Peru: cybersecurity landscape, July 2026
Ransomware led July in Peru: 25 of 47 incidents. Two cases were verifiable, along with one regulatory alert and strong pressure on the financial sector.
Key findings
- Ransomware was the dominant threat in July, with 25 of 47 verified incidents.
- Ingemmet was the clearest operational incident, suspending Petitorio Online after a ransomware attack.
- Famesa, Triton Trading, and Marpatech appeared on leak sites, but in several cases the type of impact could not be determined with certainty.
- SBS 01741-2026 and BCRP rules raised the standard for reporting, continuity, and third-party controls in the financial sector.
- Phishing and identity impersonation remained central vectors, with a focus on financial services.
- No new critical CVEs were recorded in the analyzed material, although exploitation of older flaws such as CVE-2017-0199 persisted.
- The risk reading for Peru in July is high because of the combination of digital extortion, confirmed operational impact, and regulatory pressure.
Monthly reference modules
These modules are completed automatically with the verified, dated facts within the period. Each one states its basis and counting criterion, so the figures reconcile across modules. They are the recurring month-to-month reading; the later analysis develops the cases without repeating this summary.
Indicator window: 58 dated facts in July 2026. Facts from prior months are used only as comparative context in the analysis, never as volume for this period.
Monthly Executive Summary for Peru
July ended in Peru with a clear signal: ransomware was the dominant theme of the month, accounting for 25 of 47 verified incidents within the analysis window. That dominance sat alongside a broader set of operational, regulatory, and awareness-related signals, but the period’s main takeaway is unmistakable. There were two verifiable cases with clear operational impact or public claims, Ingemmet and Famesa, while the rest of the extortion claims fall into a partial classification zone, with several sources only confirming presence on leak sites or statements from the actors involved.
The Ingemmet case was the most concrete in terms of impact. The National Digital Security Center of the PCM reported that ransomware affected the agency’s digital services, suspended Petitorio Online, and forced a return to in-person intake for mining petitions. The same source said geological and mining information remained protected and that no ransom was paid, which makes this a confirmed operational incident rather than a simple public claim. SIDEMCAT was back online the following day, although the affected service remained suspended longer.
At the same time, Famesa was claimed by Qilin on leak sites and specialized aggregators, but the available material is not enough to say with confidence whether there was encryption, exfiltration without encryption, or only publication on a leak site. What the source does make clear is that this was an unverified public claim not confirmed through official channels. That distinction matters, because July saw a large volume of ransomware cases whose true severity cannot be precisely determined from the available material.
On the regulatory front, the most relevant signal was Resolution SBS No. 01741-2026, which strengthened the obligations of banks, savings institutions, and finance companies to report cybersecurity and business continuity incidents, with public notice within 24 hours and direct notification to customers within 10 business days. Added to that was the BCRP’s new framework for instant payments using aliases, which expands the scope to banks, fintechs, digital wallets, and savings institutions, and includes requirements for risk management, information security, data protection, and operational continuity. In a month marked by multiple ransomware claims and public attention on digital fraud, the regulatory shift pushes greater operational maturity, although it also raises compliance costs for the financial ecosystem.
The third major signal was the persistence of phishing and social engineering as the main attack vector. ESET data published by local media places more than 45% of the year’s detections in campaigns involving deception, malicious scripts, and downloaders. That view aligns with the SBS warning on identity theft in financial products, which cites phishing and phone calls as entry points for unauthorized banking transactions. The month did not produce a large number of documented fraud cases, only two, but it did confirm that the operational environment remains favorable for attacks that begin with user manipulation.
Peru country risk overview for the month
Peru's risk reading in July is high. Not because the absolute volume of incidents is extraordinary compared with other months of the year, but because the mix of dominant ransomware, two incidents with clear claims or operational impact, signs of leaks involving organizations in the country, and regulatory changes aimed at resilience and 24-hour reporting creates sustained pressure on the public sector and the financial sector. The structural point is that most of the signals are not isolated noise, but campaigns driven by extortion logic, attempts at access through social engineering, and governance and patching failures that continue to appear as enablers.
The Latin American backdrop supports that reading. The month's material does not show additional verifiable events for the regional regulatory axis, but it does point to a broader pattern, digital extortion groups continue to operate against victims in several countries and maintain a presence on leak sites that cross borders. Peru was not outside that dynamic, with claims attributed to Qilin, Nova and thegentlemen, plus one state victim and an industrial firm with a regional footprint. The most relevant risk issue is that part of that exposure is concentrated in sectors with sensitive operational continuity and immediate reputational impact.
