CiberLATAMbywhalemate
Intelligence reportAug 3, 202618 min read

Situación Nacional de Ciberseguridad - Julio 2026 - Uruguay

July closed with vulnerabilities in the lead, 17 regulatory events, and two ransomware cases with different impacts in Uruguay.

Situación Nacional de Ciberseguridad - Julio 2026 - UruguaywhalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are automatically completed with verified dated events within the period. Each one states its basis and counting criterion, so the figures reconcile across modules. They are the recurring month-to-month reading; the later analysis develops the cases without repeating this summary.

Indicator window: 72 dated events in July 2026 · 2 without confirmed date (excluded from the indicators). Events from earlier months are used only as a comparative frame in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Verified Signal Monthly Dashboard July 2026 · Uruguay Primary threat: Vulnerabilities (18 of 72 events). Coverage: 72 dated events in July 2026 · 2 undated … VERIFIED EVENTS 72 period baseline: all counts measured from the bottom on this total RANSOMWARE / EXTORTION 17 2 encrypted assets confirmed · 1 exfiltration no encryption (simple extortion) UNCLASSIFIED INCIDENTS 9 breaches or outages without declared threat type FRAUD / PHISHING 2 documented fraud campaigns REGULATION 17 rules, resolutions, or sanctions UNIQUE CVEs 6 CVE-2026-48907 / CVE-2026-48908
Verified Signal Monthly Dashboard — Base: 72 verified events dated in the period for Uruguay.
MONTHLY FIXED MODULE Threat-axis distribution July 2026 · Uruguay Each event is counted in one axis only, so the total is exactly 72. "Unclassified incidents" is the remainder. Vulnerabilities 18 Ransomware 17 Regulation 17 Incidents 9 Unclassified 9 Fraud 2
Threat-axis distribution — Each event is assigned to a single axis based on its classification; the total reconciles to the 72 events in the period.
MONTHLY FIXED MODULE Sector Breakdown of Signal July 2026 · Uruguay Base: 72 incidents in the period · total 107 because 25 incidents are classified in more than one sector. Public sector / OIV 31 Technology 26 Finance 19 Other / unspecified sec… 14 Telecom 8 Healthcare 5 Retail / consumer 3 Energy 1
Sector Breakdown of Signal — Heuristic sector classification of the victim. One incident may affect more than one sector, so the total may exceed the base.
MONTHLY FIXED MODULE Critical Infrastructure in Uruguay July 2026 · Uruguay 2 of 72 facts in the period involve critical infrastructure. One fact may appear in more than one category. Public sector / government 31 Telecom / connectivity 5
Critical Infrastructure in Uruguay — Verified facts on the public sector, utilities, and essential services

Monthly Executive Summary for Uruguay

July 2026 was a heavy month for Uruguay, with a clear dominant theme, vulnerabilities, which accounted for 18 of the 72 verified events. The clearest signal did not come from a single campaign, but from multiple overlapping layers, critical Microsoft patches with three zero-days, a local CERTuy advisory on Joomla with active exploitation, and international alerts about the wp2shell chain in WordPress Core. The operational takeaway is unambiguous, exposure from outdated or poorly managed software was the main risk vector observed during the month.

At the same time, the country saw intense regulatory activity, with 17 documented moves. The Central Bank of Uruguay advanced a specific framework for Virtual Asset Service Providers, while Electronic Money Issuing Institutions were placed under periodic reporting obligations tied to cybersecurity capabilities. Added to that was Decree No. 168/026, which tightens incident management across the Central Administration and formalizes response, remediation, and reporting obligations to AGESIC. The result is a month in which cybersecurity stopped being only a technical issue and became more closely tied to prudential, compliance, and accountability duties.

