CiberLATAMbywhalemate
Intelligence report

Chile Cybersecurity Situation, September 2026

Ransomware led September in Chile, alongside active fraud and a heavy regulatory agenda on personal data

Oct 1, 202615 min read
Chile Cybersecurity Situation, September 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are completed automatically with the verified dated facts within the period. Each one states its source and counting criterion, so the figures reconcile across modules. They are the recurring month-to-month read, while the later analysis develops the cases without repeating this summary.

Indicator window: 62 dated facts in September 2026 · 1 without confirmed date (excluded from the indicators). Facts from earlier months are used only as comparative context in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Verified Signal Monthly Dashboard September 2026 · Chile Primary threat: Ransomware (17 of 62 events). Coverage: 62 dated events in September 2026 · 1 undated c… VERIFIED EVENTS 62 period baseline: all counts measured from the bottom on this total RANSOMWARE / EXTORTION 17 1 unencrypted exfiltration (simple extortion) · 5 only listed on leak site · 11 UNCLASSIFIED INCIDENTS 14 breaches or outages without stated threat type FRAUD / PHISHING 6 documented fraud campaigns documented REGULATION 11 rules, resolutions, or sanctions UNIQUE CVEs 0 none in the analyzed material (does not imply absence in the region)
Verified Signal Monthly Dashboard — Base: 62 verified dated events in Chile for the period.
MONTHLY FIXED MODULE Threat axis distribution September 2026 · Chile Each event is counted in only one axis, so the total is exactly 62. "Unclassified incidents" is the remainder. Ransomware 17 Incidents 14 Unclassified 12 Regulation 11 Fraud 6 Vulnerabilities 2
Threat axis distribution — Each event is assigned to a single axis based on its classification; the total reconciles to the 62 events in the period.
FIXED MONTHLY MODULE Sectoral Signal Distribution September 2026 · Chile Base: 62 incidents in the period · total 76 because 14 incidents are classified in more than one sector. Public sector / OIV 24 Other / unidentified sector… 22 Finance 8 Telecom 7 Health 6 Retail / Consumer 4 Technology 3 Energy 2
Sectoral Signal Distribution — Heuristic sector classification of the victim. One incident may affect more than one sector, so totals may exceed the base.
MONTHLY FIXED MODULE Distribution of CII in Chile September 2026 · Chile 11 of 62 incidents in the period involve critical infrastructure. An incident may appear in more than one category. Public sector / government 22 CII mentioned 3 Energy / utilities 2 Telecom / connectivity 5
Distribution of CII in Chile — Verified incidents linked to critical infrastructure operators or the critical public sector

Executive monthly overview for Chile

September closed in Chile with ransomware as the dominant threat, 17 cases out of 62 verified incidents during the period, while the regulatory front remained highly active and fraud took on greater operational weight. The month brought incidents in health care, retail, manufacturing, finance, and the public sector, with 14 incidents unclassified and 6 documented fraud or phishing cases.

The most sensitive case was the one involving Hospital Clínico de la Universidad de Chile, which confirmed a cyberattack with a leak of confidential medical information and led to a criminal complaint. That was joined by the incident reported by Forus to the CMF, the ransomware attack on Fosko, activity from several leak-site campaigns against Chilean companies, and Operación Rutify, which exposed a network dedicated to extracting and selling personal data from public and private entities.

At the same time, the country advanced several major regulatory milestones. The regulation for Decree No. 662 on prevention models for data protection violations was published, the bill delaying the effective date of Law 21.719 continued its legislative process, and debate continued around the Framework Cybersecurity Law, strengthened authentication in payment methods, and new initiatives on bots, disinformation, and deepfakes.

The month’s risk reading is high. That is due not only to the volume of incidents, but also to the combination of data exposure, regulatory pressure, and active fraud campaigns. The material also shows a broad attack surface across health care, finance, retail, critical infrastructure, and public administration, with consistent signs that the problem is no longer just technical prevention, but coordinated response and cross-cutting compliance.