Peru threat indicators for the period
| Indicator | Value | Base / note |
|---|---|---|
| Verified events for the period | 47 | Base for all indicators, calculated only from dated events within July 2026 |
| Time window for the indicators | 58 events | Events dated in July 2026 |
| Unclassified incidents | 14 | Breaches or outages |
| Cases with ransomware or extortion as the primary focus | 25 | Main threat of the month |
| Exfiltration without encryption, simple extortion | 2 | Ransomware breakdown by impact type |
| Leak site mention only | 4 | Ransomware breakdown by impact type |
| Type could not be determined from the material | 19 | Ransomware breakdown by impact type |
| Documented fraud or phishing cases | 2 | Previous month comparison: 4, variation -2 |
| Documented regulatory moves | 1 | Previous month comparison: 10, variation -9 |
| Critical CVEs mentioned | 0 | None in the material analyzed, which does not imply absence in the region |
| Sectors with at least one documented event | 6 | Previous month comparison: 7, variation -1 |
| Main threat of the month | Ransomware | 25 of 47 events |
| Events with direct source confirmation | 60% | Direct confirmation in the source |
| Aggregated telemetry figures excluded from the volume | 11 | Aggregated attempts or blocks, not incidents with confirmed impact |
Relevant Incidents in Peru
Ingemmet and the Petitorio Online outage
The month’s clearest case involved the Geological, Mining and Metallurgical Institute. PCM said a ransomware attack hit its digital services, forced the suspension of Petitorio Online, and shifted mining petition intake back to in-person processing. The same statement said the country’s geological and mining information was protected, and added that the complaint was filed with Divindat of the PNP. It also said the state ruled out paying a ransom.
That set of signals makes it the period’s most operationally clear incident. There is no ambiguity about the service impact, and none about the initial institutional response. SIDEMCAT resumed operations on July 19, but the core service was still suspended on that date. For defense teams, the case leaves a simple, hard lesson: when ransomware hits a public filing service, the cost is not just lost availability, but administrative friction that forces a return to manual processes.
Famesa and Qilin’s public claim
Famesa was claimed by Qilin on the leak site and in several monitoring aggregators. The available material confirms the company’s appearance on the leak site and its association with Peru, with discovery dated July 19 at 09:05 UTC. However, the public evidence does not allow the impact to be classified with confidence. Some sources mention exfiltration of internal files, others only record the leak site post, and several stress that this is an unverified claim.
That is why the case should be read cautiously. There is not enough basis to say encryption was confirmed, nor to treat any exfiltration scope as established. What is recorded is the actor’s reputational pressure and the confirmation that a Peruvian company was again exposed in the economy of digital extortion. From a response perspective, these cases require playbooks for handling public claims, reviewing leak monitoring, and preparing legal and crisis communications before full validation exists.
Marpatech and Nova’s claim
Marpatech surfaced in the leak ecosystem as a Nova victim. Ransomware.live identified it as a target with a discovery date of July 22, and Galaxy Warden said the leak site entry indicates exfiltration of internal files, though without quantifying the volume. BreachSense, meanwhile, referred to a data leak, but without additional official support. The story is another example of a month crowded with public marks of digital extortion, with uneven levels of verification.
Triton Trading and Qilin’s post
The Triton Trading case, a financial services company, was also recorded by Qilin on its leak site and by Ransomware.live. Discovery was set for July 23, and the aggregators placed it in Peru. Unlike Ingemmet, there is no official sign of operational impact. Unlike Famesa, the leak coverage is more consistent, but the key point remains unresolved, what damage actually occurred and whether the public evidence goes beyond the actor’s claim.
