Chile: cybersecurity landscape, July 2026
Chile closed July with 24 regulatory actions and 18 unclassified incidents, alongside rising deepfakes, smishing, and alerts for active vulnerabilities.
Key findings
- Regulation dominated July in Chile, with 24 documented actions out of 68 verified events.
- ANCI closed the first qualification process and placed 239 new entities under reinforced regime as Vital Importance Operators.
- The material showed 18 unclassified incidents, many tied to alleged leaks or unconfirmed outages.
- There were 9 cases with ransomware or extortion as the primary focus, but in 8 the type of impact could not be determined.
- Social engineering fraud remained active, with 7 documented cases of phishing, vishing, or smishing.
- No critical CVEs were recorded in the material analyzed for the monthly indicator, although there were alerts for active exploitation in exposed products.
- The most sensitive sectors were government, finance, health, energy, and transportation, with growing regulatory and operational impact.
Monthly reference modules
These modules are automatically completed with the verified facts dated within the period. Each one states its basis and counting criterion, so the figures reconcile across modules. They are the recurring month-to-month reading, while the analysis that follows develops the cases without repeating this summary.
Indicator window: 70 dated facts in July 2026 · 5 after the period (excluded). Facts from earlier months are used only as comparative context in the analysis, never as part of this period’s volume.
Executive monthly recap in Chile
July put regulation at the center of Chile's cyber agenda. Of the 68 verified events in the period, 24 were documented regulatory moves, the month's leading threat. There were also 18 unclassified incidents, 9 cases centered on ransomware or extortion, and 7 documented fraud or phishing cases. No critical CVEs appeared in the material reviewed, but there was intense alerting and remediation activity around vulnerabilities actively exploited inside and outside the country.
The most visible milestone was the consolidation of Chile's new cybersecurity regime. ANCI closed the first qualification process for Vital Importance Operators, published the final list, and placed 239 new entities under strengthened obligations. That included staggered reporting to the National CSIRT, security management systems, continuity plans, and a stricter regulatory perimeter for critical infrastructure, from transport and fuels to sanitation services, telecommunications, banking, and private healthcare.
At the same time, Congress moved ahead with the bill on deepfakes and synthetic content. The proposal, approved in general in the Chamber, shifted the issue from disinformation to compliance and digital integrity, with steep financial penalties, obligations for platforms, and reporting and takedown channels. It was not yet law at month end, but it sent a clear signal of tougher rules against AI-mediated fraud.
On the operational side, the clearest cases clustered around unclassified incidents and fraud campaigns. There was a purported intrusion against infrastructure at the Ministry of Transport and Telecommunications, not yet confirmed by authorities, along with a large smishing campaign, warnings about bank vishing, and scams tied to fake benefits and service outages during the frontal system. The pattern was consistent, social engineering aimed at credentials, money, and personal data.
National overview for the month in Chile
Chile's risk level for the month was high because of the volume of regulation and the combination of unconfirmed incidents, active fraud campaigns, and critical vulnerabilities with known exploitation in widely used products. There was no single confirmed systemic event inside the country, but there was an accumulation of signals that raised pressure on security, compliance, and operational continuity teams. The assessment does not rest on an invented index, but on the density of verified material and the severity of the recorded facts.
Regulation was the center of gravity. The Cybersecurity Framework Law continued to take shape through resolutions, registries, and compliance guidance. Added to that was the practical entry into force of the new Personal Data Protection Law and the parliamentary debate on deepfakes. The result is an environment in which cybersecurity is no longer just a technical issue and has become a matter of governance, notification duties, liability, and decision traceability.
At the regional level, Chile continued to appear as one of the most exposed countries in the Latin American conversation. The July material places it within a risk scenario shared with Brazil and other markets, where regulatory frameworks are tightening, platforms are adjusting responsibilities, and CERTs are issuing alerts about active exploitation. Chile was not isolated from that dynamic, but part of it, with particular intensity in regulated sectors and essential services.
The combination of government, finance, health, energy, and transportation in the map of events confirms that the exposure surface is broad. While sectors such as government and finance concentrated much of the attention, the registry of Operators of Vital Importance expands the focus to physical infrastructure and everyday services. That suggests a maturing risk profile, less centered on isolated attacks and more aligned with the country's dependence on interconnected critical systems.