National overview for the month in Chile

Chile saw a concentration of signals in September across three fronts: intrusions affecting confidentiality, ransomware or extortion against organizations in multiple sectors, and a heavy legislative push on personal data, cybersecurity, and digital fraud. The dominant pattern was mixed, but ransomware led in mentions and carried the most weight in public and technical discussion.

The month’s evidence points to elevated risk because the signal was not limited to one type of actor or one sector. Health care, retail, manufacturing, financial services, public agencies, telecoms, and digital platforms were all affected. In addition, 60% of the events were directly confirmed by the source, which gives reasonable support for concluding that the month was marked by real incidents, not just monitoring noise.

There was also a clear convergence between fraud and tougher regulation. The National CSIRT issued alerts on active campaigns impersonating well-known brands, the Central Bank warned about financial deepfakes, the ABIF signed an agreement with Microsoft against digital fraud, and the CMF kept reshaping authentication and reporting requirements. That puts banks, fintechs, merchants, and payment service providers under greater operational pressure than in August.

At the regional level, Chile was not isolated. The discussion on ransomware, active exploitation, and AI-assisted fraud drew on alerts and analysis from Brazil, Ecuador, Taiwan, Japan, and global vendors.

Chile, septiembre 2026, hitos de riesgo y regulaciónTimeline with major incidents and regulatory milestones in September 2026 for Chile.Rutify 2SepANCIOAuth alertForus 15 SepDecree662Hospital 30SepFraudactiveMost visible events of the monthOperational risk, fraud and regulation

Chile, September 2026, risk and regulatory milestones — Timeline of the month’s most visible events: incidents, active fraud, and regulation.

Chile period indicators

Indicator Value Previous month Change
Verified facts for the period 62 76 -14
Indicator time window 62 facts dated September 2026 · 1 without confirmed date (excluded from indicators) 76 facts dated August 2026 · 0 without confirmed date n/d
Unclassified incidents (breaches or outages) 14 16 -2
Cases with ransomware or extortion as the primary focus 17 24 -7
Unencrypted exfiltration (simple extortion) 1 n/d n/d
Leak site mention only 5 n/d n/d
Classification not determinable from the material 11 n/d n/d
Documented fraud or phishing cases 6 2 +4
Documented regulatory moves 11 16 -5
Critical CVEs mentioned 0, none in the analyzed material, does not imply absence in the region n/d n/d
Sectors with at least one documented fact 8 8 unchanged
Dominant threat of the month Ransomware (17 of 62 facts) Ransomware (24 of 76 facts) remains dominant
Facts with direct source confirmation 60% n/d n/d
Chile, distribución verificada por eje principalBar chart with verified incident counts by main threat axis in September 2026.Distribution by main themeVerified facts from the period in Chile17641RansomwareFraudIncidentsCVE
Chile, verified breakdown by main theme — Visual comparison of the threat themes that dominated the month in the analyzed material.

Relevant incidents in Chile

Hospital Clínico de la Universidad de Chile, cyberattack with medical data exposure

Hospital Clínico de la Universidad de Chile confirmed a cyberattack that affected its Imaging Service, enabled unauthorized access, and exposed confidential patient medical information. The institution filed a criminal complaint, and ANCI notified it of the incident on September 20, putting the health sector back among the most sensitive areas of the month.

The case stands out because of the type of data compromised and the operational and reputational impact it can have on a public university hospital. It also fits the month’s sector view, where health appears as a critical surface for ransomware, data leaks, and regulatory pressure.

Forus, contained incident with partial operational impact

Forus told the CMF that it learned on September 15 of a cybersecurity incident caused by an external actor that affected some of its computer systems. The company said its store network was operating normally, although other sales channels were showing intermittent recovery issues, and it stated that no personal data had been affected.

The available evidence supports a contained incident with partial operational impact, not a confirmed personal data breach. In open monitoring ecosystems, several sources linked the case to a leak site, but the verifiable material for the period remains at the level of a reported incident to the regulator and an unconfirmed public attribution.