Threats and active campaigns in Peru
Ransomware and extortion, with confirmed impact, public mention, and uncertain classification
The month was marked by a broad digital extortion campaign, but the quality of the evidence varies widely. Ingemmet is the only case with confirmed operational impact in the official source available. Famesa, Marpatech and Triton Trading appear at different levels of publication on leak sites and aggregators. At the same time, Ransomware.live also links Peru to Rhysida claims and references to public entities, although in that case the assessment remains at the level of actor attribution, not impact.
| Case | Type of impact according to the material | Verification status | Main source |
|---|---|---|---|
| Ingemmet | Operational disruption by ransomware | Confirmed | Tu Diario Huánuco, based on the CNSD of the PCM |
| Famesa | Cannot be determined from the material | Unverified public claim | Ransomware.live, Mallory.ai, RecentBreaches |
| Marpatech | Exfiltration without encryption, according to the leak site | Partially verified by aggregators | Ransomware.live, Galaxy Warden |
| Triton Trading | Leak site mention or public claim only | Partially verified by aggregators | Ransomware.live, HookPhish, Pulse |
| Government of Peru, MTC, other references | Cannot be determined from the material | Attributions from monitoring portals | Ransomware.live, Pulse |
Famesa, Qilin and the dispute over verification
The Famesa case deserves separate treatment because it concentrates much of the methodological ambiguity of the month. The monitoring portals agree on the Qilin claim, but there is no public confirmation from the company or Peruvian authorities in the available material. Some aggregators mention a screenshot from the leak site and others refer to exfiltration, but none provides enough elements to establish whether the incident involved encryption, leakage, or only publication of the claim.
That uncertainty does not diminish the news value. On the contrary, it points to an important trend: much of the damage in ransomware no longer depends only on service disruption, but on the pressure created by publishing the supposed victim. For security teams, that means looking not only at the technical intrusion, but also at reputation management, backup status, data traceability, and coordination with legal and institutional communications.
Marpatech and exfiltration as the main public narrative
Unlike Famesa, Marpatech does appear in the material with a more explicit mention of internal file exfiltration in the context of the Nova group. Even so, the public source does not allow the volume to be quantified or the legal scope of the leak to be established. That places it in the category of simple extortion or exfiltration without encryption, but always with the caveat that the final degree of confirmation remains partial.
Identity theft and financial fraud
The SBS warned in July about an increase in reports of digital fraud linked to identity theft. The described method was classic, but still very current: obtaining personal and financial data through phishing and phone calls, then carrying out bank transactions without the customer’s authorization. The report does not offer a final tally, but it does confirm that digital scams remained one of the most active attack surfaces of the month in the financial sector.
| Documented vector | Affected sector | Evidence for the month | Source |
|---|---|---|---|
| Phishing and phone calls | Financial | Increase in identity theft complaints | SBS |
| Unauthorized bank transactions | Financial | Digital fraud after data theft | SBS |
APT, espionage and underlying technical pressure
The month’s material does not provide a formally attributed APT case for Peru. There are signs of technical pressure and the persistence of advanced threats in the regional context, but no additional verifiable facts that would support a separate APT section with a concrete national incident. As a result, July in Peru is better described by digital extortion, phishing and regulatory tightening than by an end-to-end identified APT campaign.
Critical vulnerabilities affecting Peru
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| CVE-2017-0199 | Not specified in the material | Ongoing exploitation in Peru during 2026, within a set of flaws known since 2017 | Trujillo en Línea, based on ESET |
The material reviewed did not mention any new critical CVEs during the period, so the table contains a single record. That does not mean exploited vulnerabilities do not exist in the region, only that they did not appear in the dated July events included in this report.
Peru Regulation and Compliance
SBS 01741-2026 and stronger incident disclosure duties
Resolution SBS N.° 01741-2026 was the month’s most visible regulatory move. It amended the Market Conduct Management Regulation and tightened obligations for banks, savings banks, and finance companies on transparency, customer service, and operational and cybersecurity incident management. The most sensitive practical change is the 24-hour deadline for public disclosure of incidents, plus direct notice to affected customers within the next 10 business days when applicable.
| Obligation | Scope | Deadline | Source |
|---|---|---|---|
| Public disclosure of cybersecurity or continuity incidents | Banks, savings banks, and finance companies | Within 24 hours of the entity becoming aware | RPP Noticias, Nivel4 Blog |
| Direct notice to affected customers | Banks, savings banks, and finance companies | Within 10 business days, as a general rule | RPP Noticias, Nivel4 Blog |
| Human support alternative | Entities with automated systems | Immediate effect | RPP Noticias |
| Free debt regularization certificates | Financial entities | Immediate effect | RPP Noticias |
In parallel, several reports noted that most of the changes will only take effect 360 days after publication, opening a window to adjust processes, platforms, and systems. For security teams, the message is clear, responding well is no longer enough, they also need to document and communicate quickly, with legal traceability and operational capacity.
