CiberLATAMbywhalemate
Intelligence reportAug 1, 202618 min read

Chile: cybersecurity landscape, July 2026

Chile closed July with 24 regulatory actions and 18 unclassified incidents, alongside rising deepfakes, smishing, and alerts for active vulnerabilities.

Chile: cybersecurity landscape, July 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are automatically completed with the verified facts dated within the period. Each one states its basis and counting criterion, so the figures reconcile across modules. They are the recurring month-to-month reading, while the analysis that follows develops the cases without repeating this summary.

Indicator window: 70 dated facts in July 2026 · 5 after the period (excluded). Facts from earlier months are used only as comparative context in the analysis, never as part of this period’s volume.

CIBERLATAM / WHALEMATE Verified Signal Monthly Dashboard July 2026 · Chile Primary threat: Regulation (24 of 68 events). Coverage: 70 dated events in July 2026 · 5 after the p… VERIFIED EVENTS 68 period base: all counts measured from below on this total RANSOMWARE / EXTORTION 9 1 unencrypted exfiltration (simple extortion) · 8 undetermined classification UNCLASSIFIED INCIDENTS 18 breaches or outages without declared threat type FRAUD / PHISHING 7 documented fraud campaigns documented REGULATION 24 standards, resolutions or sanctions UNIQUE CVEs 0 none in the source material analyzed (does not imply absence in the region)
Verified Signal Monthly Dashboard — Base: 68 verified dated events for Chile in the period.
MONTHLY FIXED MODULE Threat-axis distribution July 2026 · Chile Each event is counted in only one axis, so the total is exactly 68. "Unclassified incidents" is the remainder. Regulation 24 Incidents 18 Unclassified 10 Ransomware 9 Fraud 7
Threat-axis distribution — Each event is assigned to a single axis based on its classification; the total reconciles to the 68 events in the period.
FIXED MONTHLY MODULE Sectoral Distribution of Signal July 2026 · Chile Base: 68 incidents in the period · total 119 because 34 incidents are classified in more than one sector. Public sector / OIV 45 Telecom 33 Other / no sector ident… 16 Health 10 Energy 7 Finance 4 Education 3 Technology 1
Sectoral Distribution of Signal — Heuristic sector classification by victim. One incident may affect more than one sector, so the total can exceed the base.
MONTHLY FIXED MODULE Distribution of critical operators in Chile July 2026 · Chile 23 of 68 incidents in the period affect critical infrastructure. One incident may appear in more than one category. Public sector / government 43 Critical operators mentioned 8 Energy / utilities 8 Telecom / Connectivity 15
Distribution of critical operators in Chile — Verified incidents linked to critical infrastructure operators or the public sector

Executive monthly recap in Chile

July put regulation at the center of Chile's cyber agenda. Of the 68 verified events in the period, 24 were documented regulatory moves, the month's leading threat. There were also 18 unclassified incidents, 9 cases centered on ransomware or extortion, and 7 documented fraud or phishing cases. No critical CVEs appeared in the material reviewed, but there was intense alerting and remediation activity around vulnerabilities actively exploited inside and outside the country.

The most visible milestone was the consolidation of Chile's new cybersecurity regime. ANCI closed the first qualification process for Vital Importance Operators, published the final list, and placed 239 new entities under strengthened obligations. That included staggered reporting to the National CSIRT, security management systems, continuity plans, and a stricter regulatory perimeter for critical infrastructure, from transport and fuels to sanitation services, telecommunications, banking, and private healthcare.

At the same time, Congress moved ahead with the bill on deepfakes and synthetic content. The proposal, approved in general in the Chamber, shifted the issue from disinformation to compliance and digital integrity, with steep financial penalties, obligations for platforms, and reporting and takedown channels. It was not yet law at month end, but it sent a clear signal of tougher rules against AI-mediated fraud.

On the operational side, the clearest cases clustered around unclassified incidents and fraud campaigns. There was a purported intrusion against infrastructure at the Ministry of Transport and Telecommunications, not yet confirmed by authorities, along with a large smishing campaign, warnings about bank vishing, and scams tied to fake benefits and service outages during the frontal system. The pattern was consistent, social engineering aimed at credentials, money, and personal data.

Chile, comparación de señal regulatoria e incidentesGráfico de barras con los principales indicadores del período: regulación, incidentes sin tipificar, ransomware o extorsión y fraude o phishing.Monthly signals in ChileRegulationUnclassifiedRansomwareFraud241897
Chile: regulatory signal vs. incidents comparison — The regulatory agenda outpaced unclassified incidents in volume, though both coexisted with fraud and ransomware.