Fosko, ransomware with encryption and backup recovery

Fosko S.A. faced a ransomware attack that compromised production equipment and shared files. TrendTIC added that two workstations were encrypted and a server was partially affected, while the company isolated devices, did not pay a ransom, and prioritized restoring backups.

This case shows a clearer operational impact than other mentions this month, because the source describes confirmed encryption and containment response. Public attribution to LockBit 3.0 appears in the coverage, but the material also leaves room to distinguish between what the victim confirmed and what third-party intelligence reported.

Operation Rutify, massive data leak from public agencies

Operation Rutify led to the dismantling of a network that extracted personal data from public and private institutions, with mentions of Fonasa, Sernac, Tesorería, IPS, Servel, the Secretaría de Gobierno Digital, and the Municipality of Las Condes. The investigation pointed to a scheme of illicit access, mass extraction, and sale of data to third parties.

This was not a ransomware case, but one of theft and exploitation of information at scale. Its significance in September is that it showed sustained capability to extract sensitive data from institutional environments and reinforced pressure on authentication controls, exposed surfaces, and access monitoring.

CSIRT Nacional, active fraud campaigns impersonating well-known brands

Between September 21 and 22, CSIRT Nacional issued alerts about ongoing fraudulent campaigns impersonating Gacel, Entel, Autofin, Walmart, and GTD Telsur. The communication treated them as active campaigns and provided detection guidance.

The relevance of the case is that it confirms phishing and fraud activity in an operational state, not just generic warnings. It also aligns with other signals from the month, such as the Central Bank’s warning about fraud with AI-generated video and T13’s alert on SIM swapping.

Anci, alert on abuse of OAuth Device Code in Microsoft

ANCI issued a technical alert on abuse of the OAuth Device Code flow in Microsoft Entra ID and Microsoft 365. According to the agency, attackers can compromise accounts without directly stealing passwords, by authorizing malicious applications.

The signal is not a classic CVE vulnerability, but it is a phishing and authentication abuse technique with concrete impact on corporate accounts. For Chile, the issue matters because it connects identity, cloud, and fraud, three vectors that appeared repeatedly during the period.

Threats and active campaigns in Chile

Ransomware and extortion in Chile

September recorded 17 cases with ransomware or extortion as the main focus, with most cases falling into a category where the source does not clearly show whether there was encryption, exfiltration, or only a claim on a leak site. In practice, the picture was dominated by the public visibility of leak sites and by a few incidents with real operational impact.

Among confirmed encryption cases, Fosko stands out. Cases limited to mention on a leak site include Forus, Tanner, Vigatec, S.A. Chile, and other incidents linked by third parties or tracking repositories. Several other events remain uncategorizable because the material does not clarify whether there was encryption, exfiltration, or both.

The case of Hospital Clínico de la Universidad de Chile deserves separate mention even though it does not fit the taxonomy perfectly, because the source describes a cyberattack with medical data leakage and, in the tracking ecosystem, it was linked to ransomware. From a risk perspective, the key point is that health care remained a high-value target for extortion actors.

Fraud and phishing in Chile

The 6 documented fraud or phishing cases confirm that September was a more active month than August in this area. The Central Bank warned about a deepfake video impersonating its president, ANCI warned about abuse of OAuth Device Code Flow, T13 described the SIM swapping method, and the National CSIRT detected active brand impersonation campaigns.

Also noteworthy is the continued banking scam that uses the RUT to block accounts and then asks for verification codes, along with the public debate over bots and disinformation. The combination matters because it brings together classic social engineering, identity abuse, and automation, without relying on sophisticated malware.

APT and hacktivism in Chile

The material did not include any clear case that would allow APT to be classified with confidence for September. There were digital manipulation campaigns, bots, disinformation, and coordinated operations on social networks, but the period’s corpus points more to fraud, extortion, and data theft than to a classic APT campaign against Chilean targets.