On the incident side, there were notable signals in the public and financial sectors. The websites of Hospital de Clínicas, INISA, and other Uruguayan institutions were hit by an automated vulnerability-hunting campaign that led to outages and defacement. Banco Hipotecario del Uruguay remained at the center of attention because of an October 2025 attack, with 700 gigabytes leaked on the dark web and operational and reputational costs still unresolved at the time of the July coverage. Although part of the material comes from news reporting and third-party platforms, the overall picture reflects persistent exposure in the country’s public and financial infrastructure.

There were also signs of ransomware activity in the country, although with different levels of confirmation and different types of impact. The clearest case in the month was ACU, the Automobile Club of Uruguay, listed by Deadlock, with data exfiltration before encryption according to the intelligence sources consulted. Another Uruguayan entity appeared on leak sites linked to Section9, but with no public confirmation of the victim and not enough precision about encryption or exfiltration, so it should be read as a claim that was not independently verified. A third extortion thread was the BHU case, where there was indeed extensive data leakage, although the incident dates back to October 2025 and only resurfaced in the public agenda in July.

The month’s risk picture is high. Not because of a single massive live breach, but because of the combination of a broad attack surface, active exploitation of critical CVEs, public incidents with operational impact, and a regulatory block that imposes more traceability and responsibility on operators. The country also exposed, in public debate, a growing tension between digitalization and exposure, something several local articles described clearly in July.

National Snapshot for the Month in Uruguay

Uruguay closed July with a concentrated set of verified signals spread across critical vulnerabilities, financial regulation, and state responses to incidents. The main threat was exposed software. CERTuy warned about Microsoft’s July patch bundle, with two zero-days actively exploited in Active Directory Federation Services and SharePoint Server, and the local agency also issued its own alert on Joomla vulnerabilities with active exploitation in the wild. At the same time, Uruguay’s ecosystem continued to absorb the impact of automated campaigns and extortion cases that were already underway or that appeared on leak sites without enough public confirmation.

The risk reading for Uruguay in July is high. The reason is not only the volume of events, but their mix. There were incidents affecting availability in the public sector, leaks with financial and operational impact at the BHU, two ransomware cases with different levels of evidentiary support, and a regulatory block that requires financial and state actors to institutionalize better practices. In other words, the month showed a broad attack surface, a more mature policy response, and still insufficient control over exposed software in public and corporate environments.

At the regional level, the Uruguay case fits a trend repeated across Latin America, the rapid exploitation of vulnerabilities in widely used products and the use of leak sites as a reputational pressure tactic, even before there is full public confirmation. Uruguay was not isolated from that dynamic. On the contrary, July placed it among the countries where the tension between digitalization, compliance, and operational resilience was especially visible in the same month.

Period indicators in Uruguay

Indicator Value
Country Uruguay
Period July 2026
Time window for indicators 72 dated events in July 2026 · 2 without confirmed date (excluded from indicators)
Verified events in the period 72
Unclassified incidents (breaches or outages) 9
Cases with ransomware or extortion as the primary focus 17
Confirmed encryption of assets 2
Exfiltration without encryption (simple extortion) 1
Mention on leak site only 3
Cases where classification could not be determined from the material 11
Documented fraud or phishing cases 2
Documented regulatory moves 17
Critical CVEs mentioned 6
Sectors with at least one documented event 7
Dominant threat of the month Vulnerabilities (18 of 72 events)
Events with direct source confirmation 79%

Relevant incidents in Uruguay

Hospital de Clínicas and INISA, automated campaign against vulnerable sites

On July 9 and 10, the websites of Hospital de Clínicas, INISA, and other Uruguayan public institutions were affected by a series of cyberattacks that, according to coverage, were carried out by an automated program searching for vulnerable sites. The available material does not describe a targeted intrusion with persistence or any confirmed data theft. What is verified is the impact on availability, and the fact that several pages went down or were altered. Operationally, this places the case closer to an opportunistic mass exploitation campaign than to a directed operation against a specific entity.

