CiberLATAMbywhalemate
Intelligence report

Peru Cybersecurity Situation, September 2026

Peru closed September with 48 verified incidents, focused on ransomware, insider fraud, and SBS rules on incidents and digital payments.

Oct 1, 202618 min read
Peru Cybersecurity Situation, September 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are populated automatically with verified dated facts within the period. Each one states its basis and counting criteria so the figures reconcile across modules. They are the recurring month-to-month readout; the analysis that follows develops the cases without repeating this summary.

Indicator window: 50 dated facts in September 2026 · 1 after the period (excluded). Facts from earlier months are used only as comparative context in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Monthly verified signal dashboard September 2026 · Peru Dominant threat: Unclassified (20 of 48 incidents). Coverage: 50 dated incidents in September 2026 · 1 post… VERIFIED INCIDENTS 48 period base: all counts measured from below on this total RANSOMWARE / EXTORTION 13 4 exfiltration without encryption (simple extortion) · 2 only named on leak site · 7 UNCLASSIFIED INCIDENTS 7 breaches or outages without threat type stated FRAUD / PHISHING 1 documented fraud campaigns documented REGULATION 7 standards, resolutions, or sanctions UNIQUE CVEs 0 none in the material analyzed (does not mean none in the region)
Monthly verified signal dashboard — Base: 48 verified dated incidents for Peru.
MONTHLY FIXED MODULE Threat Axis Distribution September 2026 · Peru Each incident counts under only one axis, so the total is exactly 48. "Unclassified incidents" is the remainder. Unclassified 20 Ransomware 13 Regulation 7 Incidents 7 Fraud 1
Threat Axis Distribution — Each incident is assigned to a single axis based on its classification; the total reconciles to the 48 incidents in the period.
FIXED MONTHLY MODULE Sectoral Distribution of Signals September 2026 · Peru Base: 48 incidents in the period · total 56 because 6 incidents are classified in more than one sector. Public sector / OIV 27 Other / unidentified sector… 17 Telecom 6 Technology 3 Energy 2 Retail / Consumer 1
Sectoral Distribution of Signals — Heuristic classification by victim sector. One incident may affect more than one sector, so totals may exceed the base.
MONTHLY FIXED MODULE Critical Infrastructure in Peru September 2026 · Peru 10 of 48 facts in the period involve critical infrastructure. One fact may appear in more than one category. Public sector / government 27 Explicit critical infrastructure 1 Energy / utilities 1 Telecom / connectivity 6
Critical Infrastructure in Peru — Verified facts on public sector, utilities, and essential services

Executive summary for the month in Peru

Peru ended September 2026 with 48 verified incidents, seven unclassified incidents, 13 cases centered on ransomware or extortion, and an intense regulatory signal, with seven documented regulatory moves. The dominant threat remained unclassified, with 20 of 48 incidents, while overall risk for the month stayed at a medium level because of the mix of concrete incidents, extortion campaigns, and regulatory changes with financial and operational reach.

The month’s most visible case was the compromise of the official X account of the Ministry of Economy and Finance, which was used to spread misleading messages about a supposed $HYLO cryptocurrency. The agency activated security protocols and asked the public to verify information before sharing it. At the same time, Operation Lumen led to the blocking of 132 websites in Peru, a blocking telemetry figure that does not represent a confirmed intrusion, but it did expose the coexistence of digital piracy and malware distribution in the local ecosystem.

On ransomware, the month produced a fragmented picture. Victim listings appeared on leak sites, or claims by threat actors, affecting Italtel Peru, Agrofruto SAC, Honda (Peru), gob.pe, and other companies or entities, although in several cases the source did not specify whether there was encryption, confirmed exfiltration, or only a mention on a leak site. The observed distribution suggests sustained pressure on government, agribusiness, technology, and manufacturing, with extortion and leak-site noise carrying more weight than operationally corroborated incidents.

Regulation was the other major focus. The SBS moved ahead with a single framework for reporting operational incidents, opened a public consultation on replacing cyber and outage reports, and enabled new channels for pension contributions through digital wallets and apps, always under requirements for operational risk, technology, information security, and cybersecurity management. At the same time, the country consolidated obligations on data protection, AI transparency, and controls over extortion messages and bot networks.

