CiberLATAMbywhalemate
Intelligence report

Paraguay: cybersecurity landscape, June 2026

June brought ransomware against healthcare and industry, regulatory progress, and a facial recognition complaint before the IACHR.

Jul 28, 202618 min read
Paraguay: cybersecurity landscape, June 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are automatically completed with verified dated facts within the period. Each one states its basis and counting criterion so the figures reconcile across modules. They are the recurring month-to-month readout, and the analysis that follows expands on the cases without repeating this summary.

Indicator window: 66 dated facts in June 2026 · 3 from prior months (comparative framework, not month volume) · 1 without confirmed date (excluded from indicators). Facts from prior months are used only as a comparative frame in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Monthly verified signal dashboard June 2026 · Paraguay Top threat: Unclassified (19 of 65 events). Coverage: 66 dated events in June 2026 · 3 months an… VERIFIED EVENTS 65 period base: all counts measured from below is based on this total RANSOMWARE / EXTORTION 18 3 encrypted assets confirmed · 15 classified not determinable with the UNCLASSIFIED INCIDENTS 8 breaches or disruptions with no declared threat type FRAUD / PHISHING 3 documented fraud campaigns documented REGULATION 16 regulations, resolutions, or sanctions UNIQUE CVEs 1 CVE-2024-55591
Monthly verified signal dashboard — Base: 65 verified events dated in the period for Paraguay.
MONTHLY FIXED MODULE Threat Axis Distribution June 2026 · Paraguay Each event counts on only one axis, so the total is exactly 65. "Unclassified incidents" is the remainder. Unclassified 19 Ransomware 18 Regulation 16 Incidents 8 Fraud 3 Vulnerabilities 1
Threat Axis Distribution — Each event is assigned to one axis based on its classification; the total reconciles with the 65 events in the period.
FIXED MONTHLY MODULE Sector distribution of signals June 2026 · Paraguay Base: 65 events in the period · total 81 because 15 events are classified in more than one sector. Public sector / OIV 26 Other / no sector identi… 18 Finance 10 Healthcare 8 Telecom 7 Technology 5 Retail / Consumer 4 Education 3
Sector distribution of signals — Heuristic classification by victim sector. One event may affect more than one sector, so the total may exceed the base.
MONTHLY FIXED MODULE Critical Infrastructure in Paraguay June 2026 · Paraguay 4 of 65 period facts involve critical infrastructure. One fact may appear in more than one category. Public sector / government 26 Energy / utilities 34 Telecom / connectivity 7
Critical Infrastructure in Paraguay — Verified facts on public sector, utilities, and essential services

Monthly executive summary for Paraguay

June 2026 sent a clear signal in Paraguay on two fronts: ransomware that caused real operational disruption in private healthcare and industry, and a faster regulatory debate over personal data, artificial intelligence, and biometric surveillance. The most visible case was the attack that brought down systems at clinics and private medical companies, forcing manual handling of admissions, consultations, payments, and records management. At the same time, the Krybit group claimed an attack on Enrique Remmele S.A.C.I., and Nightspire’s leak site added the Grupo Riquelme conglomerate as a victim, with threats to disclose banking, accounting, customer, and human resources data.

The month also showed that the impact was not limited to classic extortion. In healthcare, the disruption of appointments, medical records, and patient service channels had an immediate and sensitive operational component. In industry and conglomerates, the information exposed or threatened points to business continuity, reputation, and possible legal pressure. Of the cases observed, only part allowed confirmation of asset encryption; in the rest, the material was not enough to distinguish precisely between encryption, exfiltration, or only a claim posted on a leak site.

Sector signal, Paraguay, June 2026Qualitative reading based on verified incidents from the periodPrivate healthcareIndustryPublic sectorFinance and paymentsWidths only show where the month’s signal was most concentrated, not an exclusive volume by sector.
Narrative distribution of the signal by sector in Paraguay — Qualitative map of the sectors with documented incidents during the month. This is not an exclusive count, and a single incident may affect more than one sector.