National overview for the month in Chile

Chile's risk level for the month was high because of the volume of regulation and the combination of unconfirmed incidents, active fraud campaigns, and critical vulnerabilities with known exploitation in widely used products. There was no single confirmed systemic event inside the country, but there was an accumulation of signals that raised pressure on security, compliance, and operational continuity teams. The assessment does not rest on an invented index, but on the density of verified material and the severity of the recorded facts.

Regulation was the center of gravity. The Cybersecurity Framework Law continued to take shape through resolutions, registries, and compliance guidance. Added to that was the practical entry into force of the new Personal Data Protection Law and the parliamentary debate on deepfakes. The result is an environment in which cybersecurity is no longer just a technical issue and has become a matter of governance, notification duties, liability, and decision traceability.

At the regional level, Chile continued to appear as one of the most exposed countries in the Latin American conversation. The July material places it within a risk scenario shared with Brazil and other markets, where regulatory frameworks are tightening, platforms are adjusting responsibilities, and CERTs are issuing alerts about active exploitation. Chile was not isolated from that dynamic, but part of it, with particular intensity in regulated sectors and essential services.

The combination of government, finance, health, energy, and transportation in the map of events confirms that the exposure surface is broad. While sectors such as government and finance concentrated much of the attention, the registry of Operators of Vital Importance expands the focus to physical infrastructure and everyday services. That suggests a maturing risk profile, less centered on isolated attacks and more aligned with the country's dependence on interconnected critical systems.

Chile Threat Indicators

Indicator Value
Verified events for the period (basis for all indicators) 68
Indicator time window 70 events dated in July 2026 · 5 after the period (excluded)
Unclassified incidents (breaches or outages) 18
Cases with ransomware or extortion as the primary focus 9
Ransomware breakdown by impact type: Exfiltration without encryption (simple extortion) 1
Ransomware breakdown by impact type: Undeterminable classification based on the material 8
Documented fraud or phishing cases 7
Documented regulatory moves 24
Critical CVEs mentioned 0, none in the analyzed material, this does not imply absence in the region
Sectors with at least one documented event 7
Dominant threat of the month Regulation, 24 of 68 events
Events with direct source confirmation 82%
Aggregate telemetry figures excluded from the volume 2, aggregated attempts or blocks, not incidents with confirmed impact

Relevant incidents in Chile

Ministry of Transport and Telecommunications, incident still unconfirmed

On July 4, a purported cybersecurity incident was reported that would have affected the infrastructure of the Ministry of Transport and Telecommunications. Coverage cited Vecert Analyzer and VECERT Radar, which classified the case as allegedly, unconfirmed. A database with more than 100,000 records and personal and employment data was also mentioned, but the available material does not allow for a confirmed impact or attribution validated by a Chilean authority.

Smishing campaign impersonating public agencies and companies

On July 29, CronUp described a massive smishing campaign expanding in Chile. The SMS messages led to malicious links that imitated public agencies and companies. The case matters because it connects to two patterns seen during the month, credential theft and the exploitation of trust in urgent or seemingly official communications.

Digital scams during the frontal weather system

On July 21, ADN Radio warned about fraudulent messages tied to fake benefits and alleged service outages during the frontal weather system. The report is relevant because it shows how weather conditions are used as bait for fraud. There was no single dominant technical vector, but rather the reuse of social urgency as a capture mechanism.

Banking vishing and coordinated response from the financial system

Between July 23 and 28, several Chilean media outlets reported bank alerts regarding vishing. The message was consistent, no bank is authorized to ask for PINs, passwords, or codes by phone. The operational signal is clear, attackers continue to use voice, pressure, and impersonation to bypass human controls rather than technical controls.

Threats and Active Campaigns in Chile

Ransomware and extortion with primary impact

In July, 9 cases were documented with ransomware or extortion as the main focus. The material does not always make it possible to tell whether there was encryption, exfiltration without encryption, or only a listing on a leak site. In 1 case, the source describes exfiltration without encryption. In 8, the classification cannot be determined precisely from the material provided.

Leak site mention only, with no verified impact

The ransomware ecosystem showed claims against Chilean victims, including Grupo Minero Las Cenizas and Hardware Asesorías Software Ltda. However, in the cases cited here, the July material does not allow confirmation of an operational impact inside Chile. In one case, the source attributes an alleged leak to a group and labels it an unconfirmed claim. In another, the entry appears in specialized trackers, but the link to Chilean infrastructure or to an actual intrusion is not demonstrated by the evidence provided.