Banco Hipotecario del Uruguay, lasting effects of a 2025 attack

BHU remained on the agenda during July because of a cyberattack that occurred in October 2025. The sources consulted describe access to infrastructure, data theft, ransom demands, and the publication of material on the dark web after nonpayment. In July, reporting also solidified the reference to 700 gigabytes leaked and to multimillion-dollar losses with ongoing operational problems. This case matters for two reasons. First, it shows that the damage from an intrusion can extend far beyond the date of the attack. Second, because the incident again exposed an institutional weakness, including the absence of a cybersecurity officer at that time, according to press coverage.

Yamandú Orsi deepfakes in financial scams

Nación.com.uy reported, citing Revelum, the detection of 19 fraudulent ads using President Yamandú Orsi's image and voice in financial scams between January and July 2026, with 16 detections concentrated between July 21 and 23. The material does not allow confirmation of the exact number of victims or the full distribution channel, but it does mark a clear sign of public identity abuse for financial fraud. From a risk perspective, this type of scam combines social engineering, institutional trust, and the speed of synthetic audiovisual campaigns.

Decree No. 168/026 and formal incident response

Although not an incident in the strict sense, Decree No. 168/026 is relevant as a direct response to the exposure context. The Uruguayan state added more specific obligations for the Central Administration in response to confirmed information security incidents. The rule requires administrative procedures to be started immediately and, when the problem is related to insufficient planning, inadequate processes, obsolete systems, or noncompliance with the cybersecurity framework, it requires corrective measures and notification to AGESIC. This does not reduce risk on its own, but it does establish a clearer response standard.

Threats and active campaigns in Uruguay

Ransomware and extortion in Uruguay, ACU, and leak site cases

Confirmed asset encryption, ACU and Deadlock

The month’s strongest ransomware case is ACU, the Automobile Club del Uruguay, listed by Deadlock on ransomware.live, with discovery dated July 10. The associated intelligence source and follow-up coverage indicate that exfiltration took place before encryption. In this case, the operational impact was not limited to a mention on a leak site. The appearance on the victim portal and the actor’s description point to an intrusion involving double extortion techniques.

Exfiltration without encryption, BHU as a materialized extortion case

Banco Hipotecario del Uruguay appears in July as the clearest example of exfiltration with material impact. Sources describe information theft, a ransom demand, and the later publication of material on the dark web after payment was not made. The incident was attributed by the press to the Crypto24 group. Although the original date of the attack is October 2025, the persistence of its effects in July 2026 justifies its inclusion in the qualitative part of the report, not in this month’s incident base. For taxonomy purposes, what can be verified is exfiltration and extortion, with damage that continued over time.

Leak site only, Section9 and an unconfirmed Uruguayan entity

In July, several monitoring services placed a Uruguayan entity, with the domain hidden in the material, in connection with the Section9 group. Breach House, Recentbreaches, Darkfield, GalaxyWarden, and Dexpose all placed the case on July 26 or 27 and mentioned exfiltration or a publication threat, but there was no public confirmation of the affected organization and not enough precision to say with confidence whether encryption occurred. For that reason, the case should remain in the leak site mention category or undetermined classification, depending on the source consulted.

Fraud and phishing in Uruguay

Financial deepfakes using the president’s image

The Revelum report cited by Nación.com.uy is the clearest fraud case of the month. This is not classic email phishing, but fraudulent ads using deepfakes of a public figure to induce investment or divert money. The case shows an evolution in deception, more visual, more convincing, and with high segmentation potential. The most striking detail is the rapid pace over just a few days, with 16 ads detected between July 21 and 23.

Warning on poorly designed automations and AI

El País Uruguay and El Correo do not report a concrete fraud operation involving a specific organization in the country, but they do highlight a concern that became part of the local debate in July, AI systems and automations performing broader actions than intended because of design problems. This does not count as a fraud incident, but it does add context for future abuse of automation and privilege escalation campaigns.

