CiberLATAMbywhalemate
Intelligence reportAug 1, 202614 min read

Paraguay: cybersecurity landscape, July 2026

July logged 51 verified incidents, two ransomware campaigns, and a criminal case over Chinese cyberespionage against the Paraguayan state.

Paraguay: cybersecurity landscape, July 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are completed automatically with verified dated events within the period. Each one states its basis and counting criterion, so the figures reconcile across modules. They are the recurring month-to-month reading, while the later analysis develops the cases without repeating this summary.

Indicator window: 51 dated events in July 2026 · 3 from previous months (comparative frame, not monthly volume) · 11 without confirmed date (excluded from the indicators). Events from previous months are used only as a comparative frame in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Verified Signal Monthly Dashboard July 2026 · Paraguay Primary threat: Unclassified (19 of 51 events). Coverage: 51 dated events in July 2026 · 3-month ant… VERIFIED EVENTS 51 period baseline: all counts measured from below against this total RANSOMWARE / EXTORTION 11 4 asset encryption confirmed · 1 only mentioned in leak site · 6 not classified UNCLASSIFIED INCIDENTS 15 breaches or outages without declared threat type FRAUD / PHISHING 0 documented fraud campaigns documented REGULATION 1 rules, rulings, or sanctions UNIQUE CVEs 0 none in the material analyzed (does not imply absence in the region)
Verified Signal Monthly Dashboard — Baseline: 51 verified dated events in the period for Paraguay.
MONTHLY FIXED MODULE Threat Axis Distribution July 2026 · Paraguay Each case is counted in only one axis, so the total is exactly 51. "Unclassified incidents" is the remainder. Unclassified 19 Incidents 15 Ransomware 11 Vulnerabilities 5 Regulation 1
Threat Axis Distribution — Each case is assigned to one axis based on its classification; the total reconciles with the 51 cases in the period.
MONTHLY FIXED MODULE Sectoral Signal Distribution July 2026 · Paraguay Base: 51 events in the period · total 60 because 8 events are classified in more than one sector. Public sector / OIV 33 Other / no sector iden… 12 Finance 6 Technology 6 Health 1 Energy 1 Retail / Consumer 1
Sectoral Signal Distribution — Heuristic sector classification by victim sector. One event can affect more than one sector, so the total may exceed the base.
MONTHLY FIXED MODULE Critical infrastructure in Paraguay July 2026 · Paraguay 19 of 51 facts in the period involve critical infrastructure. One fact may appear in more than one category. Public sector / government 33 Explicit critical infrastructure 1 Energy / utilities 44
Critical infrastructure in Paraguay — Verified facts on public sector, utilities, and essential services

Executive summary for the month in Paraguay

July closed in Paraguay with an unusual mix of operational pressure, geopolitical dispute, and regulatory progress. The month produced 51 verified events in the corpus analyzed, including 15 unclassified incidents, 11 cases in which ransomware or extortion was the primary focus, and a dominant area that still remained unclassified in 19 of those 51 events. The picture does not show a single campaign shaping the entire month, but several parallel tracks, intrusion against the state, extortion targeting private companies, and a regulatory agenda that moved forward more forcefully than in June.

The most visible episode was the joint complaint by MITIC and the U.S. Embassy about malicious cyber operations directed at Paraguayan government platforms, followed by China’s public response and the opening of a criminal case by the Fiscalía. The material describes infiltrations into government networks, theft and disclosure of sensitive data, and disruption of digital services, but the technical attribution published in press coverage still rests on references to binational reviews and official statements, not on IOCs or a complete incident technical sheet. That leaves the case best read as a cyberespionage campaign with state impact, rather than as an intrusion with closed forensic details.

At the same time, the ransomware front remained active. Ransomware.live identified Automovil Supply S.A. as a victim of the TheGentlemen group, with discovery on 7 July and an estimated attack date of 6 July. Dexpose, for its part, reported on 1 July an extortion note from Doommageddon against Solventa & Riskmétrica S.A. In both cases, the evidence differs in substance, one appears as a victim listed on a ransomware map and the other as a claim on an extortion site. To that, add a note about sanatoriums affected that circulated as a response alert, although without closed technical identification in the available material.