BaaS, instant payments, and a wider risk perimeter
Regulation for the Banking as a Service model and the Instant Payments Service with Alias expanded the regulatory perimeter. The BCRP requires directory providers and payment system entities to submit implementation, load testing, security, and continuity plans, along with incident management, communication, and reporting measures. It also requires actors that participate in prominent payment systems or agreements to seek authorization, while those involved in non-prominent agreements must register as Payment Services Entities.
| Regulatory rule or instrument | Main requirement | Date or deadline | Source |
|---|---|---|---|
| Circular N.° 0017-2026-BCRP | Risk management, information security, data protection, and operational continuity for directory providers | Formal publication and later compliance period | Actualidad Civil |
| Regulation for the Instant Payments Service with Alias | Instant transfers using alias, DNI, mobile number, or QR | Effective 60 days after publication | Infobae Perú, RPP Noticias |
| National Payments System Regulation | Authorization or registration as an ESP depending on the type of participation | Schedule between June and December 2026 | Gestión |
Beyond the technical language, the real impact is significant. The digital payments ecosystem is facing closer scrutiny of architecture, APIs, third parties, and continuity, at the same time the month shows signs of impersonation fraud and a clear persistence of phishing. For banks and fintechs, compliance is no longer just a legal task, it is also an operational condition for sustaining trust.
Corporate governance and cybersecurity in financial services
Coverage of BaaS and the new BCRP rules highlights suitability requirements for directors and major shareholders, a business plan with financial projections, and robust risk and continuity policies. Traxxia adds that this is driving deeper due diligence on recipient fintechs, with a focus on information security, scoring, and the use of open finance data. Not a number, but it is a signal for the month, third-party oversight moved higher on the compliance agenda.
Most affected sectors in Peru
The month recorded activity in six sectors with at least one documented incident. That points to a broad footprint, though not an even one. The real weight fell on the public sector, financial services, and the technology services ecosystem tied to both. Ingemmet, the Government of Peru, and references to the MTC appear in the ransomware and leak segment, banks, savings banks, finance companies, and digital wallets account for regulation and fraud, and service and manufacturing companies linked to regional supply chains round out the picture.
| Sector | Signal type | Relevant events this month |
|---|---|---|
| Public | Ransomware, leak site claims, national drill | Ingemmet, references to Government of Peru, SIMAC 2026 |
| Financial | Regulation, fraud, instant payments | SBS 01741-2026, BCRP, identity spoofing |
| Manufacturing / engineering | Ransomware and leaks | Famesa, Marpatech, Triton Trading |
| Technology / digital services | Incident response and cybersecurity | SIMAC 2026, BaaS, alias directories |
| Mining and related infrastructure | Operational disruption | Ingemmet and Petitorio Online |
| Commerce / payments ecosystem | Compliance and continuity | ESP, BaaS, payment aliases |
The sector breakdown shows a clear tilt toward activities that depend on availability and transactional trust. That explains why the most visible incidents and regulations touched the areas where an outage or a leak is most expensive, public procedures, payments, credit, identity, and institutional reputation.
Trends and signals to watch in Peru
The month-over-month comparison shows three concrete changes. First, documented fraud and phishing cases fell from 4 in the previous month to 2 in July. That does not mean structural relief, because the vector remains very present, but it does show fewer individually documented incidents in the available material. Second, regulatory moves dropped from 10 to 1, although the only one in July was deeper and more operational than several of the earlier ones: SBS 01741-2026 and the BCRP regulation change reporting rules, continuity requirements, and the compliance perimeter. Third, sectors with documented incidents fell from 7 to 6, with a sharper concentration in the public and financial sectors.
The dominant threat shifted from incidents in the previous month to ransomware in July. That change matters because it is not just a difference in labeling. In the previous month, the picture was more dispersed, while in July the volume is organized around digital extortion and its operational ripple effects. The result is a clearer surface for analysis: less noise, more pressure on specific organizations, and a greater need for fast response to public claims.
There is also a signal worth following closely, even if it does not translate into a single high-profile incident: the continued exploitation of older vulnerabilities dating back to 2017. The material does not introduce new critical CVEs, but it does reiterate that nearly 10% of detections in Peru exploit flaws known for years. That figure, combined with the persistence of phishing and the regulatory pressure on notification and continuity, suggests the main problem is not a lack of tools, but the gap between exposure and operational maturity.
Security recommendations for teams in Peru
- Review ransomware response procedures with a focus on service continuity, public communication, and legal coordination. The July cases show that the first critical decision is not always technical, it is also operational and reputational.