Chile Threat Indicators
| Indicator | Value |
|---|---|
| Verified events for the period (basis for all indicators) | 68 |
| Indicator time window | 70 events dated in July 2026 · 5 after the period (excluded) |
| Unclassified incidents (breaches or outages) | 18 |
| Cases with ransomware or extortion as the primary focus | 9 |
| Ransomware breakdown by impact type: Exfiltration without encryption (simple extortion) | 1 |
| Ransomware breakdown by impact type: Undeterminable classification based on the material | 8 |
| Documented fraud or phishing cases | 7 |
| Documented regulatory moves | 24 |
| Critical CVEs mentioned | 0, none in the analyzed material, this does not imply absence in the region |
| Sectors with at least one documented event | 7 |
| Dominant threat of the month | Regulation, 24 of 68 events |
| Events with direct source confirmation | 82% |
| Aggregate telemetry figures excluded from the volume | 2, aggregated attempts or blocks, not incidents with confirmed impact |
Relevant incidents in Chile
Ministry of Transport and Telecommunications, incident still unconfirmed
On July 4, a purported cybersecurity incident was reported that would have affected the infrastructure of the Ministry of Transport and Telecommunications. Coverage cited Vecert Analyzer and VECERT Radar, which classified the case as allegedly, unconfirmed. A database with more than 100,000 records and personal and employment data was also mentioned, but the available material does not allow for a confirmed impact or attribution validated by a Chilean authority.
Smishing campaign impersonating public agencies and companies
On July 29, CronUp described a massive smishing campaign expanding in Chile. The SMS messages led to malicious links that imitated public agencies and companies. The case matters because it connects to two patterns seen during the month, credential theft and the exploitation of trust in urgent or seemingly official communications.
Digital scams during the frontal weather system
On July 21, ADN Radio warned about fraudulent messages tied to fake benefits and alleged service outages during the frontal weather system. The report is relevant because it shows how weather conditions are used as bait for fraud. There was no single dominant technical vector, but rather the reuse of social urgency as a capture mechanism.
Banking vishing and coordinated response from the financial system
Between July 23 and 28, several Chilean media outlets reported bank alerts regarding vishing. The message was consistent, no bank is authorized to ask for PINs, passwords, or codes by phone. The operational signal is clear, attackers continue to use voice, pressure, and impersonation to bypass human controls rather than technical controls.
Threats and Active Campaigns in Chile
Ransomware and extortion with primary impact
In July, 9 cases were documented with ransomware or extortion as the main focus. The material does not always make it possible to tell whether there was encryption, exfiltration without encryption, or only a listing on a leak site. In 1 case, the source describes exfiltration without encryption. In 8, the classification cannot be determined precisely from the material provided.
Leak site mention only, with no verified impact
The ransomware ecosystem showed claims against Chilean victims, including Grupo Minero Las Cenizas and Hardware Asesorías Software Ltda. However, in the cases cited here, the July material does not allow confirmation of an operational impact inside Chile. In one case, the source attributes an alleged leak to a group and labels it an unconfirmed claim. In another, the entry appears in specialized trackers, but the link to Chilean infrastructure or to an actual intrusion is not demonstrated by the evidence provided.
Fraud and phishing
The month recorded 7 documented cases of fraud or phishing. Most were built around impersonation of banks, public agencies and services of public interest. In Chile, social engineering continues to work because it targets fast decisions, not technical perimeter weaknesses. The vishing campaign and the end-of-month smishing are part of the same risk family, even if the channel and pretext change.
APT, opportunistic intrusion and cyber intelligence
The case involving the Ministry of Transport and Telecommunications cannot be labeled as a confirmed intrusion. It does, however, serve as a cyber intelligence signal that merits monitoring. The available material does not provide official TTPs or reusable IoCs, so it should not be placed in an APT category. Even so, it adds pressure on the public sector and shows that threat actors continue to view Chilean state infrastructure as a high-value target.