The regulatory front also moved decisively. Law 7593/2025 on Personal Data Protection continued to drive analysis of its future impact, while June saw initiatives to regulate AI, ban indiscriminate biometric surveillance in election advertising, set rules for tax monitoring of cryptoassets, and adapt consumer and digital payments rules. There was also a complaint before the IACHR over secret facial recognition use in Asunción, filed by EFF, TEDIC, and CEJIL. Taken together, these developments point to a country entering a more formal regulatory phase, but still with implementation gaps and open disputes over state transparency.

The month’s risk reading is high. Not because of overwhelming volume, but because of the mix of concrete disruption in sensitive sectors, extortion over data with high exposure potential, and a regulatory agenda that is still being built. The regional backdrop matched that pattern, with comparative and contextual material placing Paraguay within a Latin American wave in which attackers prioritize critical services, use double extortion, and exploit exposed attack surfaces, while states move more slowly than the market on data protection, AI, and cryptoassets.

Paraguay national monthly overview

June 2026 in Paraguay was uneven, but one trend stood out clearly. The most serious operational signal was ransomware affecting private health care, where response had to revert to paper and manual processes. That meant degraded service, overloaded staff, and direct risk to patients. At the same time, industry and business groups faced pressure through extortion tied to possible database exposure, which affects continuity, intellectual property, accounting, and labor relations.

The severity came not only from the names of the victims, but from the nature of their functions. Private health care and medicine are sectors that hold highly sensitive information and have very little tolerance for downtime. Industry and conglomerates, meanwhile, are attractive targets for ransomware actors looking to negotiate using financial and business data. The month also showed that attackers are using leak portals and pressure campaigns, even when public material does not always make it possible to confirm whether there was encryption or only the victim’s publication on a leak site.

The qualitative risk reading for Paraguay is high, based on the combination of 65 verified events during the period, 18 cases with ransomware or extortion as the primary focus, 8 unclassified incidents, and 16 documented regulatory moves. That mix points to an environment with sustained offensive pressure and, at the same time, an institutional capacity still taking shape. The absence of a massive case count does not reduce the seriousness of the confirmed impacts, because several of them affected critical services, sensitive data, and operators with public exposure.

In the Latin American context, Paraguay does not stand alone. This month’s material places it in the same regional dynamic where ransomware groups combine pressure over data, selective leaks, public negotiation, and posting on extortion sites. At the same time, the regional policy debate is accelerating around personal data, AI, surveillance, and digital assets. Paraguay is part of that trend with one key difference, the regulatory front is advancing, but it still coexists with fragmented sector ecosystems and incidents that show operational gaps that remain very costly.

Paraguay threat indicators

Indicator Value
Verified incidents in the period (basis for all indicators) 65
Indicator time window 66 incidents dated in June 2026, 3 from prior months (comparative frame, not monthly volume), 1 without confirmed date (excluded from indicators)
Unclassified incidents (breaches or outages) 8
Cases with ransomware or extortion as the primary focus 18
Ransomware breakdown by impact type: confirmed asset encryption 3
Ransomware breakdown by impact type: impact could not be determined from the material 15
Documented fraud or phishing cases 3
Documented regulatory actions 16
Critical CVEs mentioned 1
Sectors with at least one documented incident 8
Predominant threat of the month Unclassified (19 of 65 incidents)
Incidents with direct source confirmation 74%
Aggregated telemetry figures excluded from volume 1 (aggregated attempts or blocks, not incidents with confirmed impact)

Relevant Incidents in Paraguay

Private clinics and medical providers, operational impact from ransomware

The month’s most sensitive case was the attack that hit private clinics and medical companies in Paraguay. Coverage by La Tribuna and El Nacional describes systems being shut down, manual operations, and delays in admissions, tests, appointments, payments, and services for insured patients. Specific institutions were also named, including Migone, Grupo Británico, Las Lomas, Santa Clara and Reyva. The analytical value of the case is not only the ransomware attribution, but the degradation of clinical service, which forces real-time process redesign and exposes providers to direct tension between operational continuity and handling clinical information.