National snapshot for the month in Peru

The month in Peru mixed isolated high-profile incidents with a strong regulatory front and signs of persistent exposure to digital fraud. The risk reading is medium, because there were confirmed incidents with reputational and operational impact, but also a high share of regulatory and contextual developments, and the material did not record a massive campaign with sustained systemic degradation or verified critical CVEs.

The underlying pattern shows a growing reliance on digital channels for banking, pensions, public administration, and information services. That has a clear effect, more room for fraud, impersonation, extortion, and access control failures. The Public Ministry's figure of 29.118 reports of computer crimes between January and July 2026, together with 457 reports of aggravated fraud linked to cards and 19.602 computer fraud cases in that same period, confirms that the underlying problem remains the fraud economy, not just classic malware.

Peru, September 2026MEFbreachedBank fraudSBSconsultationFamousSparrow inPeruLumenblocks
Incident and regulatory timeline in Peru, September 2026 — The month’s most visible events, sorted by date. Includes confirmed incidents, extortion campaigns, and regulatory developments.

At the regional level, Peru fits a Latin American trend of greater pressure on public and financial organizations. ESET and specialized media placed the country within a cyberespionage campaign attributed to FamousSparrow, while Casbaneiro and other banking malware families circulated across the region with impact on several markets, including Peru. The month did not show a sharp jump in critical vulnerability exploitation, but it did show the normalization of transnational campaigns and extortion-driven pressure mechanisms.

Period indicators in Peru

The month was based on 48 verified events dated in September 2026, with 50 events in the time window considered and one later event excluded. The indicators point to lower volume than the previous month in almost every category, but not to a linear drop in risk, because high-impact reputational, extortion, and regulatory reform events persisted.

Indicator September 2026 Previous month Change
Verified events in the period 48 64 -16
Indicator time window 50 events dated in September 2026, 1 later than the period excluded N/A N/A
Unclassified incidents (breaches or outages) 7 10 -3
Cases with ransomware or extortion as the primary focus 13 25 -12
Exfiltration without encryption, simple extortion 4 N/A N/A
Leak site mention only 2 N/A N/A
Classification could not be determined from the material 7 N/A N/A
Documented fraud or phishing cases 1 8 -7
Documented regulatory moves 7 15 -8
Critical CVEs mentioned 0, none in the analyzed material N/A N/A
Sectors with at least one documented event 5 7 -2
Main threat of the month Unclassified, 20 of 48 events Ransomware, 25 of 64 events Shift in focus
Events with direct source confirmation 79% N/A N/A
Aggregated telemetry figures excluded from volume 2, aggregated attempts or blocks, not incidents with confirmed impact N/A N/A
Period indicators, PeruVerified events48Ransomware or extortion13Fraud or phishing1Regulation7Sectors with events5
Month-to-month indicator distribution compared — Key counts for the period, excluding blocking telemetry and any events outside the time window.

Relevant Incidents in Peru

The month’s most significant incidents centered on account takeover, ransomware claims, and the blocking of sites linked to malware. The common thread was a lack of sufficient technical detail in several cases, which required careful separation between confirmed intrusion, declared extortion, and a simple mention on a leak site.

Compromise of the MEF’s official X account

Peru’s Ministry of Economy and Finance said its official X account was compromised and that it activated security protocols to regain access. According to consolidated coverage, posts promoting a supposed cryptocurrency were published from that profile and later removed, and the agency clarified that the posts were not official.

The item matters because of the ministry’s institutional reach and the social engineering risk it created. In the material reviewed, there was no technical attribution or evidence of exfiltration from MEF internal systems, so the case should be read as account compromise and impersonation fraud, not a confirmed data breach.

Operation Lumen and blocking of pirate sites with malware

Indecopi, with support from IFPI, ordered the blocking of 132 websites in Peru during Operation Lumen. La República expanded the figure to 317 blocked sites across several countries, 44 of them associated with malware or other malicious activity, and showed that 132 were in Peru.

This episode should not be counted as an intrusion against a Peruvian entity, but as a coordinated domain-blocking action. Even so, it offers a useful signal, digital piracy remains a vector for malware exposure and data theft, especially when free content consumption acts as bait.

Computer fraud case against a former bank teller

The Lima Centro Provincial Corporate Prosecutor’s Office specialized in cybercrime secured an eight-year, ten-month sentence against a former bank teller for aggravated computer fraud. The case involved 12 unauthorized withdrawal transactions from CTS accounts belonging to three clients, totaling more than S/ 30.000.