The regulatory and political context around bot farms, deepfakes, and public opinion manipulation is strong. But based on the evidence available, it should be treated as a front of disinformation and abusive automation, not as a consolidated APT attribution.

Critical vulnerabilities affecting Chile

CVE Software Exploitation Source
CVE-2026-85706 GitLab CE/EE Unauthenticated arbitrary local file read; patches released on September 10, 2026 GitHub Security Advisories, INCIBE-CERT
CVE-2026-93577 GitLab An authenticated user could execute arbitrary code on a GitLab server under certain conditions CVE.org, GitLab
CVE-2026-89078 GitLab An authenticated user could execute arbitrary code on a GitLab server under certain conditions CVE.org, GitLab
CVE-2025-20265 Fortinet Active exploitation of an authentication bypass, reported in a CISC Brazil bulletin CISC Brasil
CVE-2026-67276 MikroTik RouterOS SSH authentication bypass, part of the MikroTrick chain, with active exploitation in the region NICS-TW, DIVD, HawkEye
CVE-2026-86060 MikroTik RouterOS Active exploitation, privilege escalation, and part of the MikroTrick chain NICS-TW, DIVD, HawkEye

No critical CVEs were reported in the Chilean material for the period, but there were relevant alerts in the region and in products used by local organizations, especially GitLab, Cisco, Ivanti, Fortinet, and MikroTik.

Regulation and compliance in Chile

Chile closed September with a dense regulatory agenda covering data protection, cybersecurity, payment systems, and digital environments. The most important item was Decree No. 662, published on September 9, which approves the regulation on infringement prevention models in personal data protection under Law 21.719.

The regulation sets requirements, modalities, and procedures for implementing, certifying, registering, and supervising those models. At the same time, the government submitted to the Senate the bill that would delay the entry into force of Law 21.719 by one year, while public debate continued to stress that the postponement had not been approved by month-end.

On the sector side, the Cybersecurity Framework Law 21.663 kept rolling out obligations for operators of vital importance and essential service providers. The month’s material highlighted 3-hour deadlines for early warning, 72 hours for the first assessment, and 15 days for the final report, in addition to the obligation to report incidents to the National CSIRT.

Payments regulation also kept moving. The CMF tightened authentication requirements, and debate over the MK4 reform reshaped liability for fraud. At the same time, the reserve of vehicle data used in covert police operations and the bills on digital manipulation, bots, and deepfakes show a broader regulatory perimeter around data and content.

Regulatory milestones for the month

Date Milestone Scope
2026-09-01 Senate filing of the bill delaying Law 21.719 Personal data and the new Agency
2026-09-09 Publication of Decree No. 662 Infringement prevention models
2026-09-14 Debate on MK4 reform and strengthened authentication Fraud in payment systems
2026-09-16 Bill on digital manipulation and bot farms Disinformation and automation
2026-09-23 Bill to reserve data from police vehicles Protection of sensitive information
2026-09-26 Deepfake bill under consideration AI-generated content

Compliance implications

The month’s regulatory signal pushes organizations to review data inventories, legal bases, access controls, traceability, retention, and incident response. The material shows that compliance within a single framework is no longer enough, because one event can trigger obligations across personal data, cybersecurity, and financial fraud.

In banking and payment services, the convergence of stronger authentication, user liability presumptions in certain cases, and AI-assisted fraud channels requires legal, fraud, technology, and security teams to align. In health care and the public sector, the pressure comes from operational continuity, protection of sensitive data, and the ability to notify promptly.

Most affected sectors in Chile

Health, finance, the public sector, and retail concentrated the month’s most sensitive signal, although the distribution was not exclusive and several incidents cut across more than one sector at a time. Health stood out because of the Hospital Clínico de la Universidad de Chile case and the debate over ransomware with catastrophic reach. Finance came under pressure from fraud, authentication, and phishing campaigns.