The public source does not confirm a ransom payment or a completed data leak at the time of the report. It does make clear that the operational impact was severe enough to force manual procedures back into use. In health care, that kind of disruption affects more than technology: it alters records, waiting times, and potentially the traceability of care.

Enrique Remmele S.A.C.I. and Krybit

On June 17, 2026, Malware.news and ransomware.live listed Enrique Remmele S.A.C.I. as a Krybit victim. The available public information points to an early documentation stage: the tracking portal lists Paraguay and an estimated attack date of June 17, with some third-party credentials compromised, but no full inventory of the damage. The material does not provide a closed detail on the type of exfiltration or on confirmed encryption in this case.

What matters for the national report is that ERSA appears as an industrial victim with public exposure in a ransomware group that was already operating as RaaS and using double extortion techniques. For Paraguay, that adds a risk signal for manufacturing and process industries, where downtime and reputational pressure often go hand in hand.

Grupo Riquelme and Nightspire

On June 25, 2026, DeXpose reported that Nightspire claimed responsibility for an attack on the Paraguayan conglomerate Grupo Riquelme. Ransomware.live dates the case to June 13 and details categories of information allegedly compromised, such as databases, banking and financial data, accounting records, customer information, human resources data, and data from critical business applications. Breachsense added that the attributed leak reaches 133 GB, although that figure does not by itself prove the exact content or the scale of operational damage.

In this incident, the source clearly places it in the logic of data extortion. What it does not allow is a conclusive confirmation of whether assets were encrypted or whether the focus was on the threat of disclosure. For analytical purposes, the case should therefore be read as extortion with potential exposure of multiple layers of corporate information.

Facial recognition in Asunción, petition before the IACHR

EFF, TEDIC and CEJIL filed a complaint before the Inter-American Commission on Human Rights against the Paraguayan state for refusing to provide information about facial recognition systems used for mass surveillance. The petition was formalized on June 19, according to El Notariado, and EFF says the case centers on cameras installed since 2019 in Asunción and the lack of access to protocols for the use and handling of biometric data.

Although this is not a cyber intrusion, it is a digital security and governance issue with direct impact on privacy and democratic oversight. The case shows that the cybersecurity debate in Paraguay now goes beyond malware or fraud, and also includes state transparency, biometrics and fundamental rights.

IRS, record tampering and computer fraud

The Internal Audit report of the IPS documented a scheme to alter records in the REI system in order to hide employer debts and transfer them to fictitious or deceased identities. The available material describes an internal manipulation of data, not a classic external intrusion, but it is still a case of computer fraud with financial impact. The pattern is different from ransomware, although the effect on data integrity is similar in terms of trust and traceability.

For the national reading, the case serves as a reminder that security risks do not come only from outside. Manipulation of internal systems by users with access can also cause material damage, fraud and control problems.

Threats and active campaigns in Paraguay

Ransomware and extortion: confirmed encryption

In June, encryption of assets was confirmed in three cases in the country, but only one was described with enough operational clarity in the source material: the attack against private medical clinics and healthcare companies, which left systems paralyzed and forced manual operations. That picture is consistent with encryption or severe unavailability caused by ransomware, although the public source provides no forensic details on the payload or recovery.

To avoid overstating what was not proven, it is worth separating that case from others in which the source only describes a claim on a leak portal or a threat to disclose data. In Paraguay’s June threat picture, that distinction matters because the risk assessment changes significantly depending on whether there was encryption, exfiltration, or only victim publication.

Ransomware and extortion: exfiltration or pressure on data without determinable encryption

Grupo Riquelme fits this category better. Nightspire claims the attack and the exposure of sensitive data, and ransomware.live lists the compromised categories. However, the material does not make it clear whether the operation included system encryption, only exfiltration, or a combination of both. A similar case applies to ERSA, where public visibility centers on the Krybit claim, the warning about data publication, and the victim listing on monitoring sites, but not on a full technical postmortem.

That distinction matters for defensive and compliance teams. Not every case listed by a group on its portal necessarily means loss of availability. Sometimes the pressure is on confidentiality and negotiation, not on operations. In others, such as private healthcare, the operational damage was visible from the start.