The value of the case is not only the conviction, but the pattern it exposes. The operation relied on the legitimate access of an employee, which reinforces the importance of internal controls, transaction traceability, and segregation of duties in financial institutions.

FamousSparrow cyberespionage campaign against government agencies

ESET and specialized media reported that FamousSparrow deployed the SparroWocky backdoor against government agencies in Latin America, including Peru. The material does not identify which Peruvian institutions were affected or confirm the extraction of classified information, but it does place the country within the scope of a sustained cyberespionage campaign.

The case does not appear as an isolated operational incident, but as part of a long-running regional campaign. Its relevance for Peru lies in the targeted sector, government, and in the continued interest in state environments across Latin America.

Threats and active campaigns in Peru

The month brought a mix of ransomware, extortion, and cyberespionage, with many cases where the available evidence was not enough to determine the exact technical impact. The right reading is not that there was more encryption, but that there was more visibility into claims, leaks, and listings on extortion sites.

Ransomware and extortion, with partial classification

Italtel Peru was listed by Everest as a victim, AGROFRUTO SAC appeared tied to ArcusMedia, Honda (Perú) appeared in claims attributed to Panzer, and gob.pe was listed by SafePay. In several of those cases, the source did not specify whether there was encryption, exfiltration, or only a mention on a leak site.

The clearest part of the month was simple extortion, with four cases in which the source did suggest data theft and pressure to negotiate. There were also two leak-site mentions with no further detail and seven cases in which the material did not allow the impact to be classified. That breakdown matters because it avoids overstating the operational effect.

Campaign or victim Type of impact according to the material Date Status
AGROFRUTO SAC, ArcusMedia Exfiltration without encryption or extortion, according to the source 2026-09-23 Confirmed by the source, not validated by the company
Italtel Peru, Everest Leak-site mention only 2026-09-01 Not verified by the organization
Honda (Perú), Panzer Impact could not be determined from the material 2026-09-15 Claim without independent technical proof
gob.pe, SafePay Leak-site mention only 2026-09-15 No official confirmation

Fraud and phishing

The MEF case was the month’s most visible fraud or phishing signal, with deceptive posts coming from a compromised institutional account. Beyond that episode, the material provides more context than new cases, especially on the volume of digital fraud in the country and the persistence of impersonation and scam attempts designed to get the victim to authorize transactions.

The Experian figure cited by several media outlets is useful for sizing up the environment, 73.5% of Peruvians said they had faced at least one digital fraud attempt in the past year, and 49% of those who received attempts ended up falling for the trap. That is not a monthly incident, but it does explain why compromised accounts keep working so well as fraud vectors.

Cyberespionage and APT campaigns

FamousSparrow was the month’s most relevant APT campaign because of its regional reach and because it included Peruvian government entities among its target set. The material does not report exploitation of critical CVEs in Peru or confirm which institution was hit, so the signal should be read as geopolitical exposure, not as a confirmed incident with classified impact.

There were also references to Casbaneiro, a banking trojan that targeted users in the region and was observed by FortiGuard Labs in August, with countries such as Argentina, Peru, Colombia, and Mexico within the campaign’s reach. From a country perspective, this reinforces that the financial sector remains the most exposed to malware built to steal credentials.

Critical vulnerabilities with impact in Peru

No critical CVEs were reported in the material analyzed for September 2026. That does not mean there were no exploited vulnerabilities in the region, only that none were documented in a verifiable way in the sources provided for Peru during this month.

CVE Software Exploitation Source
No critical CVEs were reported in the material analyzed N/A N/A N/A

Regulation and compliance in Peru

The regulatory front was especially active and offered clearer signals than the technical incidents. The SBS moved ahead on operational incident reporting, digital channels for retirement contributions, risk management, and data protection obligations, while Congress and other bodies pushed rules on bots, extortion, AI, and privacy.

SBS and a single operational incident report

The SBS authorized a public consultation on a draft that would replace separate reports for significant outages and significant cybersecurity events with a single operational incident framework. The proposal includes initial, interim, and final reports, staggered deadlines, and categories covering business interruption, system failure, data compromise, and financial fraud.

