted banks and public agencies using trusted domains and legitimate email. That pattern does not confirm state sponsorship or a closed APT attribution, but it does show a trust-engineering tactic that raises the risk of initial delivery.

Along the same lines, a reported intrusion into PagBank's payments ecosystem appeared in a manifesto from a group identifying itself as 1877 Team. The available material offers no independent confirmation from authorities or from the provider itself, so it should be read as an allegation, not a verified incident. Even with that caution, the episode is useful for tracking threat actors' appetite for Brazilian financial infrastructure.

Critical vulnerabilities with impact in Brazil

CVE Software Exploitation Source
CVE-2026-48907 Joomla Content Editor (JCE) Active exploitation confirmed by CTIR Gov in Brazil; fixes were recommended immediately CTIR Gov / Portal Gov.br, 2026-07-10
CVE-2026-56291 Balbooa Forms for Joomla Active exploitation in real-world environments, added to CISA's KEV catalog DFT Info, 2026-07-12
CVE-2026-45659 Microsoft SharePoint on-premises Active exploitation reported by CISA for remote code execution CEVIU News, 2026-07-17
CVE-2026-332201 Microsoft SharePoint on-premises Active exploitation reported by CISA for spoofing CEVIU News, 2026-07-17
CVE-2026-56164 Microsoft SharePoint on-premises Active exploitation reported by CISA for privilege escalation CEVIU News, 2026-07-17

The concentration of vulnerabilities in web components and internet-facing platforms was no coincidence. In July, the material also linked active exploitation of enterprise VPNs to real compromises in Brazilian organizations, especially through CVE-2024-24919. The practical result is a fairly clear attack surface, perimeter access, CMS, form components, and enterprise collaboration.

Regulation and compliance in Brazil

Regulatory activity was one of the month’s densest themes. ANPD closed the first phase of monitoring on 56 data processing agents, with 27 full compliance cases, 8 with pending items, and 21 with no response. That snapshot shows a regulator already prepared to move from policy to sanctions, not only in the abstract terrain of the LGPD, but in basic controls, support channels, and assignment of responsibility.

That was joined by a new operating framework for digital platforms. Decrees 12.975/2026 and 12.976/2026 took effect on July 20 and expanded duties on content moderation, illegal advertising, transparency, appeals mechanisms, and liability for systemic failures. ANPD was left as the central authority to oversee a substantial part of the regime. The shift is clear, more obligations and more traceability, with less room for platform inertia.

The case of women online drew a sensitive line. Decree 12.976 imposed deadlines to take non-consensual intimate content offline, including when it is manipulated with artificial intelligence, and gave ANPD authority to regulate, supervise, and investigate violations. In parallel, the authority updated its reporting channels and began monitoring the generation and modification of intimate content by AI. That combination of rulemaking and enforcement capacity is already producing concrete effects.

The Central Bank followed a different but converging logic. Its discussion of Pix starts from a prudential view of cyber risk and pushes it to the center of financial supervision. The possibility of limiting operating hours, transaction amounts, key registration, and even suspending access to the system was presented not as an isolated penalty, but as a preventive response to institutions with weak controls. For banks and fintechs, that makes cybersecurity an operating condition of the business.

There were also announcements from Susep, ANPD consultations with PNUD, and several legislative proposals in progress, including PL 4.752/2025 on the Legal Framework for Cybersecurity. The pattern is consistent, Brazil is not only responding to incidents, it is also rewriting the regulatory perimeter that defines who can operate, under what obligations, and with what minimum controls.

Most Affected Sectors in Brazil

Healthcare was the month’s most exposed sector because of the combination of volume, data exposure, and social cost. Isac Tecnología en Saúde, SPDM, and Reni Farmácias Associadas point to a pattern that does not need much interpretation. Clinics, hospitals, care providers, and technology vendors across the health ecosystem are under pressure. The context material also reinforces that healthcare is one of the areas where Brazil concentrates a very high share of regional ransomware activity.

Corporate services also remained under pressure. Lucas Alcaraz’s analysis placed that segment as the main ransomware target in Brazil in 2026 within the available material, and several victims disclosed in July fit that pattern. The reason is familiar, criminal groups continue to target places where operations must keep running, payments are possible, and third-party chains are broad.

Energy and utilities stood out through Sinop Energia and msgas.com.br. Although the number of incidents is lower than in healthcare, the systemic risk is higher. An incident in this kind of environment can affect service continuity, sector regulation, and, potentially, critical infrastructure.