Critical vulnerabilities affecting Chile
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| CVE-2024-6387 | OpenSSH | Active exploitation confirmed by Chile’s government CSIRT | Chile’s government CSIRT |
| CVE-2023-46805 | Ivanti Connect Secure and other Ivanti products | Actively exploited in chained campaigns | Chile’s government CSIRT |
| CVE-2024-21887 | Ivanti Connect Secure and other Ivanti products | Actively exploited in chained campaigns | Chile’s government CSIRT |
| CVE-2024-22024 | Ivanti Connect Secure and other Ivanti products | Active exploitation reported | Chile’s government CSIRT |
| CVE-2024-22026 | Ivanti Connect Secure and other Ivanti products | Active exploitation reported | Chile’s government CSIRT |
| CVE-2024-22028 | Ivanti Connect Secure and other Ivanti products | Active exploitation reported | Chile’s government CSIRT |
| CVE-2024-22029 | Ivanti Connect Secure and other Ivanti products | Active exploitation reported | Chile’s government CSIRT |
| CVE-2024-22030 | Ivanti Connect Secure and other Ivanti products | Active exploitation reported | Chile’s government CSIRT |
| CVE-2026-48282 | Adobe ColdFusion | Active exploitation confirmed by Adobe and flagged by INCIBE-CERT | Adobe, INCIBE-CERT |
| CVE-2026-50522 | Microsoft SharePoint Server | Known exploitation, included in CISA KEV | CISA, CTIR Gov of Brazil |
| CVE-2026-58644 | Microsoft SharePoint, according to Security Affairs reference | Included in CISA KEV | Security Affairs |
| CVE-2026-15409 | SonicWall SMA1000 | No active exploitation confirmed, patch available | INCIBE |
| CVE-2026-15410 | SonicWall SMA1000 | No active exploitation confirmed, patch available | INCIBE |
| CVE-2023-4966 | Citrix NetScaler ADC and Gateway | Active exploitation confirmed in earlier campaigns | Chile’s government CSIRT |
Regulation and compliance in Chile
Regulation dominated the month. The National Cybersecurity Agency issued Exempt Resolution No. 187 and closed the second stage of the first qualification process for Operators of Vital Importance. That placed 239 new entities under a tougher regime for security, continuity, reporting, and oversight. The list is not cosmetic, it reshapes obligations across entire sectors and moves cybersecurity into corporate governance structures.
The Cybersecurity Framework Law was also defined more clearly in operational terms. Essential institutions and OIVs must report significant incidents to the National CSIRT with an early warning within up to 3 hours, an update within 72 hours, and a final report within 15 days. When the event affects essential services of an OIV, the update must be delivered within a maximum of 24 hours. The law also sets graduated penalties and higher caps for vital operators.
The new Personal Data Protection Law 21.719 emerged as a second regulatory front. In July, several reports treated it as already in force or in full rollout. The available material describes obligations to map processing activities, assess gaps, define the legal basis, apply corrective actions, and notify the future Data Protection Agency and the affected individuals within a limited timeframe when the breach involves risk. For banks, fintech companies, and merchants using payment methods, that means more documentation and less room for improvisation.
The deepfake bill adds another layer. The debate is not limited to false content, it also touches digital integrity, consent, traceability, and platform responsibility. Requirements for visible labeling, reporting channels, and removal within 72 hours show a trend toward demanding specific procedural responses, not just broad principles.
Most affected sectors in Chile
The month's sector breakdown put government, finance, health, energy and mining at the center of the accumulated evidence. That does not mean they were the only ones affected, because a single incident can affect more than one sector, but it does show where the signal was concentrated. The mix of government incidents, banking fraud, health alerts and exposure of critical infrastructure points to a country with distributed risks, though not evenly spread.
Government appears twice, as a historical target of incidents and as a focus of the new regulatory framework. The alleged leak at the Ministry of Transport and Telecommunications reinforces that exposure, although there has been no official confirmation. Finance, meanwhile, was affected by three different forces, customer fraud, new enhanced authentication requirements and pressure to comply with personal data rules. It is a sector facing not only attacks, but also a growing obligation to prove that controls are effective.
Health and basic services remain sensitive because of the quality of the data they manage and the social impact of any disruption. The OIV framework extends that sensitivity to water, transportation, fuels, telecommunications and digital infrastructure. That shift matters because it turns sectors long viewed as support functions into central targets for national resilience.
The practical reading is that Chile no longer sees cybersecurity only as perimeter defense for the corporate network. The month showed once again that real exposure comes from the interdependence between data, services, digital identity and operational continuity. When those four elements overlap, the impact is not limited to IT. It reaches the business, the end user and the state.
Trends and signals to watch in Chile
There is no comparable baseline for almost all indicators in the period, so it would be wrong to invent a month-over-month trend where the source does not show one. A strong qualitative trend does stand out, July was more regulatory than the previous months in the available material and more explicit in imposing obligations on critical sectors.
The main signal to watch is the real implementation of the Cybersecurity Framework Law. July showed the shift from the statute to the concrete administration of the regime, with final lists, resolutions and guidance. That should translate into more audits, more reporting and tighter continuity requirements. If OIVs do not mature their capabilities, the regulatory gap will become visible quickly.