- Adjust leak and leak site playbooks. When the impact is unclear, as in Famesa or Triton Trading, the organization needs verification capability, evidence preservation, and a response to public pressure before it has the full picture.
- Prioritize strong authentication and identity spoofing monitoring in the financial sector. The SBS alert makes clear that phishing and calls remain effective vectors for unauthorized operations.
- Prepare teams for the new incident communication regime. The 24 hour window requires channels, spokespeople, templates, and classification criteria to be ready before the event.
- Review third parties, APIs, and technical dependencies in BaaS models, instant payments, and alias directories. Regulatory compliance will require evidence of information security, continuity, and testing.
- Keep patching and hardening systems exposed to exploitation of old flaws. The CVE-2017-0199 case shows that old exploits are still active and still have a market.
- Run tabletop exercises that bring together cybersecurity, operations, legal, and customer service. July made it very clear that incidents do not end in IT.
Material limits
This report was written exclusively from the material provided for July 2026 and considers only facts dated within that window. Facts from earlier months were used only for the explicit comparison requested, and were not added to the period total. Aggregated telemetry figures were excluded from the incident count because they reflect detections, attempts, or automated blocks, not intrusions with confirmed impact.
The critical CVE indicator is 0 in the analyzed material for the period. That means no new critical CVEs appeared in the July facts included here, not that no critical vulnerabilities were exploited in Peru or across the region. The same rule applies to other zeros or missing counts, they indicate no record in this month’s corpus, not the real absence of the phenomenon.
Sources not allowed under the editorial guidelines were also excluded, including consumer social networks, LinkedIn posts, and sponsored content when it functioned as advertising or a press release. References taken from ransomware monitoring portals, news outlets, official agencies, and regulatory documents were used only within the verification limits present in the material. When a ransomware claim was not confirmed by an official source, it was treated as such and not as a fully validated incident.
CHART placeholders
Technical limits of the corpus
The material does not include enough consistent IoCs, hashes, domains, or IPs published to build a solid technical annex without forcing interpretation. There is also no homogeneous set of TTPs accurately attributed to a single actor for the country during the period. For that reason, the technical annex of indicators of compromise and TTPs was omitted.
Operational closeout for Peru
July left Peru with an uneasy but clear mix: more ransomware pressure, tighter compliance demands, and a financial ecosystem entering a period of greater formalization of controls. The challenge is not only to detect more, but to respond better, document faster, and shorten the gap between an incident, the decision, and the communication.
Charts
Sources
- Claude Code para empresas en Perú: guía 2026Duotach
- El Consejo de Ministros de Perú acuerda las primeras medidas sobre seguridad y empleoInfobae (agencia EFE)
- Ejecutivo solicita facultades para legislar por 120 días: ¿qué materias están incluidas?Caretas
- Revise las principales normas legales publicadas del 19 al 25 de julio del 2026El Peruano
- Gobierno pide facultades legislativas en seguridad, economía y empleoLa Razón
- Ransomware incidents involving Peru (map view)ransomware.live
- La suplantación de identidad en productos financierosSuperintendencia de Banca, Seguros y AFP (SBS)
- Bancos, cajas y financieras deberán permitir transferencias inmediatas con número de celular, DNI o QR tras nueva norma del BCRPEnfoque Real
- Circular N.º 0017-2026-BCRPActualidad Civil
- Pagos instantáneos en Perú: BCRP dispone que todos los bancos acepten transferencias inmediatas con QR, DNI o celularInfobae Perú
- Más de 50 fintech serían supervisadas por el BCRP, ¿pasarán la prueba de fuego?Gestión
- El 2026 regulatorio cambió las reglas para fintech peruanasTraxxia
