CiberLATAMbywhalemate
Intelligence report

Paraguay Cybersecurity Update: September 2026

Ransomware led September in Paraguay with 19 incidents and one Panzer case against Inovapy; there were also 13 unclassified incidents and 9 regulatory

Oct 1, 202618 min read
Paraguay Cybersecurity Update: September 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are completed automatically with verified dated facts from the period. Each one states its basis and counting criterion so the figures reconcile across modules. They are the recurring month-to-month reading, while the analysis that follows develops the cases without repeating this summary.

Indicator window: 63 dated facts in September 2026 · 1 from prior months (comparative frame, not monthly volume). Facts from prior months are used only as a comparative frame in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Monthly verified signal dashboard September 2026 · Paraguay Main threat: Ransomware (19 of 63 events). Coverage: 63 events dated in September 2026 · 1 month an… VERIFIED EVENTS 63 period base: all counts from below is measured against this total RANSOMWARE / EXTORTION 19 1 asset encryption confirmed · 2 exfiltration no encryption (simple extortion) UNCLASSIFIED INCIDENTS 13 breaches or outages without declared threat type FRAUD / PHISHING 6 documented fraud campaigns REGULATION 9 rules, resolutions, or penalties UNIQUE CVEs 0 none in the material analyzed (does not imply absence in the region)
Monthly verified signal dashboard — Base: 63 verified events dated in the period for Paraguay.
MONTHLY FIXED MODULE Threat axis distribution September 2026 · Paraguay Each event counts in only one axis, so the total is exactly 63. "Unclassified incidents" is the remainder. Ransomware 19 Unclassified 15 Incidents 13 Regulation 9 Fraud 6 Vulnerabilities 1
Threat axis distribution — Each event is assigned to one axis based on its classification; the total reconciles to the 63 events in the period.
FIXED MONTHLY MODULE Sectoral Distribution of Signals September 2026 · Paraguay Base: 63 incidents in the period · total 82 because 16 incidents are classified in more than one sector. Public sector / OES 34 Other / unidentified sector… 13 Telecom 8 Health 8 Finance 6 Technology 5 Energy 4 Retail / Consumer 4
Sectoral Distribution of Signals — Heuristic classification by victim sector. One incident may affect more than one sector, so the total may exceed the base.
MONTHLY FIXED MODULE Critical Infrastructure in Paraguay September 2026 · Paraguay 11 of 63 period facts involve critical infrastructure. One fact may appear in more than one category. Public sector / government 31 Explicit critical infrastructure 4 Energy / utilities 47 Telecom / Connectivity 8
Critical Infrastructure in Paraguay — Verified facts about public sector, utilities, and essential services

Executive summary of the month in Paraguay

Paraguay closed September 2026 with ransomware dominating the picture, 19 of 63 verified incidents, alongside a second active front in the financial system, where congressional requests for reports to the Central Bank increased over cyber fraud, prudential supervision, and questionable transactions. At the same time, the country went through a prolonged connectivity outage, while the regulatory debate remained focused on personal data and critical infrastructure.

The clearest extortion case was the attack attributed by Panzer to Inovapy, a Paraguayan technology company, which ended in a public claim on a leak site. The source confirms the claim and the threat of publication, but does not verify encryption of assets. In the rest of the month’s ransomware and extortion cases, most remained in a gray area, with 6 leak-site-only mentions and 10 files in which the material does not allow an exact technical impact to be determined.

Regulatory pressure kept building. There were 9 documented moves, including the progress of the critical infrastructure law and the release of the personal data protection law, which already set an adjustment window for organizations and financial entities until November 2027. On the compliance front, the month’s tone was preventive, not punitive, but there were clear signs that the financial sector will have to operate with greater traceability, reporting, and third-party control.

The overall operational reading is high risk. Not because of a flood of isolated incidents, but because of the convergence of digital extortion, institutional scrutiny of systemic banks, a prolonged connectivity drop, and a regulatory framework pushing organizations to redesign security and data governance processes. Direct source confirmation reached 62%, enough to support the month’s picture without relying on rumors.