Another signal is the hardening of identity fraud. Vishing, smishing and opportunistic scams tied to social or weather-related events show an increasingly professionalized fraud economy. No sophisticated technical vulnerability is needed to cause harm. A poorly managed chain of trust is enough.
It will also be necessary to watch the effect of the new Data Law and the deepfakes bill on platforms, vendors and companies that use generative AI in customer service, marketing or identity verification. The overlap between automation and compliance is no longer theoretical. It is starting to shape contracts, internal processes and reputational exposure.
Finally, the relationship between alerts on actively exploited vulnerabilities and the national inventory of critical assets deserves close attention. OpenSSH, Ivanti, ColdFusion, Citrix and SharePoint are not isolated cases in the report. They are reminders that patching remains a first-order operational obligation, especially where there is internet exposure and essential services.
Security recommendations for teams in Chile
- Check immediately whether the organization was designated as a Critical Infrastructure Operator and, if so, align governance, response, and continuity with the 3 hours, 72 hours, and 15 days deadlines.
- Validate notification workflows with CSIRT, legal, continuity, and institutional relations teams. In a regulated incident, the biggest risk is not only technical, it is also coordination.
- Strengthen anti-fraud controls and out-of-band verification for vishing, smishing, and impersonation of public agencies. Do not trust the channel the attacker controls.
- Prioritize patching and exposure reduction for internet-facing services. This month’s material includes several examples of active or known exploitation on widely used platforms.
- If the organization uses generative AI or publishes synthetic content, prepare traceability, labeling, and takedown or correction procedures before the regulation requires them more strictly.
- Make sure response teams have criteria to classify incidents without overreacting to leak rumors, but also without dismissing early cyber intelligence signals.
- Maintain an updated inventory of critical assets, especially in transportation, fuels, health, telecom, and digital services, because Chile’s regulatory shift already treats them as surfaces of systemic risk.
Material limitations
This report was built exclusively from the material provided for July 2026 and from the time window stated by the indicators, 70 dated facts in July 2026 and 5 later ones excluded from the count. Facts from other months were used only when comparison was explicitly allowed and always with the month stated.
An indicator at 0, especially the one for critical CVEs mentioned, means none were recorded in the material analyzed during July 2026. It does not mean there were no critical vulnerabilities or active exploitation in the region. In fact, the material does include alerts about OpenSSH, Ivanti, Citrix, ColdFusion, SharePoint and SonicWall, but they were not counted as critical CVEs in the monthly indicator because of the way they were consolidated.
Aggregate telemetry figures, such as automated attempts or blocks, are also excluded from the volume. This month, 8.8 trillion cyberattack attempts in 2025 were mentioned by SEK and ADN Radio, but that figure is volume telemetry, not confirmed incidents with impact. It was not added to the period’s incident count.
The available material excluded sources that are not on the authorized list for citation, including consumer social networks, LinkedIn posts and sponsored or purely commercial content. When any item provided unconfirmed data, the report treated it as such and avoided turning it into settled fact. That is especially important in cases of alleged leaks and ransomware claims, where public evidence does not always rise to the level needed to confirm intrusion, encryption or exfiltration.