In the public sector, Operación Rutify showed a massive extraction of information from multiple agencies. In retail, Forus added a contained incident that affected sales channels. In manufacturing, Fosko showed that ransomware is still hitting production continuity, not just administrative systems.

There was also a signal in telecommunications and digital platforms because of the debate over interception, jammers, bots, and deepfakes. That overlap matters because it expands the exposure set beyond the sectors usually seen as most sensitive and shifts attention toward reputation, identity, and content.

The sector-by-sector risk picture is that health and finance remain the areas under the heaviest combined pressure from confidentiality, continuity, and regulation. But the month made clear that digital government, retail, and manufacturing are also within reach of opportunistic campaigns or actors seeking extortion.

Compared with August, September recorded fewer verified incidents overall, fewer unclassified incidents, and fewer cases where ransomware or extortion was the primary focus. Even so, documented fraud and phishing cases rose from 2 to 6, and the month shifted more toward identity abuse, impersonation, and active deception campaigns.

The regulatory trend also changed shape. In August, pressure around data and cybersecurity was already building, but in September it hardened into regulations, bills under review, technical alerts, and new debates over liability. Law 21.719, the Framework Cybersecurity Law, and the strengthened authentication rules continued to set the agenda.

In ransomware, the monthly picture shows a decline from August, although the problem did not go away. It kept appearing in multiple forms, from cases with confirmed encryption to simple mentions on leak sites. For operational monitoring, that means not overreacting to every claim, but also not underestimating the broader pattern.

The most important signal to watch in October is the convergence of fraud, identity, and automation. The Central Bank case, alerts from the National CSIRT, SIM swapping, and OAuth abuse show that an attacker does not necessarily need to exploit a CVE to compromise an account, drain a channel, or erode trust.

Recommendations for security teams in Chile

Review incident response processes so a single event can trigger technical, legal, and regulatory notifications without duplication or gaps. The combination of the Cybersecurity Framework Law, the future data authority, and sector-specific obligations calls for coordinated playbooks and clear timelines.

Prioritize identity controls. This month's material shows abuse of OAuth, SIM swapping, brand impersonation, and financial deepfakes. Phishing-resistant MFA, validation of sensitive changes through separate channels, and monitoring for authentication anomalies should be at the top of the list.

Harden the exposed attack surface on collaboration and development platforms, especially GitLab, and keep patching cycles short for software with active exploitation or recently fixed critical flaws. Although there were no critical Chilean CVEs this month, there was relevant indirect exposure through vendors and tools used locally.

Operationally separate plans for encryption, extortion without encryption, and leak sites. September's material made clear that not every case attributed to ransomware amounts to a confirmed intrusion with operational impact. That distinction improves prioritization and avoids rushed decisions.

Strengthen inventory, classification, and retention of personal data, especially in health care, finance, retail, and the public sector. Operation Rutify and the case of the Hospital Clínico de la Universidad de Chile show that the value of data remains the center of gravity of risk.

Frequently Asked Questions

What is the difference between the September ransomware cases and active fraud?

In September there were 17 cases with ransomware or extortion as the primary focus and 6 documented fraud or phishing cases. The first group ranged from confirmed encryption, as in Fosko, to simple mentions on leak sites, while the second centered on impersonation, SIM swapping, deepfakes, and authentication abuse.

Which sectors should prioritize immediate action after this month?

Health care, finance, the public sector, and retail were the most pressured by events during the period, although several incidents affected more than one sector. Health care because of medical data exposure, finance because of fraud and authentication, the public sector because of Rutify, and retail because of the Forus case are the clearest priorities.

How does the regulatory agenda intersect with operational incidents?

The overlap is direct: Law 21.719 pushes controls over personal data, the Cybersecurity Framework Law requires reporting and incident handling, and the CMF deepens authentication and fraud responsibilities. A single event can trigger different obligations depending on the type of data, system, and sector involved.

Why does the report insist on distinguishing leak sites, exfiltration, and encryption?