The regulatory layer advanced more clearly than in prior months. Paraguay approved a new Personal Data Law, with rights to access, rectification, deletion, objection, portability, and automated review, along with data minimization and breach notification within 72 hours when applicable. A bill to regulate drones also appeared, with mandatory registration and Remote ID, and the BCP continued adjusting rules on payments, fees, and transparency in the financial system. The month did not record critical CVEs in the analyzed material, but that does not mean there were no exploited vulnerabilities in the region.

Paraguay national monthly overview

Paraguay's risk reading in July was moderate, with isolated spikes of high severity in the state sector and in extortion campaigns that reached private companies. The reason was not just volume, but the mix of actors with different objectives, a state under pressure from cyberespionage, and private-sector targets exposed by uneven control maturity. The month was defined less by a flood of similar cases than by the coexistence of targeted intrusion, extortion, and a compliance agenda that is beginning to reshape the picture.

On the operational side, the country continued to show a sensitive attack surface in government networks, banking, and health services. The material cites a critical vulnerability tied to an institutional VPN protected only by a password, without two-factor authentication, along with observations about outdated systems, insufficient patching, and limited investment in protection at clinics. This was not a single type of exposure, but repeated weaknesses in remote access, cyber hygiene, and response maturity. That helps explain why several items in the month end up describing readiness, control reviews, or training needs, rather than closed remediation.

At the regional level, Paraguay's signal aligned with a Latin American trend of growing friction between state infrastructure, geopolitical pressure, and opportunistic crime. In this case, however, the coverage had a distinctive element, the overlap between cyberespionage accusations, diplomatic response, and a domestic criminal case. That places Paraguay in an exposure category where the discussion does not stop at malware or fraud, but also includes digital sovereignty, attribution, and data governance.

Paraguay incident indicators for July 2026

Indicator July 2026 Previous month Change
Verified incidents in the period (base for all indicators) 51 65 -14
Indicator time window 51 incidents dated July 2026 · 3 from previous months (comparative frame, not monthly volume) · 11 without confirmed date (excluded from indicators)
Unclassified incidents (breaches or disruptions) 15 8 +7
Cases with ransomware or extortion as the primary focus 11 18 -7
Confirmed asset encryption 4
Leak site mention only 1
Classification cannot be determined from the material 6
Documented fraud or phishing cases 0 3 -3
Documented regulatory moves 1 16 -15
Critical CVEs mentioned 0, none in the analyzed material, does not imply absence in the region
Sectors with at least one documented incident 6 8 -2
Predominant threat of the month Unclassified (19 of 51 incidents) Unclassified (19 of 65 incidents)
Incidents with direct source confirmation 78%

Relevant Incidents in Paraguay

Cyber operations against Paraguayan state platforms

On July 10, MITIC and the U.S. Embassy issued a joint statement warning about malicious cyber operations targeting the Paraguayan state’s digital platforms. Subsequent coverage said a cybersecurity review of government networks identified multiple threat actors linked to the Government of the People’s Republic of China. The material also refers to unauthorized access, disruption of digital services, and the theft and disclosure of sensitive data. The source does not provide IOCs or a closed exploitation chain, but it does make clear that the matter moved from suspicion to a public complaint and a criminal case.

Criminal case over cyberattacks on the Paraguayan state

Paraguay’s Prosecutor’s Office opened a criminal case to investigate intrusions into government computer systems attributed to actors linked to China, and the investigation was assigned to specialized prosecutor Irma Llano. The key point is not only that the case was opened, but that it has now been formalized before the Public Ministry with a description of events that includes intrusion, disruption, and exposure of sensitive information. That gives the episode a legal dimension that in other countries often takes longer to reach.