Sources
- Ciberseguridad de los organismos del Estado e infraestructura crítica de la informaciónBiblioteca del Congreso Nacional de Chile (Ley Fácil)
- Ley Marco de Ciberseguridad (Ley 21.663): Implicancias y Desafíos para los Operadores Críticos en ChileCámara Franco Chilena
- La inteligencia artificial: cuestión de ética y capacidades en América Latina y el CaribeEl País
- Si te dicen esto, es vishing: la estafa telefónica por la que los bancos en Chile están alertandoEl Mostrador
- Más de $700 millones: Avanza proyecto que busca multar a quienes usen IA para estafarT13
- Alerta por cambio en los bancos: ya cambiaron los requisitos para transferir dineroEl Mostrador
- DPL News Spotlight Política DigitalDPL News
- Chile busca multar la difusión de ‘deepfakes' creados con IA por hasta 760.000 dólaresEl Comercio
- Cámara aprueba proyecto para regular uso de deepfakesTVN (Exponencial)
- Debate y votación en Sala del proyecto de ley sobre deepfakesYouTube / Registro Cámara de Diputadas y Diputados
- Avanza proyecto que busca multar a quienes usen IA para estafarT13
- ALERTA 65/2026 – Vulnerabilidade crítica que afeta o SharePointGSI – CTIR Gov (Gobierno de Brasil)
- Vulnerabilidad crítica en OpenSSH (CVE-2024-6387)CSIRT de Gobierno de Chile
- Si te dicen esto, es vishing: la estafa por la que alertan los bancos en ChileEl Mostrador
- Alerta de seguridad: vulnerabilidades en IvantiCSIRT de Gobierno de Chile
- SharePoint enfrenta una falla crítica de ejecución remota explotada activamenteDiario Bitcoin
- U.S. CISA adds Microsoft SharePoint and Check Point flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs
- Critical Unauthenticated Remote Code Execution Vulnerability in Microsoft SharePoint Server CVE-2026-50522SecureVerifyConnect
- Copec, Aguas Andinas, Nuevo Pudahuel y decenas de grandes empresas quedan bajo el nuevo régimen de ciberseguridadDiario Financiero
- Cámara aprueba proyecto que sanciona las deepfakes creadas con IA con multas de hasta $716 millonesBioBioChile
- Diputados aprobaron en general proyecto que regula la IA y combate los "deepfakes"Radio Cooperativa
- Chile busca multar la difusión de 'deepfakes' creadas con IA por hasta 760.000 dólaresSwissinfo / EFE
- CVE-2026-50522: SharePoint Machine Key TheftDatawiza
- CISA Adds SharePoint RCE CVE-2026-50522 to KEV, Orders Fixes by July 25Zetik
- Chile advances bill to strengthen protection of digital copyrightEU Intellectual Property Helpdesk
- Novas regras passam a exigir mais responsabilidade das big techs no paísSindpd
- A ressalva que ficou de fora: o decreto da moderação copiou a cláusula eleitoral da Europa, mas sem o ponto centralAtlas Público
- Congresso dos EUA pede ação contra o Brasil por projeto de big techsTribuna do Norte
- Oposição pede urgência para derrubar decreto de Lula sobre big techsPoder360
- Decreto que estabelece diretrizes de proteção às mulheres na internet já está em vigorMinistério das Mulheres / Governo Federal do Brasil
- Marco Civil da Internet ganha novas regras e amplia deveresSampi
- Novas regras para big techs entram em vigor e reforçam segurança digital no BrasilPortal Amazonas
- Alerta por cambio en los bancos: ya cambiaron los requisitos para transferir dineroEl Mostrador
- Law 21.663 and data protection in ChileQuarancle
- Alerta de seguridad: vulnerabilidades en Citrix NetScaler ADC y GatewayCSIRT de Gobierno de Chile
- Multas de hasta $2.800 millones: el reto de las empresas ante las nuevas leyes de ciberseguridadTivit
- INCIBE alerta de dos vulnerabilidades críticas en SonicWall SMA1000Moncloa.com
- ALERTA 56/2026 — Campanha envolvendo Joomla Content Editor (JCE) vulnerávelGabinete de Segurança Institucional da Presidência da República (CTIR Gov)
- Guía de ciberseguridad y cumplimiento normativo en Chile (Ley 21.663 y 21.719)Prey Project
- Information Technology 2026 - ChileChambers and Partners
- 102 Alerta Red de Retransmisión Operativa CHARLIEColCERT
- CCS lanza guía esencial de protección de datos personales para pequeñas y medianas empresasCámara de Comercio de Santiago (CCS)
- Prepara tu eCommerce: ley de datos personales Chile 2026BigBuda / Garrigues
- La ANPD concluyó un monitoreo sobre encargados de datos y 21 empresas y órganos públicos podrían ser sancionados por incumplir la LGPDCiberLATAM
- Al-2026-0036 – Ransomware WallstreetECUCERT
- APSB26-68 - Adobe Security BulletinAdobe