APT, hacktivism, and opportunistic campaigns in Uruguay

The July material does not show strong evidence to attribute a classic APT campaign against Uruguay. What does appear is opportunistic, large-scale activity, with exploitation of vulnerable sites and leak sites used to increase pressure on victims. The campaign involving sites from Hospital de Clínicas and INISA fits better as automated exploitation than as a persistent actor with strategic objectives. That distinction matters because it changes the needed containment approach, from hardening exposure and patching to reviewing credentials, logs, and persistence mechanisms.

Threat type Case Verifiable impact Note
Ransomware ACU, Deadlock Exfiltration before encryption according to follow-up sources Victim identified in intelligence portals
Extortion BHU, Crypto24 700 GB leaked and ransom demanded The original attack is from October 2025, with effects still active in July
Leak site Uruguayan entity associated with Section9 Mention and publication threat, without public confirmation The source does not specify whether encryption occurred
Fraud Yamandú Orsi deepfakes 19 fraudulent ads between January and July, 16 in three days in July Risk of social engineering and financial fraud

Critical vulnerabilities affecting Uruguay

The vulnerability agenda dominated the month and was backed by local and external sources. CERTuy was the most relevant actor for Uruguay, because it not only circulated Microsoft’s advisory but also issued its own alert on Joomla. That was joined by advisories from other response teams that help frame the severity of the exposure.

CVE Software Exploitation Source
CVE-2026-56155 Active Directory Federation Services Actively exploited, included in KEV CERTuy, 22 de julio de 2026
CVE-2026-56164 SharePoint Server Actively exploited, included in KEV CERTuy, 22 de julio de 2026
CVE-2026-50661 BitLocker Publicly disclosed, with no evidence of active exploitation at the time of the alert CERTuy, 22 de julio de 2026
CVE-2026-48907 Joomla Content Editor, JCE Documented vulnerability, with no active exploitation mentioned in the source CERTuy, 8 de julio de 2026
CVE-2026-48908 SP Page Builder for Joomla Active exploitation in the wild CERTuy, 8 de julio de 2026
CVE-2026-49049 Helix3 for Joomla Documented vulnerability, with no active exploitation mentioned in the source CERTuy, 8 de julio de 2026

These flaws point to two clear takeaways for Uruguay. First, Windows environments and Microsoft 365 or SharePoint remain a high-value attack surface for opportunistic and advanced threat actors. Second, CMS platforms and third-party extensions, especially Joomla, remain a classic weak point in institutions that manage public or semi-public sites with irregular update cycles.

Regulation and compliance in Uruguay

July was a particularly active month for regulation. The Central Bank of Uruguay approved a specific framework for Virtual Asset Service Providers, with requirements for authorization, corporate governance, compliance, auditing, and information security. The regulatory package includes the need to appoint independent officers outside the technology area, conduct annual external audits on service continuity and cyberattack resilience, and meet additional operational and user protection obligations. Different media outlets summarized the rule from complementary angles, but the core is the same, more oversight, more segregation, more control.

For Electronic Money Issuing Institutions, starting on July 1, 2026, they must periodically report their cybersecurity capabilities to the BCU. This is an important shift because it turns cybersecurity into regulatory supervision data, not just an internal practice. The message is clear, the regulator wants comparable data and a baseline of resilience across the financial system.

Decree No. 168/026, approved on July 17 and officially published on the 30th, completes the picture from the state side. The measure requires the Central Administration to activate administrative procedures immediately after incidents, and sets consequences if problems are linked to lack of foresight, inadequate processes, or outdated systems. The logic is institutional maturity, although its effectiveness will depend on actual implementation, internal timelines, and AGESIC’s ability to support and supervise.