The change matters because it standardizes reporting language and requires supervised entities to treat technology, operational, and continuity incidents under one management model. For compliance and security teams, that means adjusting internal manuals, event classification, and escalation workflows.

Retirement contributions through digital wallets and apps

The SBS approved Resolution SBS No. 02326-2026 to allow retirement contributions to be paid through digital wallets, mobile apps, banking agents, and other mechanisms. The rule requires operational, technology, information security, cybersecurity, business continuity, and third-party risk management, along with reconciliation and traceability controls.

This move expands the exposure surface of the retirement system, but does so with explicit controls. It also introduces obligations tied to personal data use and the submission of risk reports to the SBS, making the contractual and technical rollout of the new channels more demanding.

Personal data protection and artificial intelligence

The month reinforced the practical application of the personal data framework and the Regulation of the Artificial Intelligence Law. The material cites the obligation to notify the authority within 48 hours after becoming aware of certain incidents that create significant exposure of personal data, and refers to penalties under the LPDP, with fines ranging from 0.5 to 100 UIT, or from 5 to 100 UIT for sensitive data.

In addition, in the AI field, companies were told to strengthen governance, transparency, and the role of the Personal Data Officer. That combination suggests privacy and cybersecurity are no longer being handled as separate tracks in local supervision.

Rules on bots, extortion, and digital messages

There were legislative initiatives to penalize bot and troll networks used to distort information relevant to elections, as well as to criminalize extortion messages from the preparatory stage. Although still proposals, they point to a tougher stance on low-cost, high-volume digital crime.

Rules on numbering for commercial messages and measures tied to anti-money laundering in technology platforms for remote gaming and betting also remained under discussion. The signal is clear, Peru is widening the regulatory perimeter around digital services, communications, and fraud.

Regulatory move Entity Cybersecurity or data impact Status
Single operational incident reporting SBS Standardizes escalation and incident classification Public consultation
Retirement contributions through digital channels SBS Expands digital surface and requires risk management Approved
Data protection and incident notification Data authority Reinforces compliance and notification deadlines In force according to material
Bots and troll networks in elections Congress Proposed criminal classification Legislative review

Most Affected Sectors in Peru

The sectors most exposed this month were finance, government, agribusiness, technology, and, to a lesser extent, manufacturing. That distribution reflects not only confirmed incidents, but also extortion claims and cyberespionage campaigns that reached the country from several angles.

The financial sector carried the heaviest qualitative weight because of the banking fraud conviction, the debate over strengthened authentication, and the volume of digital fraud reports filed by the Public Prosecutor's Office. The dominant risk there remains access abuse, victim-authorized fraud, and social engineering, not necessarily classic perimeter compromise.

The public sector was affected on two separate fronts. One was the compromise of the MEF account, with an immediate reputational impact. The other was exposure to cyberespionage through FamousSparrow and the SafePay signal on gob.pe, both cases useful for gauging criminal and APT interest in state infrastructure and public services.

Agribusiness and manufacturing appeared mainly in ransomware claims, with AGROFRUTO SAC, Honda (Peru), and Cerámicas Kantu in the orbit of different groups. In technology, Italtel Peru appears as an early extortion mention on a leak site. None of these cases should be counted as equivalent, because the material does not give them the same level of verification.

The month’s main shift was a move away from the clearly dominant ransomware seen in August toward a more dispersed mix of fraud, extortion, compromised account incidents, and regulation. Compared with the previous month, verified events fell from 64 to 48, and ransomware, fraud, and regulation also declined, but operational risk did not fall proportionally.

In ransomware or extortion, the most visible change was quantitative. The previous month had documented 25 cases with that primary focus, while September ended with 13. That drop should not be read as a structural reprieve, because much of September’s material was concentrated in a few cases with greater institutional visibility, especially the MEF and gob.pe.

The dominant threat also changed. In August, it was ransomware, with 25 of 64 events. In September, it shifted to unclassified, with 20 of 48 events. That turn reflects a loss of analytical clarity, not necessarily a better environment, and it is explained by the weight of regulatory signals, context news, and campaigns whose impact could not be fully determined.

The fraud front remains central. Although documented fraud or phishing cases fell from 8 to 1 in the monthly comparison, hard data from the Public Prosecutor’s Office and Experian studies show massive, persistent exposure. The gap between attempt and success also remains wide, and the MEF account confirmed that a single compromised institutional account is enough to trigger a chain of deception.