- SBS cambia las reglas para bancos, cajas y financieras - RPP NoticiasRPP Noticias
- Noticias - CiberLATAMCiberLATAM
- Bancos, cajas y financieras deberán permitir transferencias inmediatas con número de celular, DNI o QR tras nueva norma del BCRPRPP Noticias
- Perú establece su primer marco regulatorio para el modelo de Banking as a Service (BaaS)LinkedIn
- SBS regula el Banking as a Service (BaaS): ¿qué es y cómo cambiará a los bancos en Perú?La República
- SBS impone nuevas reglas a bancos y financieras: así cambiará la atención al clientePerú Retail
- Entidades financieras del Perú deberán informar oportunamente incidentes que afecten a sus clientesNivel4 Blog
- Comentario sobre Resolución SBS 01741-2026 y protección de usuarios financierosLP Derecho / Estudio Camus y Márquez Abogados
- Perú superó más de 350 mil amenazas digitales en lo que va del 2026PressPeru
- Falta de actualización y deficiencia técnica en el Perú aumenta riesgo de ciberataquesHuaraz en Línea
- Perú realizará cuarto simulacro nacional de ciberataques para fortalecer la seguridad digitalEl Peruano
- Perú realizará cuarto simulacro nacional de ciberataques para fortalecer la seguridad digital del paísDesde Adentro
- Qilin Ransomware Attack Targets Famesa in PeruDexpose
- 77 victims for PeruRansomware.live
- Perú superó más de 350 mil amenazas digitales en lo que va de 2026 y crecen las operaciones de ciberespionaje en la regiónGadgerss
- ESET lanza su informe de amenazas del primer semestre de 2026: La IA aumenta la eficiencia de los ciberatacantesBusiness Empresarial
- Simulacro de Ataques Cibernéticos 2026PCM – Gob.pe
- Ciclo de Entrenamiento en Gestión de Incidentes y Simulacro de CiberataquesPCM – Gob.pe
- Perú realizará cuarto simulacro nacional de ciberataques para fortalecer la seguridad digitalNotiPeru
- Perú pone a prueba defensa digital por ciberataqueCentral de Noticias NET
- Taller 5 [SIMAC2026]: CSIRT Planes de Respuesta y Recuperación ante IncidentesPCM – YouTube
- Ransomware Group Qilin Hits: FamesaHookphish
- Victim: FamesaRansomware.live
- Qilin Leads Global Ransomware Victim Claims Across ...Mallory.ai
- Famesa — QILIN Ransomware AttackBreach House
- Famesa Data Breach (2026) — What Leaked & Am I Affected?RecentBreaches
- Famesa Data Breach in 2026BreachSense
- Famesa — claimed by qilinPulse
- Qilin Ransomware Attackers Exploit PAN-OS ...The Hacker News
- Bitdefender Threat Debrief | July 2026Bitdefender
- Simulacro de Ataques Cibernéticos 2026 - OrientaciónGob.pe
- Perú realizará cuarto simulacro nacional de ciberataques para fortalecer la seguridad digital del paísTVPerú
- Más de 350 mil detecciones de ciberataques en Perú de enero a mayo de 2026Agencia Andina
- El Perú superó más de 350 mil amenazas digitales en lo que va de 2026Forbes Perú
- Inteligencia artificial incrementa ciberataques en Perú: más de 350 mil amenazas digitales registradas en 2026Diario Viral
- Perú Blockchain Conference: Alertan sobre incremento en ciberdelitos impulsados por IA y criptomonedasDiarioBitcoin
- Qilin Ransomware Attack Targets Famesa in PeruMalware.news
- Ransomware Group qilin Hits: Triton TradingHookPhish
- Respuesta del Centro Nacional de Seguridad Digital ante ciberataques en PerúTu Diario Huánuco
- Falta de actualización y deficiencia técnica en el Perú aumenta riesgo de ciberataquesTrujillo en Línea
- Alerta integrada de seguridad digital N° 112-2026-CNSDGobierno del Perú
- Victim: Upanal CNC SolutionsRansomware.live
- Triton Trading — QILIN Ransomware Attack | Breach HouseBreach House
- Qilin ransomware publishes Peruvian company Triton TradingPulse (Kalir.io)
- Triton TradingBreachSense
- Manufacturing / Engineering Ransomware Victims & DataBreachou.se
- Nova Ransomware Attack Targets Marpatech in PeruDexpose.io
- Victim: MarpatechRansomware.live
- Marpatech Listed by nova Ransomware GroupGalaxy Warden
- Marpatech Data Breach in 2026BreachSense
- Nova · Ransomware Wing · PulsePulse (Kalir.io)
- Filtración de base de datos de licencias de conducir del Gobierno PeruanoPulse (Kalir.io)
- Ministerio de Transportes y Comunicaciones - MTCGobierno del Perú – MTC
- Licencia de conducir - Categorías - Ministerio de Transportes y ComunicacionesGobierno del Perú – MTC
- Consulta de licencia de conducir y récord MTC por DNITramitaPeru.com
- Qilin - Threat Actor ProfileMallory.ai