Date Regulation or action Scope Cyber relevance
July 1, 2026 Start of periodic reporting for IEDE Financial system Supervision of cybersecurity capabilities
July 10, 2026 Final PSAV regulation, according to ECIJA Virtual assets Corporate governance, compliance, and security
July 16, 2026 Circular No. 2507 from the BCU, according to El Observador PSAV Comprehensive framework for virtual asset providers
July 17, 2026 Decree No. 168/026 Central Administration Formal incident handling and required adjustments
July 30, 2026 Official publication of the decree Central Administration Regulatory validity and public notice

Sectors most affected in Uruguay

The sectors most affected by July's activity were public sector, financial services, technology, transportation, and food and services. This distribution should be read as overlap, not as separate silos. The same incident can affect more than one sector, for example, a breach at a financial institution carries regulatory, reputational, and operational impact at the same time.

The public sector faced two kinds of pressure. On one hand, direct impact on the websites of institutions such as Hospital de Clínicas and INISA, with an automated pattern of vulnerability scanning. On the other, the regulatory shift driven by Decreto N.º 168/026 and the Rendición de Cuentas bill, which requires annual cybersecurity reports. That dual move, incident plus regulation, suggests Uruguay's public sector came under pressure from both technical exposure and administrative demands.

The financial sector appeared on several fronts. BHU continued to show the effects of a major attack with a large-scale leak, while the BCU tightened the framework for PSAV and IEDE. The contrast is telling. The regulator recognized that the attack surface is no longer limited to traditional banking, but also includes cryptoasset and electronic money ecosystems. In practice, operational risk and compliance risk became much more closely tied.

In transportation and automotive services, ACU appeared as a victim linked to Deadlock. In food and services, the case tied to Section9 showed that ransomware actors are still targeting organizations with operational and reputational value. Finally, the deepfake fraud block overlaps with the financial sector, although the abuse itself stems from the use of a political identity and not from a specific financial platform.

There is no formal comparative baseline available for this country, because this is the first archived period with this indicator format. For that reason, no monthly change against June should be inferred. Even so, July does surface several signals worth tracking.

The first is the dominance of vulnerabilities. If 18 of the month’s 72 verified events fall into this category, the message is that Uruguay remains highly exposed to patch cycles from major vendors and to flaws in widely used software, especially Microsoft and third-party CMS platforms. The Joomla case and the Microsoft package show that the window between disclosure and exploitation remains very short.

The second is the consolidation of extortion as a pressure tactic, beyond encryption. In July, one confirmed encryption case, one exfiltration and ransom case, and several appearances on leak sites with incomplete classification coexisted. This suggests operators still value data publication, even when they do not achieve full technical impact on the infrastructure.

The third is the institutionalization of response. Uruguay is moving from issuing alerts and documenting incidents to demanding reports, audits, and formal accountability. The BCU and AGESIC are pushing in that direction. It remains to be seen whether agencies and operators turn that regulatory pressure into practical changes in inventory, patching, privilege segregation, and operational continuity.

The fourth is the growth of synthetic fraud. The deepfakes of Yamandú Orsi are a warning about social engineering campaigns that are more convincing and harder to stop with traditional controls. If material of that kind circulated widely in July, more attempts to abuse public or corporate identity are likely in the months ahead.

Security recommendations for teams in Uruguay

Prioritize remediation of the components cited by CERTuy, especially the vulnerabilities actively being exploited in Active Directory Federation Services, SharePoint Server and SP Page Builder for Joomla. If there is public exposure, response time should be measured in hours, not days. In Microsoft environments, also review coverage of the rest of the July patch set, because the local advisory highlights a much broader attack surface than the zero-days.

Review the inventory and exposure of CMS platforms, extensions and plugins. The campaign against Joomla and the description of the mass defacement of Uruguayan sites show that public-facing pages remain an easy target when the update cycle falls behind. Manual verification that patches were actually applied, rotation of administrative credentials and review of privileged accounts remain basic measures that cannot be left to platform inertia.