Paraguay, September 2026, key signalsBCP issuesalert frauddigitalPanzeragainst InovapyHealthdefacementpublicCongressrushes requestsBGP outage over9 daysSep 24Sep 18Sep 16Sep 9 to 18Sep 15 to 25
Key signals timeline, Paraguay, September 2026 — Verified milestones of the month, focused on extortion, connectivity, and regulation.

Monthly national overview in Paraguay

Paraguay in September showed a mix of technical exposure, regulatory pressure, and reputational noise in the financial system, with high risk from the overlap of extortion, bank fraud, legislative debate, and an internet outage lasting more than nine days. The month was not defined by a single confirmed large-scale breach, but by several simultaneous fronts that affected perception and response.

Ransomware was the most visible vector, but the most sensitive front for decision-making was financial. The Senate and Chamber of Deputies pushed requests for information to the BCP on Itaú, Ueno, and Atlas, with references to cyber fraud, security controls, internal investigations, and probes. The debate was not limited to compliance. It also pointed to solvency, related-party transactions, and the effectiveness of oversight.

At the same time, Congress addressed critical infrastructure, and the country kept debating personal data protection. That overlap matters because the same ecosystem that demands more digitization, such as digital CDA and unified registries, expands the attack surface and increases dependence on technical controls. Paraguay’s current moment looks more like a forced reset than an isolated crisis.

In the regional context, Paraguay is not alone. Ransomware activity in Latin America continued to be driven by opportunistic campaigns against technology and manufacturing, and the country reflected that trend through the Inovapy case and unverified claims about public institutions. The issue was not a lack of signals, but the overlap of signals with different levels of quality and evidentiary maturity.

Paraguay Period Indicators

Indicator September 2026 August 2026 Change
Verified events in the period (base for all indicators) 63 55 +8
Time window for the indicators 63 events dated September 2026 · 1 from prior months (comparative frame, not monthly volume) 55 events dated August 2026 N/A
Unclassified incidents (breaches or outages) 13 11 +2
Cases with ransomware or extortion as the primary focus 19 0 +19
Confirmed asset encryption 1 N/A N/A
Exfiltration without encryption (simple extortion) 2 N/A N/A
Leak site mention only 6 N/A N/A
Classification not determinable from the material 10 N/A N/A
Documented fraud or phishing cases 6 11 -5
Documented regulatory developments 9 11 -2
Critical CVEs mentioned 0 N/A N/A
Sectors with at least one documented event 7 5 +2
Dominant threat of the month Ransomware (19 of 63 events) Unclassified (20 of 55 events) Shift in focus
Events with direct source confirmation 62% N/A N/A

The monthly base is 63 verified events, all dated September 2026, plus 1 event from prior months used only as a comparative frame. The absence of critical CVEs in the material analyzed does not mean there were no vulnerabilities in the region, only that none were recorded in this sample.

Ransomware and extortion breakdown Cases
Confirmed asset encryption 1
Exfiltration without encryption (simple extortion) 2
Leak site mention only 6
Classification not determinable from the material 10

Relevant incidents in Paraguay

Panzer and Inovapy, the clearest case of the month

September's clearest incident was Panzer's claim against Inovapy, a Paraguayan technology company. The primary source describes a threat to publish data if the company did not contact the group, and the monitoring ecosystem logged it as a pending or claimed case, but without public confirmation from the victim.

Breach House, Pulse, GalaxyWarden, RecentBreaches, SecurityArsenal, and BreachSense all match the claim to Panzer and place Inovapy in Paraguay. The key operational point is that the available material does not prove system encryption. It does confirm extortion backed by data publication or leak threats.

Element Verified data
Victim Inovapy
Country Paraguay
Attributed group Panzer
Sector Technology
Confirmed impact Leak claim and publication threat
Confirmed encryption Not supported by the material

Paraguayan connectivity suffered a prolonged degradation

Telecom Observer recorded a significant interruption in Paraguay's connectivity between September 15 and September 25, lasting more than nine days and reaching a severity of 18.310. The report links the episode to BGP anomalies, a drop in normalized traffic, and lower backscatter, although it does not publicly attribute the cause.

The relevant issue is not just the duration, but the way the failure stretched across several days. That points to a network infrastructure event with broad effects on availability and monitoring, closer to systemic degradation than to a point outage.