Fraud and phishing

The month recorded 7 documented cases of fraud or phishing. Most were built around impersonation of banks, public agencies and services of public interest. In Chile, social engineering continues to work because it targets fast decisions, not technical perimeter weaknesses. The vishing campaign and the end-of-month smishing are part of the same risk family, even if the channel and pretext change.

APT, opportunistic intrusion and cyber intelligence

The case involving the Ministry of Transport and Telecommunications cannot be labeled as a confirmed intrusion. It does, however, serve as a cyber intelligence signal that merits monitoring. The available material does not provide official TTPs or reusable IoCs, so it should not be placed in an APT category. Even so, it adds pressure on the public sector and shows that threat actors continue to view Chilean state infrastructure as a high-value target.

Critical vulnerabilities affecting Chile

CVE Software Exploitation Source
CVE-2024-6387 OpenSSH Active exploitation confirmed by Chile’s government CSIRT Chile’s government CSIRT
CVE-2023-46805 Ivanti Connect Secure and other Ivanti products Actively exploited in chained campaigns Chile’s government CSIRT
CVE-2024-21887 Ivanti Connect Secure and other Ivanti products Actively exploited in chained campaigns Chile’s government CSIRT
CVE-2024-22024 Ivanti Connect Secure and other Ivanti products Active exploitation reported Chile’s government CSIRT
CVE-2024-22026 Ivanti Connect Secure and other Ivanti products Active exploitation reported Chile’s government CSIRT
CVE-2024-22028 Ivanti Connect Secure and other Ivanti products Active exploitation reported Chile’s government CSIRT
CVE-2024-22029 Ivanti Connect Secure and other Ivanti products Active exploitation reported Chile’s government CSIRT
CVE-2024-22030 Ivanti Connect Secure and other Ivanti products Active exploitation reported Chile’s government CSIRT
CVE-2026-48282 Adobe ColdFusion Active exploitation confirmed by Adobe and flagged by INCIBE-CERT Adobe, INCIBE-CERT
CVE-2026-50522 Microsoft SharePoint Server Known exploitation, included in CISA KEV CISA, CTIR Gov of Brazil
CVE-2026-58644 Microsoft SharePoint, according to Security Affairs reference Included in CISA KEV Security Affairs
CVE-2026-15409 SonicWall SMA1000 No active exploitation confirmed, patch available INCIBE
CVE-2026-15410 SonicWall SMA1000 No active exploitation confirmed, patch available INCIBE
CVE-2023-4966 Citrix NetScaler ADC and Gateway Active exploitation confirmed in earlier campaigns Chile’s government CSIRT

Regulation and compliance in Chile

Regulation dominated the month. The National Cybersecurity Agency issued Exempt Resolution No. 187 and closed the second stage of the first qualification process for Operators of Vital Importance. That placed 239 new entities under a tougher regime for security, continuity, reporting, and oversight. The list is not cosmetic, it reshapes obligations across entire sectors and moves cybersecurity into corporate governance structures.

The Cybersecurity Framework Law was also defined more clearly in operational terms. Essential institutions and OIVs must report significant incidents to the National CSIRT with an early warning within up to 3 hours, an update within 72 hours, and a final report within 15 days. When the event affects essential services of an OIV, the update must be delivered within a maximum of 24 hours. The law also sets graduated penalties and higher caps for vital operators.

The new Personal Data Protection Law 21.719 emerged as a second regulatory front. In July, several reports treated it as already in force or in full rollout. The available material describes obligations to map processing activities, assess gaps, define the legal basis, apply corrective actions, and notify the future Data Protection Agency and the affected individuals within a limited timeframe when the breach involves risk. For banks, fintech companies, and merchants using payment methods, that means more documentation and less room for improvisation.

The deepfake bill adds another layer. The debate is not limited to false content, it also touches digital integrity, consent, traceability, and platform responsibility. Requirements for visible labeling, reporting channels, and removal within 72 hours show a trend toward demanding specific procedural responses, not just broad principles.

Most affected sectors in Chile

The month's sector breakdown put government, finance, health, energy and mining at the center of the accumulated evidence. That does not mean they were the only ones affected, because a single incident can affect more than one sector, but it does show where the signal was concentrated. The mix of government incidents, banking fraud, health alerts and exposure of critical infrastructure points to a country with distributed risks, though not evenly spread.