Alert over cyberattack on Paraguayan clinics

Diario Paraguayo published a report on July 3 responding to an attack that affected private clinics. The text recommends isolating systems, declaring an institutional emergency, setting up a crisis committee, and preserving evidence. It does not identify institutions or malware families, but it does confirm that the local discussion was already dealing with an incident with real operational impact on private healthcare, along with prior weaknesses in patching, obsolete systems, and poor cyber hygiene.

Extortion attack against Solventa & Riskmétrica S.A.

Dexpose reported on July 1 an extortion note from the Doommageddon group against Solventa & Riskmétrica S.A., a Paraguayan credit rating agency. The publication says the group threatened to leak sensitive data if negotiations did not take place. In this case, the source clearly frames the incident as extortion, but does not publish enough detail to conclude that assets were encrypted.

Threats and active campaigns in Paraguay

Ransomware and extortion, with uneven impact

Confirmed asset encryption

Ransomware.live listed Automovil Supply S.A. as a victim of the TheGentlemen group, with the case discovered on July 7 and the estimated attack date set for July 6. That record is what supports confirmed encryption within the month, alongside reporting on the response to the sanatorium case, where the journalistic material suggests operational impact but does not fully identify the family or the technical scope. The July report on the automotive company is more clearly classified by the intelligence platform.

Mention only on a leak site

The Solventa & Riskmétrica S.A. case falls into the extortion category with publication on a leak site, because Dexpose reports a Doommageddon note threatening to publish data, but the material provided does not allow confirmation that encryption was verified.

Typing cannot be determined from the material

In the sanatorium case, the documentation speaks of a cyberattack that prompted an institutional response, and a secondary source that cannot be used as primary evidence suggests a move to paper records. With the material fit for citation, there is not enough to determine whether this was encryption, exfiltration, or a mix of both. For that reason, it should remain classified as undetermined.

Cyberespionage attributed to China-linked actors

The other active line this month was state-linked and geopolitical. Coverage from ABC Color, Infobae, La Política Online, Swissinfo and other outlets converges on a joint Paraguay and United States complaint over infiltration of government networks, a Chinese response denying the allegations, and an expanded case at the prosecutor’s office. The reporting links the campaign to Flax Typhoon in the 2024 background and to new actors detected in 2026, although that technical attribution is supported by joint reviews and official statements, not by a public forensic release.

Fraud and phishing

No fraud or phishing cases were documented in the period material.

Critical vulnerabilities with impact in Paraguay

CVE Software Exploitation Source
No critical CVEs were recorded in the material analyzed N/A The month's corpus did not publish critical CVEs or associated exploitation Period indicator

Regulation and compliance in Paraguay

Paraguay moved in July on a regulatory agenda with direct implications for privacy and operational oversight. The new Personal Data Law adds rights of access, rectification, deletion, objection, portability and review of automated decisions. It also requires data minimization, establishes a free procedure for citizens and provides for breach notification within 72 hours when applicable. Enforcement and supervision will fall to the National Personal Data Protection Agency, under MITIC.

ABC Color also reported the phased penalty regime, with fines ranging from 20 to 2,500 jornales for general violations, up to 5,000 for sensitive data and up to 10,000 when children or adolescents are involved. The press also said the law will take full effect in 2027, giving organizations a reasonably short preparation window for inventories, contract reviews, privacy policy updates, stronger controls and staff training.

At the same time, Congress received a bill to regulate drones with mandatory registration before DINAC, the Air Force or Digemabel, depending on use, plus remote electronic identification. While not a cybersecurity rule in the strict sense, it is tied to traceability, technical control and possible system interoperability. The BCP also advanced work on SIPAP fees, new maximum card commissions and transparency rules for payment services, a package that keeps pushing the financial system toward digitization under tighter oversight.

Most affected sectors in Paraguay

The month produced incidents across six sectors, though not with the same intensity or quality of evidence. The public sector carried the heaviest strategic burden because of the cyberespionage case and the mention of compromised government networks. The private sector, meanwhile, stood out for extortion and ransomware, especially in automotive, risk rating, and medical centers.