The Superintendency of Health appeared in a defacement claim

VECERTRadar reported a defacement campaign against domains of Paraguay's Superintendency of Health, signed "Hacked By Ghostteam - Zumarius". The available source does not provide official confirmation or independent evidence of data theft, so the case remains in the realm of unverified attribution.

Even so, the episode matters because it shows offensive activity against a health-sector agency alongside other signs of exfiltration attributed to the same actor. September's material does not allow for a broader impact claim, but it does confirm public exposure of institutional subdomains.

The Ministry of Health was drawn into an unconfirmed preventive alert

VECERT issued a preventive alert about a supposed 10.5 GB exfiltration attributed to the Ministry of Public Health and Social Welfare. The source itself marked the case as unconfirmed and pointed to observable evidence in cybercrime forums, without validating an intrusion or the authenticity of the material.

Diario Judicial later picked up the same line, also describing it as unconfirmed. For the monthly analysis, this remains an alleged extortion or leak signal, not a proven breach.

Congress shifted scrutiny to the banking system

The Senate and Chamber of Deputies spent much of September on requests for information to the Central Bank about Itaú, Ueno, and Atlas. The questions covered cyber fraud, security controls, audits, disciplinary proceedings, and corrective measures, moving well beyond an isolated case and into oversight of the financial system.

At Banco Atlas, the focus also shifted to alleged money laundering, trusts, and administrative actions by the supervisor. At Ueno, the emphasis was on solvency, prudential limits, and related parties. Cyber risk was mixed with reputation, corporate governance, and institutional trust.

Bank or entity Focus of the request Associated risk
Banco Itaú Paraguay Cyber fraud, controls, and disciplinary proceedings Operational and supervisory risk
Ueno Bank Solvency, related parties, prudential limits Prudential and reputational risk
Banco Atlas Money laundering, audits, trusts AML and internal control risk

Threats and active campaigns in Paraguay

Ransomware and extortion: Panzer dominated the month

The month recorded 19 cases with ransomware or extortion as the primary focus, but only one with confirmed encryption. In practice, most of the material describes claims, threats to leak data, or pending statuses, which makes it necessary to separate the narrative of real impact from the extortion narrative with care.

The Inovapy case fits exfiltration without confirmed encryption, because the source refers to a leak threat and aggregators classify it as a leak claim. Other files, such as the alleged healthcare incident, remained undetermined. The monthly picture is one of sustained extortion pressure, not confirmed destruction.

Impact type Cases Readout
Confirmed asset encryption 1 Lower volume, higher technical impact
Exfiltration without encryption 2 Extortion with threat of publication
Mentioned only on a leak site 6 Claim without independent validation
Undetermined classification 10 Insufficient evidence to classify

Fraud and phishing: the banking and social-engineering front

There were 6 documented fraud or phishing cases, fewer than in August, but with a clear concentration in the financial sector and in messaging or urgent-call scams. The BCP and other organizations stepped up warnings about requests for data, suspicious links, token or PIN codes, and calls about account blocks.

The pattern for the month was familiar, identity spoofing, social engineering, and false investment promises. The issue was not technical sophistication, but the persistence of campaigns that exploit urgency, fear, and trust in financial or institutional brands.

Vector Examples this month Official response
Urgent calls about account blocks Warnings from the BCP Do not share data, verify through official channels
Fake links and messages Recommendations from the BCP and 1000 Noticias Do not open links or download suspicious files
Institutional impersonation MADES and other agencies Report it, preserve evidence, confirm identity

APT and hacktivism, with weak but present signals

The material did not show a classic APT campaign with solid attribution. It did include a defacement signal against the Superintendence of Health and a case of alleged exposure in the state ecosystem that can be read as hacktivism or opportunistic intrusion, although without strong attribution or a complete technical chain.

In response terms, public claims by actors like these need to be treated as indicators, not as settled evidence. The combination of defacement, leak claims, and unconfirmed preventive alerts creates operational noise that can escalate quickly if it overlaps with real availability failures.

Critical vulnerabilities with impact in Paraguay

September evidence did not identify any critical CVEs directly linked to a verified intrusion in Paraguay. There were advisories and technical references from CERT-PY and the threat intelligence ecosystem worth tracking, but the material reviewed did not connect them to a confirmed local exploitation.