In regulation, the signal to watch is how the SBS implements the single operational incident procedure and how entities adapt their internal processes. The shift toward digital channels for pension contributions and the tightening of personal data and AI obligations leave less room for ad hoc controls. September marked the move from regulatory debate to execution pressure.

Recommendations for security teams in Peru

Security teams in Peru should prioritize account control, operational traceability, and incident response for operational disruptions over a reading focused only on malware. September’s material shows that the most visible damage came from impersonation, extortion, and trust abuse, not from a single large-scale technical exploit.

First, strengthen protection for institutional and high-profile accounts. The MEF case shows that a compromised account can become a fraud channel within minutes. That requires phishing-resistant MFA, permission reviews, monitoring for anomalous posts, and playbooks to revoke sessions and communicate the incident through alternate channels.

Second, review internal controls and segregation of duties in financial and customer service environments. The former bank cashier case shows that legitimate access remains a highly effective fraud route. Teams should audit privileges, log sensitive changes, and review alerts for unusual activity from internal profiles.

Third, prepare compliance for the SBS’s new operational incident framework. The workflows for classification, escalation, initial reporting, follow-up, and closure should be written before the rule fully enters into force. It also makes sense to align incident response with privacy and business continuity, because the regulator now treats them as one practical problem.

Fourth, review exposure to leak sites and ransomware threat intelligence providers without confusing a claim with a confirmed breach. In September, there were several cases where the evidence was incomplete. That means validation should rely on internal context, internal telemetry, and logs, not external listings alone.

Fifth, keep awareness campaigns focused on authorized user fraud, deepfakes, and identity impersonation. The month’s material shows that the user remains the weakest decision point. Training should be operational, not generic, with examples of messages, urgent claims, and fraudulent links.

Frequently Asked Questions

What is the difference between ransomware cases and simple extortion cases in Peru this month?

In September, the material distinguishes between exfiltration without encryption, mere mention on a leak site, and cases where the classification could not be determined. That affects AGROFRUTO SAC, gob.pe, Honda (Perú) and Italtel Peru, among others. The difference is developed in Threats and active campaigns in Peru.

What changed in Peru's reporting rules for incidents?

The SBS promoted a single procedure for operational incidents with initial, intermediate and final reports, and set aside the separation between significant interruptions and cybersecurity incidents. That change is linked to moves on digital pension contributions and data protection, covered in Regulation and compliance in Peru.

Was the MEF case a data breach or an account compromise?

The material presents it as a compromise of the official X account and fraudulent use of the profile to promote a supposed cryptocurrency. There is no confirmation of exfiltration from the ministry's internal systems. Details on the incident and its scope appear in Relevant incidents in Peru and in the executive summary.

Were any critical CVEs exploited in Peru during September?

No critical CVEs were recorded in the material analyzed for this month. That does not mean there were no vulnerabilities in the region, only that none were documented in a verifiable way in the sources provided. The corresponding table is in Critical vulnerabilities with impact in Peru.

Which sector showed the strongest signal for a local CISO?

Finance was the most sensitive sector because of the combination of fraud, access abuse, regulation and stronger authentication. Government was also exposed because of the MEF and the FamousSparrow cyberespionage campaign. The sector-level analysis is developed in Most affected sectors in Peru.

Material limitations

This report was built exclusively from the material provided for Peru in September 2026. The indicator window covers 50 dated items from the month, with one later item excluded. Items with no confirmed date were left out of the counts and would only be mentioned if their undated status were clarified, which was not necessary here.

The absence of critical CVEs in the indicator does not mean that no exploited vulnerabilities existed in the region. It only means they did not appear in this month’s analyzed material. The same applies to the other zeros in the table, which reflect no record in the sources, not the absence of facts in the country or in Latin America.

Aggregate telemetry on blocks or attempts, such as Operation Lumen, was not counted as an incident with confirmed impact. If it is mentioned, it should be understood as an automated block or containment action, not as a verified intrusion. The figures of 132 blocked sites in Peru and 317 in the regional operation were used only as context, with their source and time window made explicit.

Consumer social media and sponsored content were excluded as evidence, along with sources not included in the permitted list. Statements with insufficient support or promotional material were also avoided when building trends. When a ransomware claim could not be verified, it was treated as such, without elevating it to a confirmed incident.

Sources