- Attackers exploit critical Adobe ColdFusion vulnerability (CVE-2026-48282)Help Net Security
- El INCIBE alerta de una vulnerabilidad crítica de Path Traversal en Adobe ColdFusion (CVE-2026-48282) que ya está siendo explotada activamenteMoncloa.com / INCIBE-CERT
- CVE-2026-48282: Mitigating a Critical Vulnerability in Adobe ColdFusionAkamai
- Chile recibió 8,8 billones de intentos de ciberataque en 2025 y expertos advierten que las empresas siguen tardando meses en detectar una intrusiónG5 Noticias
- Fintech chilenas necesitarán expertos en IA, ciberseguridad y regulación hacia 2030Chócale
- INCIBE alerta de seis vulnerabilidades en NetScaler ADC y Gateway de CitrixMoncloa.com
- Múltiples vulnerabilidades en NetScaler de CitrixINCIBE-CERT
- Robos y fraudes en el uso de tarjetas e instrumentos financierosBiblioteca del Congreso Nacional de Chile
- Publicación sobre desafíos de implementación y plazos de la nueva ley de protección de datos en ChileValentina Palma (LinkedIn)
- Ciberseguridad, Protección de Datos y Gestión Digital - Cambios regulatorios en Chile (Ley 21.663 y Ley 21.719)Goose
- Reportan nuevo incidente de ciberseguridad en Chile: Ministerio de Transportes entre los afectadosADN Radio
- Chile rompe récord de ciberataques: los cinco errores que los delincuentes aprovechan para estafarADN Radio
- Chile acumula el 7% de los ciberataques en América Latina: qué significa eso para su empresaTrendTIC
- Falsos bonos y cortes de servicios: alerta por estafas digitales durante el sistema frontal en ChileADN Radio
- ANCI oficializa segunda nómina de Operadores de Importancia Vital y cierra hito clave de la Ley Marco de CiberseguridadTrendTIC
- Ley Marco de Ciberseguridad: Nunca es suficiente. Por María Claudia Ardila, Directora de Ventas de Sophos para el Sur de LatinoaméricaG5Noticias
- Nueva Ley de Protección de Datos: Las millonarias multas que obligarán a las empresas a replantear la gestión de su informacióne-negocios.cl
- Chile busca multar la difusión de 'deepfakes' creados con IA por hasta 760.000 dólaresInfobae / EFE
- Resolución 187 Exenta (24-jul-2026) M. de Transportes y TelecomunicacionesBiblioteca del Congreso Nacional de Chile (LeyChile)
- ANCI identifica 915 Operadores de Importancia Vital en Chile: multas suben a 40.000 UTMCyberix
- Ley 21.663: Chile's Cybersecurity Framework Law ExplainedZynap
- CYBER INTELLIGENCE ALERT: GOVERNMENT SECTOR — CHILEVECERT Radar (Vecert Analyzer)
- Finaliza calificación de operador de importancia vitalBlog de Huichalaf
- ANCI publica la nómina final de Operadores de Importancia Vital y concluye el primer proceso de calificaciónJDF Jara del Favero
- Chile concentra el 7% de los ciberataques en América Latina, según un informe del sector TIAnálisis.com
- Feed De Noticias De Ciberseguridad [29/07/2026]CronUp Ciberseguridad
- Panorama De Ciberseguridad: Semana Del 27 Al 31 De Julio De 2026CronUp Ciberseguridad
- “Teléfono robado, teléfono bloqueado”: Gobierno anuncia campaña para proteger datos personales ante robo de celularesSubsecretaría de Telecomunicaciones de Chile (Subtel)
- Chile busca multar la difusión de 'deepfakes' creados con IA por hasta 760.000 dólaresSwissinfo
- Proyecto de ley busca bloquear servicios digitales ilegales y proteger a consumidores en ChileSentenciaJudicial.cl
- Cámara aprueba proyecto que regula los deepfakes: multas de hasta 716 millonesPauta
- Multas por difundir deepfakes creados con IA llegarían a $716 millones en ChileCooperativa
- Las Cenizas Listed by thegentlemen Ransomware GroupGalaxyWarden
- Victim: Las Cenizasransomware.live
- Grupo Minero Las Cenizas Data Breach in 2026BreachSense
- Chile Ransomware & Cyber AttacksBreach House
- Cuando el ransomware deja de filtrar: el caso The Gentlemen y la Corporación ColinaSecurity Chu
- Hardware Asesorias Software Ltda — DEADLOCK Ransomware AttackBreach House
- Victim: Hardware Asesorias Software Ltda – Deadlockransomware.live
- Ransomware.live Activity – Technology/CLransomware.live
- Hardware Asesorias Software Data Breach in 2026BreachSense
- La llegada de los “carteles” al mundo digital: alertan por nuevo modelo de cibercrimen que ya afecta a LatinoaméricaADN Radio Chile
- Enorme ciberamenaza: Chile recibió más de ocho billones de intentos de ataques cibernéticos el año pasadoLa Tercera
- La confianza digital, el nuevo objetivo de los ciberdelincuentesPwC Chile