Government appears twice, as a historical target of incidents and as a focus of the new regulatory framework. The alleged leak at the Ministry of Transport and Telecommunications reinforces that exposure, although there has been no official confirmation. Finance, meanwhile, was affected by three different forces, customer fraud, new enhanced authentication requirements and pressure to comply with personal data rules. It is a sector facing not only attacks, but also a growing obligation to prove that controls are effective.

Health and basic services remain sensitive because of the quality of the data they manage and the social impact of any disruption. The OIV framework extends that sensitivity to water, transportation, fuels, telecommunications and digital infrastructure. That shift matters because it turns sectors long viewed as support functions into central targets for national resilience.

The practical reading is that Chile no longer sees cybersecurity only as perimeter defense for the corporate network. The month showed once again that real exposure comes from the interdependence between data, services, digital identity and operational continuity. When those four elements overlap, the impact is not limited to IT. It reaches the business, the end user and the state.

There is no comparable baseline for almost all indicators in the period, so it would be wrong to invent a month-over-month trend where the source does not show one. A strong qualitative trend does stand out, July was more regulatory than the previous months in the available material and more explicit in imposing obligations on critical sectors.

The main signal to watch is the real implementation of the Cybersecurity Framework Law. July showed the shift from the statute to the concrete administration of the regime, with final lists, resolutions and guidance. That should translate into more audits, more reporting and tighter continuity requirements. If OIVs do not mature their capabilities, the regulatory gap will become visible quickly.

Another signal is the hardening of identity fraud. Vishing, smishing and opportunistic scams tied to social or weather-related events show an increasingly professionalized fraud economy. No sophisticated technical vulnerability is needed to cause harm. A poorly managed chain of trust is enough.

It will also be necessary to watch the effect of the new Data Law and the deepfakes bill on platforms, vendors and companies that use generative AI in customer service, marketing or identity verification. The overlap between automation and compliance is no longer theoretical. It is starting to shape contracts, internal processes and reputational exposure.

Finally, the relationship between alerts on actively exploited vulnerabilities and the national inventory of critical assets deserves close attention. OpenSSH, Ivanti, ColdFusion, Citrix and SharePoint are not isolated cases in the report. They are reminders that patching remains a first-order operational obligation, especially where there is internet exposure and essential services.

Security recommendations for teams in Chile

  1. Check immediately whether the organization was designated as a Critical Infrastructure Operator and, if so, align governance, response, and continuity with the 3 hours, 72 hours, and 15 days deadlines.
  2. Validate notification workflows with CSIRT, legal, continuity, and institutional relations teams. In a regulated incident, the biggest risk is not only technical, it is also coordination.
  3. Strengthen anti-fraud controls and out-of-band verification for vishing, smishing, and impersonation of public agencies. Do not trust the channel the attacker controls.
  4. Prioritize patching and exposure reduction for internet-facing services. This month’s material includes several examples of active or known exploitation on widely used platforms.
  5. If the organization uses generative AI or publishes synthetic content, prepare traceability, labeling, and takedown or correction procedures before the regulation requires them more strictly.
  6. Make sure response teams have criteria to classify incidents without overreacting to leak rumors, but also without dismissing early cyber intelligence signals.
  7. Maintain an updated inventory of critical assets, especially in transportation, fuels, health, telecom, and digital services, because Chile’s regulatory shift already treats them as surfaces of systemic risk.

Material limitations

This report was built exclusively from the material provided for July 2026 and from the time window stated by the indicators, 70 dated facts in July 2026 and 5 later ones excluded from the count. Facts from other months were used only when comparison was explicitly allowed and always with the month stated.

An indicator at 0, especially the one for critical CVEs mentioned, means none were recorded in the material analyzed during July 2026. It does not mean there were no critical vulnerabilities or active exploitation in the region. In fact, the material does include alerts about OpenSSH, Ivanti, Citrix, ColdFusion, SharePoint and SonicWall, but they were not counted as critical CVEs in the monthly indicator because of the way they were consolidated.

Aggregate telemetry figures, such as automated attempts or blocks, are also excluded from the volume. This month, 8.8 trillion cyberattack attempts in 2025 were mentioned by SEK and ADN Radio, but that figure is volume telemetry, not confirmed incidents with impact. It was not added to the period’s incident count.

The available material excluded sources that are not on the authorized list for citation, including consumer social networks, LinkedIn posts and sponsored or purely commercial content. When any item provided unconfirmed data, the report treated it as such and avoided turning it into settled fact. That is especially important in cases of alleged leaks and ransomware claims, where public evidence does not always rise to the level needed to confirm intrusion, encryption or exfiltration.

Sources