Banking and financial services also remained in view, though more because of regulation, technology risk, and cybersecurity debate than because of a specific incident. The Paraguayan Banking Convention 2026 added AI, cybersecurity, and digital vulnerability as central themes, while the BCP continued to set fees, payments, and risk-based supervision. That suggests the sector did not face a discrete crisis, but it did face sustained pressure to strengthen controls and governance.

Healthcare was the other sensitive sector during the month. References to medical centers, outdated systems, unpatched vulnerabilities, and the need for crisis response show that the problem was not only malware, but preparedness. The available text also suggests that the affected organizations were already carrying accumulated weaknesses, which often makes recovery harder and prolongs disruption.

Compared with June, July showed a lower total volume of verified events, but more unclassified incidents and a sharp drop in regulatory activity. That does not point to a reduction in risk. It points to a month centered on high-interest incidents and political signals, with less compliance coverage than the previous month. The drop in ransomware or extortion cases from 18 to 11 does not ease the pressure, because those 11 still include confirmed encryption, leak sites and undetermined cases.

The most important signal to watch is the consolidation of the state layer. When an intrusion moves from a diplomatic complaint to a criminal case, it is no longer just a technical matter. Paraguay also ended up in a debate over attribution, digital sovereignty and the security of government networks that is likely to continue in August, especially if new details emerge about scope or affected infrastructure.

It is also worth watching whether July was an isolated peak or the start of a period of greater extortion pressure on private sectors. Automotive, health and risk rating do not belong to the same vertical, but they do share broad exposure and reputational leverage. If the trend continues, the most likely pattern is not a single dominant group, but opportunistic campaigns against targets with low tolerance for disruption.

Compared with June, the clearest shift is qualitative, not numerical, fewer regulatory initiatives, more pressure from ambiguous incidents and a much more mature public discussion about personal data. There is no CVE baseline for comparison, because none were recorded in the material analyzed in July. That should be read as a lack of mention, not as a lack of exploitation in the region.

Security recommendations for teams in Paraguay

  1. Review remote access and require multifactor authentication on VPNs and administrative consoles, especially in government environments and critical vendor operations.
  2. Prioritize data inventory, contract review, updates to privacy policies and records of processing, in line with the new Personal Data Law.
  3. Prepare specific extortion playbooks, with evidence preservation, asset segmentation, backup validation and decision thresholds for operational continuity.
  4. In health care and services with high availability dependence, verify that response plans account for legacy systems, pending patches and degraded operations.
  5. For public entities, strengthen identity monitoring, access correlation and change traceability, since the month’s material suggests persistent intrusion rather than opportunistic noise.
  6. In the financial sector, speed up alignment between compliance, cybersecurity and third-party management, because the regulatory agenda and payment services kept moving at the same time.
  7. Do not treat extortion as a synonym for ransomware. Separating encryption, exfiltration and a simple mention on a leak site improves prioritization and avoids responses that are oversized or, on the other hand, underestimated.

Material limitations

This report was built exclusively from the material provided for Paraguay in July 2026. The facts in the main block are the only ones counted for the period indicators. Facts from previous months were used only as comparative context and should always be read as background, not as July volume. Unconfirmed-dated facts were excluded from the indicators, although they could be used as qualitative context when the source allowed it.

A zero indicator, especially for critical CVEs, means there was no record in the analyzed material during this month. It does not mean that no critical vulnerabilities were exploited in the region or in the country, only that they did not appear in the available July corpus. The same applies to fraud and phishing, their absence in the indicators reflects the material, not the full threat landscape.

The declared time window for the indicators included 51 dated events in July 2026, 3 events from previous months as comparative context, and 11 events without confirmed dates excluded from the counts. Aggregated telemetry, such as automated attempts or blocks, was not used to count incidents or infer severity.

Consumer social networks, sponsored content, and advertorials were also left out of the quantitative body. References to LinkedIn, YouTube, or other spaces not included in the list of available sources were not used as primary evidence. When a claim depended on unresolved journalistic attribution, it was identified as such and not treated as technical certainty.

Sources