Ransomware and extortion: leak site mention only

The June material also includes cases where the public signal is mainly a mention on leak sites or threat intelligence pages. That does not, by itself, confirm total impact, but it does show actor interest and exposure that could escalate. In the national report, this category helps avoid mixing verified facts with campaigns that are still at the claim stage.

Fraud and phishing

The material documents three fraud or phishing cases during the period. The clearest is the internal scheme detected at IPS, where data was manipulated to transfer debts and create an appearance of regularity. Although this is not phishing in the strict sense, it is documented fraud involving misuse of systems. In addition, the technical information on Krybit describes targeted phishing as an access vector, but that appears as an attribute of the actor and not as a separate local incident in Paraguay.

APT, espionage, or hacktivism

The month’s material did not include a Paraguayan case clearly classified as APT or hacktivism with confirmed impact. The dominant threat focus remained ransomware, extortion, and internal fraud. That does not mean espionage or activism risk is absent, only that the verified facts were not enough to support that classification.

Critical vulnerabilities with impact in Paraguay

CVE Software Exploitation Source
CVE-2024-55591 FortiOS / FortiProxy Mentioned as an authentication bypass leveraged by NightSpire in at least one technical case, within the analyzed material on the group’s TTPs Mallory

Regulation and compliance in Paraguay

June was a particularly active month for regulation. Paraguay already has Law 7593/2025 on Personal Data Protection, with a vacatio legis until November 2027, and that continued to drive analysis around internal compliance, consent, transparency, proportionality, and impact assessments. The key issue is not only legal, but operational: which systems use sensitive data, how purpose is documented, and who has access to automated processing.

At the same time, lawmakers documented a bill on election advertising on social media that bans microtargeting based on ideological profiles or political affiliations without consent and creates a mandatory registry of accounts for digital political advertising. It was also reported that legislators are pushing a strategy to regulate AI and implement the data law, with risk-based classification, a ban on indiscriminate biometric surveillance, and a public registry of AI systems. That points to an agenda trying to close several gaps at once, although still at the design stage.

The digital assets front also moved forward. Revista Plus and Atlas21 reported on regulatory work to apply securities market rules to digital assets and on new reporting obligations for bitcoin and other cryptocurrency transactions above 5,000 dollars per year. InfoNegocios, meanwhile, noted that Paraguay still lacks a fintech law and a single comprehensive framework for digital assets, forcing operators to work under partial rules from several authorities. The result is greater oversight, but still fragmented.

The complaint filed by EFF, TEDIC and CEJIL before the IACHR over the secret use of facial recognition adds a different dimension. This is not only about compliance, but about the democratic governance of surveillance technologies. For organizations working with biometrics, video surveillance or automated analytics, the message is clear: the regulatory transition period is no longer theoretical.

Most affected sectors in Paraguay

The month’s sectoral signal centered on private healthcare, industry, legal and compliance services, and the public sector tied to surveillance and data management. Private healthcare was the sector with the clearest operational impact. The reason is straightforward, a down clinical system affects scheduling, medical records, admissions, billing and patient care. In that kind of environment, digital continuity is not a convenience, it is part of the service.

Industry appears because of the ERSA case and also because of exposure affecting conglomerates such as Grupo Riquelme. The concern there is availability, trade secrets, accounting, customer data and the continuity of administrative processes. The extortion logic is different, but just as sensitive. If a business group runs several lines of business, a single incident can cut across more than one operational front.

The public sector also appears, though for other reasons. IPS was not a documented external intrusion, but a case of internal manipulation of records. Even so, the damage is comparable in terms of data integrity and institutional trust. The complaint over facial recognition, meanwhile, opens a privacy and state surveillance front with cross-cutting effects for the entire administration.

The set of events also shows a closer relationship between technology, regulation and public services. Health, finance, surveillance, consumer markets and cryptoassets appear linked by the need for clear rules, access traceability and incident response. These are not isolated sectors, but overlapping layers of a digital infrastructure that is still maturing.