In the financial sector and among virtual asset providers, align regulatory obligations with technical controls. The new BCU framework should not be treated as a paperwork exercise. Requiring an independent security lead, external audits and evidence of resilience against cyberattacks forces organizations to organize records, continuity, fund segregation and incident response. If that documentation does not translate into real tests, drills and internal metrics, compliance will be fragile.

In public agencies, formalize incident response under Decreto N.º 168/026. That means clear escalation paths, designated owners, criteria for reporting to AGESIC and traceability for remediation efforts. It also makes sense to review institutional websites exposed to the internet, because the mass attack against public pages showed that the risk does not always come from a sophisticated intrusion, but from low-cost automation against poorly maintained attack surfaces.

Strengthen anti-fraud controls for synthetic media and impersonation campaigns. The Yamandú Orsi deepfakes show that visual verification is no longer enough. Security and communications teams should define procedures for public alerts, ad takedowns, brand monitoring and out-of-band confirmation when suspicious audio or video pieces appear.

Priority Action Target area
High Patch actively exploited CVEs Microsoft, SharePoint, AD FS, Joomla
High Review privileges and administrative accounts Websites, CMS and public portals
High Test incident response and escalation Central Administration and regulated financial entities
Medium Audit continuity and resilience PSAV, IEDE and critical providers
Medium Monitor fraud with deepfakes and brand abuse Finance, institutional communications

Technical appendix: indicators of compromise and TTPs

Section9 and Deadlock, domains and observable footprints

July material includes at least one explicit IOC in the Section9 case. ransomware.live publishes for the Section9 group the compromise identifier 0CB7BEB4F390737D72070C4DAD8C1516A962C333DE7668ACA379CAA0DD7F1277CB6703B746B4, tied to its communications infrastructure. This data is useful for detecting contacts or infrastructure linked to the operator.

In the ACU and Deadlock case, the sources consulted do not provide hashes, IPs, or C2 domains, but they do include references to victimology and timing. The first-observed date reported by ransomware.live was July 10, 2026, and the associated sector was transportation and logistics. GalaxyWarden and Pulse descriptions point to a data exfiltration pattern before encryption, consistent with double extortion.

TTPs observed in July campaigns

In the Uruguayan sites affected by the automated July campaign, the pattern described was a bot scanning thousands of sites for a specific vulnerability. In the technical version shared on YouTube, the use of outdated Joomla extensions is suggested, although that should not be taken as independent confirmation. Even so, the TTP logic is clear, mass reconnaissance, exploitation of public-facing surface, and availability disruption.

In the ransomware and extortion cases, the repeated tactic was pressure through publication of data or the threat of publishing it. BHU shows the classic variant with theft, ransom, and leakage after nonpayment. Section9 appears closer to the leak site ecosystem with a public threat. ACU, according to the intelligence sources, would have followed a double-extortion logic.

Material limitations

This report was built exclusively from the material provided for Uruguay, without internet access or additional external validation. The reporting window for the indicators is July 2026, with 72 dated events within the period and 2 without a confirmed date, which were excluded from the counts. Events from earlier months were used only as qualitative context when they were clearly identified as such, for example the BHU attack that occurred in October 2025. Aggregated telemetry was not added to the indicators, because material on attempts, scans or blocks does not constitute incidents.

When an indicator appears as 0, that means it did not appear in the material analyzed for the month, not that it did not happen in Uruguay or the region. This distinction is especially relevant for CVEs and for certain fraud or disruption categories. In this case, critical CVEs were mentioned, but the principle remains valid for any reading of absence. The absence of evidence in the corpus does not mean the absence of a real-world event.

Items without a confirmed date were also left out of the counts, even if they may provide context. In addition, the corpus includes sources of varying quality, from CERTuy, AGESIC, BCU and other official bodies to media coverage and ransomware intelligence platforms. Sponsored sources, commercial statements, consumer social networks and publications not included in the authorized list were excluded as evidence. When a claim depended on third-party monitoring or secondary coverage, that attribution was preserved and was not treated as official confirmation unless the material allowed it.

Sources