CVE Software Exploitation Source
CVE-2026-85706 GitLab CE/EE Critical traversal flaw in the commits API, arbitrary file reading; no exploitation reported in Paraguay Mallory Security
CVE-2026-86418 MISP Exposure of organization metadata from the dashboard; applies through 2.5.45 NIST NVD
CVE-2026-86440 MISP Validations to block javascript:, backslash, and unauthorized origins; recommends updating to 2.5.46 or later OpenCVE
CVE-2026-86441 MISP Affects all versions through 2.5.45; requires patching or disabling affected widgets OpenCVE
CVE-2026-86452 MISP Affects all installations through 2.5.45 or earlier OpenCVE

CERT-PY also published advisories on Ubiquiti, Samba, Joomla!, Synology, WordPress, and GitLab, including a critical-severity vulnerability in GitLab. None of those advisories were tied in the material to a concrete Paraguayan intrusion during September.

Regulation and compliance in Paraguay

September's regulatory agenda centered on two areas, personal data protection and critical infrastructure. In both cases, the country is moving toward a stricter framework, with preparedness, notification, and control obligations that directly affect banks, essential operators, and digital providers.

Law No. 7593/2025 on personal data protection was presented as the most significant structural change. According to the material, it takes full effect on November 27, 2027 and includes a 24-month adjustment period. Its scope is broad, covers financial institutions, and provides for a specialized agency within MITIC with oversight, inspection, and sanctioning powers.

Rule or initiative Status in September 2026 Practical effect
Law No. 7593/2025 on personal data Full effect expected for November 2027 Process, notice, record, and legal-basis alignment
Critical infrastructure bill Under legislative review Security, response, and incident-notification plans
Digital CDA and unified registry Technical implementation underway Greater technological dependence across the financial system

For the critical infrastructure bill, the Senate considered a proposal that requires public and private operators to have security and response plans, and it calls for incident notification within up to 12 hours. The text also includes a National Cybersecurity Council, a critical infrastructure registry, and IDS/IPS requirements plus security controls for IoT and operational technologies.

That regulatory package targets the core of operations. It is not limited to paperwork compliance. If approved in those terms, Paraguay will require essential sectors to operate under something closer to a continuity and incident-reporting regime than a general privacy policy.

Most affected sectors in Paraguay

The financial sector drew the most mentions, though not the highest number of confirmed breaches. Requests for reports from the BCP, warnings about digital fraud, and the debate over digital CDA accounts put banks and the regulator at the center of the agenda. That does not mean the system suffered more intrusions than other sectors, only that it faced more public and political scrutiny.

Technology was also highly visible because of the Inovapy case, the clearest ransomware incident of the month. At the same time, health care and public administration surfaced through weaker signals, such as the preventive alert about the Ministry of Health and the defacement attributed to the Superintendence of Health. In both cases, the evidence was thinner than on the financial front, but enough to show a real attack surface.

Sector Type of signal Risk reading
Finance Fraud, oversight, regulation Highly exposed because of public pressure and digitization
Technology Ransomware and extortion Direct impact from extortion against a local provider
Health care Defacement and preventive alerts Signal of exposed surface, with low confirmation
Government Regulatory debate and critical infrastructure Growing demand for preparedness and reporting
Paraguay, sector signal distribution7 sectors with at least one documented incidentFinancial ServicesTechnologyGovernmentHealthcareUnder greater scrutinyPanzer caseData and Critical InfrastructureDefacement
Sector distribution, Paraguay, September 2026 — Sectors with at least one documented incident, according to the verified monthly dataset.

National connectivity also deserves separate mention. A prolonged BGP degradation is not a sector, but it affects everyone across banking, health care, government services, and public platforms. In a month marked by more digitalization, that availability failure was an uncomfortable sign of structural dependence.

September broke with the previous month’s pattern on two fronts. First, the dominant theme shifted from "uncategorized" to ransomware, with 19 of 63 incidents. Second, fraud and phishing fell from 11 to 6, while regulatory moves also edged down slightly from 11 to 9. The picture points to less diffuse noise and more concentration around extortion and governance.

The comparison with August also sharpens the sector view. In September, 7 sectors had documented incidents, compared with 5 the previous month, which suggests a broader narrative and operational surface. The increase is not explained only by more incidents, but by the accumulation of signals in banking, health, technology, critical infrastructure and connectivity.