Because they do not carry the same operational impact or the same legal weight. A mention on a leak site may be only a claim, exfiltration without encryption points to simple extortion, and confirmed encryption implies service disruption or degradation. Mixing them distorts the risk picture.

What should a team in Chile review this week?

It should review phishing-resistant MFA, cross-notification procedures, exposure of critical software such as GitLab, and response plans for fraud involving compromised identities. It is also worth validating inventories of personal data, because September showed that regulatory pressure and technical pressure are already overlapping.

Material limitations

This report was built exclusively from the material provided for Chile in September 2026. The indicator window is the one stated at the start, 62 dated facts in September 2026, plus 1 undated fact that was excluded from the indicators. No internet or external information was used.

An indicator at 0, especially in the critical CVEs mentioned, means it did not appear in the material analyzed for the period. It does not mean there were no critical vulnerabilities or active exploitation in the region. In fact, the corpus does include relevant alerts outside Chile that provide context, but they do not change the national indicator value.

Undated facts may be used only as qualitative context. In this case, the undated material was not counted in the indicators. Aggregated telemetry, or automated attempts and blocks treated as incidents, were also excluded.

Consumption sources and content excluded under editorial criteria when they were not on the allowed list were left out of the count, along with LinkedIn posts and other social networks not enabled as evidence. Where a source showed uncertain attribution, the report treated it as such and did not elevate it to confirmation.

Frequently Asked Questions

What changed between August and September in ransomware, fraud, and regulation in Chile?

September saw fewer total incidents than August. The volume of ransomware or extortion dropped, and unclassified incidents also declined, but fraud or phishing cases increased. At the same time, regulation gained weight with the implementing rules for Decree 662, the bill to extend Law 21.719, and new proposals on bots and deepfakes.

What is the relationship between the Rutify case and the Hospital Clínico de la Universidad de Chile?

Both show the value of data as a central target, but they stem from different vectors. Rutify was a mass data extraction and resale operation involving multiple agencies, while the hospital confirmed a cyberattack with a leak of confidential medical information. Together, they explain why health care and the public sector were so exposed.

What should banks and fintechs prioritize in light of what happened this month?

They should strengthen phishing-resistant authentication, review credential-change processes, monitor SIM swapping, and align legal and technical response to fraud. The month combined deepfakes, impersonation campaigns, OAuth abuse, and regulatory changes from the CMF, so identity and traceability move to the forefront.

Why does the report not treat every mention on leak sites as a confirmed incident?

Because many are only claims from ransomware groups or third-party trackers. Without confirmation from the victim, without technical data, and without evidence of operational impact, the material should be treated as a leak site mention. That distinction avoids artificially inflating the month’s severity.

What regulatory signal should be watched closely in October?

The effective entry into force of Law 21.719 and the progress of the extension bill, together with implementation of the rules under Decree 662. In parallel, developments on fraud in payment media, police data confidentiality, and projects linked to bots and AI-generated content should also be tracked.

Does zero critical CVEs mean there were no serious vulnerabilities in the region?

No. It means that no critical CVEs appeared in the material analyzed for Chile in September. The corpus does include critical advisories and active exploitation in other countries and products, but they were not recorded as a Chilean signal for the period within the sample used for this report.

Material limitations

This report is limited to the material provided for Chile and to the September 2026 period. The indicators are calculated only from the 62 events dated within that period, while 1 event with no confirmed date was excluded from all metrics. No aggregated telemetry was available to convert attempts or blocks into incidents.

A value of 0 in an indicator, especially in mentioned critical CVEs, means it did not appear in the material analyzed for the month. It does not mean there were no vulnerabilities or active exploitation in the region. The corpus does include comparative references outside Chile, but they are not included in the national count.

Sources excluded by editorial rule were not used as evidence, and mentions in unapproved social media channels were also left out of the analytical body. When a source showed uncertain attribution or opaque methodology, it was treated as such and was not elevated to direct confirmation.

The final result therefore reflects only what was actually verified in the document set provided, not the full universe of incidents that may have occurred in Chile or the region during September.

Sources