There is no month-over-month comparison baseline because this is the first archived period with this indicator format for Paraguay. For that reason, it would not be appropriate to invent an increase or decrease rate versus May. What June did leave, however, was a mix of active ransomware, data extortion and regulatory expansion that warrants close attention in July.

The first signal to watch is private healthcare. If incidents continue to require manual operations, that means resilience and recovery plans are still not absorbing the burden of attacks of this type. The second is industry and conglomerates. The exposure of ERSA and Grupo Riquelme suggests attackers are still finding value in companies with multiple business units and high-impact financial or workforce data.

The third is the maturation of the regulatory agenda. Law 7593/2025, the initiatives on AI, election propaganda rules and digital asset regulations point to a real acceleration in compliance. For security teams, that changes the focus, incident response is no longer enough, they also need to document processing, access, monitoring and the use of biometrics.

The fourth signal is the tension between surveillance and privacy. The CIDH case could become a regional reference if it moves forward. If that happens, Paraguay would need to review not only the legality of the deployment, but also the transparency and impact assessment of facial recognition technologies.

Finally, it is worth tracking the technical evolution of Krybit and Nightspire. The June material describes groups using RaaS, double extortion, legitimate tools, RDP abuse and, in Nightspire’s case, an intrusion technique that in some scenarios reaches exploitation of CVE-2024-55591. That does not mean Paraguay is facing a single campaign, but it does mean it is dealing with actors that combine opportunistic access and public pressure.

Security recommendations for teams in Paraguay

  1. Put operational continuity first in healthcare, industry, and public-facing services. If ransomware forces a move to manual mode, the organization is already too late on its response plan. Recovery, segmentation, and restoration need to be tested with real exercises.
  2. Review remote access, RDP, and legitimate administration tools. The actors seen in the material use remote access, administration, and exfiltration software that can go unnoticed without tight behavioral controls.
  3. Strengthen internal identity and privilege controls. The IPS case shows the threat can also come from inside, with users altering data, account statuses, or traceability.
  4. Prepare inventories of sensitive data and automated processing. Law 7593/2025 and the debate over AI, biometrics, and surveillance require knowing what data is processed, on what legal basis, and who can access it.
  5. Review the use of biometrics and video surveillance under data minimization, transparency, and impact assessment criteria. The facial recognition case before the IACHR could raise the expected standard for public and private entities.
  6. Segment clinical, accounting, and customer service systems. The combination of encryption and extortion means a single outage can affect several critical functions at the same time.
  7. Monitor exposed attack surfaces in edge services and public applications. The technical material on ransomware in June emphasizes vectors such as targeted phishing and exploitation of unpatched exposed services.
  8. Align security with regulatory compliance in digital assets and payments. The new crypto reporting rules and tax exemptions for PSAV and fintech imply documentation processes and traceability controls that should not be left out of the security area.

Material limits

This report was prepared exclusively from the material provided for Paraguay in June 2026. There was no access to the internet or to external sources beyond the authorized list. The indicator window includes 66 dated facts from June 2026, 3 facts from earlier months used only as comparative context, and 1 undated fact, which was excluded from the indicators.

A key methodological point is that an indicator at zero, particularly the CVE indicator if that had been the case, means only that it was not recorded in the material analyzed, not that there was no activity or critical exploitation in the region. This month, the critical CVE indicator mentioned 1 case, so the absence of other names should not be interpreted as the absence of vulnerabilities in Paraguay or in Latin America.

It is also necessary to distinguish between incidents and telemetry. The figure of 734.5 million cyberattack attempts cited by La Nación and attributed to Fortinet corresponds to automated attempts or blocks in 2025, not to incidents with confirmed impact in June 2026. For that reason, it is not included in the month's total and, by itself, cannot be used to measure the real damage.

On sources, consumer social media, sponsored content and notes whose value was mainly promotional were excluded. When a claim depended only on material with uncertain attribution, it was treated as such and not as fact. The report prioritizes confirmed facts, notices from the outlet itself or the technical tracker, and regulatory or institutional documentation available in the provided archive.

Sources