The main qualitative shift was the arrival of ransomware as the leading threat. In August there were no cases of that type in the previous report base; in September there were, and with a recognizable campaign against a local company. That marks an important change in monitoring priorities for October.

On regulation, the tone declined in volume but increased in density. The personal data law is no longer an abstract item and has become a real compliance calendar. The same applies to critical infrastructure. These are not decorative announcements, but frameworks that will likely start shaping contracts, audits and internal reporting.

Security recommendations for teams in Paraguay

Security teams should focus on three lines of effort in October: tighten identity and fraud controls in digital channels, review exposure of critical services, and prepare evidence to meet upcoming reporting obligations. The month showed that Paraguay's problem is not only technical, it is also one of institutional traceability.

First, in banking and financial services, organizations should strengthen out-of-band verification for sensitive transactions, alerts for account changes, and controls around urgent calls or suspicious links. BCP's warnings show that social engineering fraud remains the most exploitable vector because of its volume and how easy it is to carry out.

Second, organizations handling personal data need to review privacy notices, processing records, legal basis, and incident response procedures. The personal data law requires documentation maturity, but the real impact will come from the ability to prove control over access, third parties, and retention.

Third, for essential operators and technology providers, the priority is operational continuity. Segment access, audit exposed services, review backup and restoration, and test procedures for outages caused by connectivity loss or extortion. September showed that unavailability can also come through the network, not only through malware.

Priority Specific action Target area
High Review authentication flows and anti-fraud verification Banking and payments
High Inventory personal data and processing databases Compliance and legal
Medium Simulate connectivity loss and failover Infrastructure and networks
Medium Validate exposure of public and third-party services Technology and vendors

Frequently Asked Questions

What changed between August and September in Paraguay?

September shifted from a month with no dominant ransomware to one in which ransomware became the main threat, with 19 of 63 incidents. Fraud and phishing also fell from 11 to 6, and regulatory moves dropped from 11 to 9. The focus moved toward extortion, banking, and critical infrastructure.

How confirmed is the Panzer case against Inovapy?

The public claim by the Panzer group is confirmed, as is its appearance on leak sites, but there is no public confirmation from the victim of an intrusion, nor conclusive evidence of encryption. The material supports describing the case as extortion with a leak threat, not a fully validated breach.

What does it mean that there were no critical CVEs in the month’s indicator?

It means the material analyzed in September did not record critical CVEs as part of the period’s events. It does not mean critical vulnerabilities do not exist in the region. In fact, the body of the report mentions CERT-PY advisories and relevant CVEs, but they were not tied to a confirmed Paraguayan intrusion.

Which sectors were most exposed by the combination of incidents and regulation?

Finance, technology, health, and government concentrated the most visible signal. Banking faced pressure from fraud and oversight, technology from ransomware, health from defacement and preventive alerts, and government from the discussion of critical infrastructure and personal data. Connectivity affected all of them across the board.

What should a local CISO look at first after this month?

A local CISO should review identity fraud, service exposure, and incident response capacity. The month showed that an attack can arrive as extortion, impersonation, or network degradation. It is also advisable to align compliance with the personal data law and with future critical infrastructure reporting requirements.

Material limitations

This report was built exclusively from the facts provided for Paraguay in September 2026 and from 1 earlier fact used only as a comparative frame. No external internet sources or material outside the available source list were added. Consumer social networks and sponsored content were excluded unless they appeared as secondary evidence within the already consolidated material.

The time window for the indicators is the one stated in the assignment, 63 facts dated in September 2026 and 1 from previous months as a comparative frame, not the month’s volume. A 0 indicator, especially for the critical CVEs mentioned, means it did not appear in the analyzed material, not that no activity or vulnerability exists in the region.

The ransomware taxonomy also needs careful reading. The material separates confirmed encryption, exfiltration without encryption, a mention only on a leak site, and cases where the source does not allow the impact to be determined. Mixing those categories would give a misleading reading of the real operational risk.

Finally, several September signals are unconfirmed attributions, especially defacements, alleged leaks, and claims by actors such as Zumarius. Those items were used as context, not as confirmation of breaches. When the source did not confirm the incident or marked it as pending, the report treated it accordingly.

Sources