Technology, consumer sectors, and real estate rounded out the map. These are not sectors that dominate public discussion every month, but July showed that ransomware and extortion were not confined to the usual verticals. That spread suggests the month should not be read only as a story about hospitals, but as broad pressure on organizations with digital exposure and ability to pay.

The comparison with the previous month shows a clear shift in focus. In June, the report's main threat category had been incidents, with 25 of 67 events. In July, ransomware moved to the top, with 25 of 64 events. This is not just a statistical change, it signals that extortion returned to shape the local agenda more strongly than breaches or generic disruptions.

The profile of unclassified incidents also changed. They fell from 25 to 10 compared with the previous month. That suggests better classification quality in the coverage, but also more cases where the material made it possible to identify the ransomware component with greater precision. At the same time, documented fraud or phishing cases went from 5 to 0, which does not eliminate the problem, but does indicate that July was dominated by other fronts.

Regulatory activity rose sharply. Regulatory moves increased from 6 to 13, and that is not incidental. The state responded to incidents and structural risks with more monitoring, more decrees, and more public consultations. For security teams, that means risk is no longer measured only in infections or leaks, but also in the ability to meet oversight demands, provide documentation, and respond quickly.

In critical vulnerabilities, the jump from 2 to 5 CVEs mentioned is a sign of a broader exposed surface. It does not mean there was more exploitation than in other months, but it does show that July brought more references to flaws that were actively exploited or clearly prioritized by response agencies. The focus should remain on VPNs, CMS, SharePoint, and internet-exposed components.

Compared with the rest of Latin America, Brazil remained an outlier in both volume and the concentration of claimed victims. The region saw cross-cutting campaigns against health, services, and government, but Brazil maintained a distinct density of ransomware and a more active regulatory ecosystem. That combination makes it a regional reference case, not just another country on the map.

Security recommendations for teams in Brazil

First, harden remote access and perimeter exposure. July’s reporting again put VPNs, gateways, and access solutions at the center of intrusions. Patching, mandatory MFA, privileged credential review, and access segmentation should no longer be treated as cycle tasks, but as permanent, auditable controls.

Second, review the ability to contain exfiltration, not just encryption. In Brazil, several cases this month showed that the most likely damage is no longer just downtime, but data publication and secondary extortion. That requires outbound monitoring, detection of anomalous transfers, hardened backups, and an incident response plan that includes legal and regulatory communications.

Third, prepare evidence for the regulator before you need it. ANPD showed a more aggressive agenda, the Central Bank did too, and several sectors came under specific scrutiny. Security and compliance teams should have updated inventories of assets, owners, remediation evidence, support channels, and incident traceability ready to go. If it is not documented, July made it clear that it can count as noncompliance.

Fourth, prioritize business and collaboration web platforms. The month combined CVEs in CMS, forms, SharePoint, and widely used enterprise solutions. That means accelerating exposure inventories, patch cycles, third-party component validation, and searches for legacy configurations that can no longer withstand current pressure.

Fifth, for critical sectors such as healthcare, energy, and financial services, align cybersecurity with operational continuity. July’s cases show that adversaries target the places where downtime is most costly. Response plans should include tested recovery, isolation of vital systems, identity protection, and drills that go beyond crisis-room exercises.

Material limitations

This report was prepared exclusively from the facts provided for Brazil, July 2026, and from the comparative framework explicitly identified as belonging to previous months. The time window for the indicators is the one stated at the outset, 66 facts dated July 2026 and 1 fact from previous months used only for comparison, not as part of the month's volume.

A value of 0, especially in documented fraud or phishing cases, means that no facts of that type appeared in the July material analyzed. It does not mean that fraud or phishing did not occur in Brazil during the month, only that no verifiable record of it was found in this corpus. The same applies to CVEs and any category not observed in the period, no record does not mean no activity in the region.

The distinction between ransomware with confirmed encryption, extortion with exfiltration, and a simple mention on a leak site was preserved whenever the material allowed it. In several cases, the source did not specify whether encryption occurred, and in those cases no additional classification was imposed. Telemetry totals were also excluded, because they correspond to automated attempts or blocks and not to intrusions with confirmed impact.

All sources not eligible for citation under this report's rules were excluded from the body, including consumer social media posts and LinkedIn posts, as well as any promotional or sponsored material that did not function as a verifiable primary source. When trends or risk assessments were mentioned, official agencies, CERT/CSIRT, vendor advisories, and victim records were prioritized over commercial reports or marketing content.

Sources