Uruguay Cybersecurity Situation, September 2026
More ransomware, more fraud, and more regulation: September closed with 67 verified incidents, 14 extortion cases, and 9 regulatory measures.
Key findings
- Blanco & Etcheverry was the month’s most serious incident, with confirmed encryption, a ransom demand, and a later data leak.
- Total volume rose from August, with 67 verified incidents and more ransomware, fraud, and unclassified signals.
- The UTE impersonation and WhatsApp takeover scam showed that social engineering fraud remains the most lucrative vector.
- The BCU pushed major changes in virtual assets, strengthened authentication, and open finance, with a focus on control and compliance.
- The government agenda moved in parallel on forensic investigation, international cooperation, and early incident notification.
- No critical CVEs appeared in the material analyzed, but extortion, leaks, and reputational risk were high.
- The gap between business concern and effective control adoption remains a baseline signal for the Uruguayan market.
Monthly reference modules
These modules are populated automatically with verified dated events from the period. Each one states its source basis and counting criterion so the figures reconcile across modules. They are the recurring month-by-month readout; the later analysis expands the cases without repeating this summary.
Indicator window: 67 dated events in September 2026 · 8 from prior months (comparative frame, not month volume) · 1 without a confirmed date (excluded from the indicators) · 5 after the period (excluded). Prior-month events are used only as a comparative frame in the analysis, never as volume for this period.
Executive monthly summary for Uruguay
The month closed with 67 verified incidents in Uruguay, a heavier signal load than in August and a mixed pattern: ransomware and extortion cases increased, documented fraud also rose, while the relative weight of regulation declined. The clearest case of the month was the intrusion against the law and accounting firm Blanco & Etcheverry, attributed to Gunra, with encryption, a ransom demand, and later data disclosure.
September shows a country where harm is no longer concentrated only in major incidents, but also in impersonation, messaging scams, and leaks with reputational and legal impact. The Ministry of the Interior warned about a scam that uses a fake UTE procedure to take over WhatsApp accounts and ask the victim’s contacts for money. That was accompanied by a conviction for computer fraud and a series of official workshops to strengthen investigation, digital evidence, and international cooperation.
On the regulatory side, the agenda stayed active. The Central Bank of Uruguay advanced the regime for virtual asset service providers, with applications opening on September 1, and launched a public consultation on new requirements for stronger authentication and complaint handling in electronic transactions. The open finance project also took shape, along with warnings about managing financial data in a more interconnected infrastructure.
The operational reading for the month is medium to high risk, not because of a wave of critical vulnerabilities, none appeared in the material reviewed, but because of the combination of higher incident volume, a large share of unclassified events, and repeated signs of extortion, fraud, and data exposure. The confirmation quality was relatively good, with 79% of the events directly backed by their source.
Monthly national overview in Uruguay
Uruguay posted a broad activity picture in September, with 67 verified incidents and seven sectors with at least one documented case. No single threat category dominated, because 24 incidents could not be classified precisely, but two clear clusters stood out: extortion and ransomware on one side, fraud and phishing on the other. Qualitatively, that places the month in medium-high risk.
The most visible pressure centered on user-deception campaigns and data leakage. The fake UTE official, WhatsApp account takeover, and the collection of codes by SMS form a simple and effective chain, far from sophisticated technical exploitation, but with real impact on people and their contacts. The Radar report for Datasec published by InfoNegocios reinforces that reading: 63% of companies say they are fairly or very concerned about incidents, but only 20% believe they have fully implemented the necessary measures.
The other layer of the month was regulatory. The BCU not only continued expanding the perimeter around virtual assets, but also pushed higher standards for authentication, complaints handling, and open finance. That agenda runs alongside warnings from AEBU about leaks and fraud if interoperability moves forward without uniform security requirements. In other words, Uruguay’s financial system is digitizing faster than some control practices are maturing.
At the regional level, September in Uruguay looks similar to other Latin American markets where regulatory maturity, fraud pressure, and ransomware campaigns focused on exfiltration coexist. The difference is that the country shows a strong institutional role, both through CERTuy activity and through the response from the Ministry of the Interior and the Central Bank. The problem is not a lack of response, but the speed at which the fronts are multiplying.
Uruguay period indicators
| Indicator | Value |
|---|---|
| Verified facts in the period (basis for all indicators) | 67 |
| Indicator time window | 67 facts dated September 2026 · 8 from prior months (comparative frame, not monthly volume) · 1 without confirmed date (excluded from indicators) · 5 after the period (excluded) |
| Unclassified incidents (breaches or outages) | 11 |
| Cases with ransomware or extortion as the primary focus | 14 |
| Ransomware breakdown by impact type: Confirmed asset encryption | 2 |
| Ransomware breakdown by impact type: Exfiltration without encryption (simple extortion) | 1 |
| Ransomware breakdown by impact type: Mentioned only on leak site | 2 |
| Ransomware breakdown by impact type: Type not determinable from the material | 9 |
| Documented fraud or phishing cases | 9 |
| Documented regulatory moves | 9 |
| Critical CVEs mentioned | 0, none in the analyzed material (does not imply absence in the region) |
| Sectors with at least one documented fact | 7 |
| Predominant threat of the month | Unclassified (24 of 67 facts) |
| Facts with direct source confirmation | 79% |
Relevant incidents in Uruguay
Blanco & Etcheverry and the Gunra attack
The clearest case of the month was the attack against the legal and accounting firm Blanco & Etcheverry, where the Gunra group encrypted information, demanded a ransom, and then released about 300 GB of data when payment did not materialize. The local primary source also verified the publication on the dark web, making this episode the strongest and most damaging incident of the period.
El Observador also reported that the leaked material included information on at least 35 individuals and 149 companies, according to Team Capybara's analysis. That exposure did not show credentials, keys, passwords, or specific identity documents, but it did reach a confidentiality level described as critical in the cited report.
The impact did not stop at the firm. The same coverage placed Blanco & Etcheverry as the third Uruguayan company listed by Gunra in less than three months, which suggests the group is maintaining pressure on local targets. For the country, the relevant point is not only the volume of the leak, but the repeated appearance of Uruguayan victims under the same criminal operator.
UTE impersonation scam and WhatsApp account takeovers
The Ministry of the Interior warned about a impersonation scheme in which an attacker poses as a UTE employee, asks for the victim's mobile number, and then requests the code received by SMS to take over WhatsApp. Once inside the account, the criminal asks the victim's contacts for money, turning an access fraud into a social spread scam.
Police in Rocha reported a specific case with that pattern, and Telenoche detailed that the victim received a call offering to change the meter. The attack is simple to carry out, but effective in reach: it uses trust, urgency, and reuse of the messaging channel to amplify harm.
The official response was preventive and practical. The Ministry of the Interior recommended ending suspicious calls, not sharing personal data or SMS codes, and using the Verifica service on WhatsApp. That guidance fits the threat pattern of the month, which favored user deception over technical intrusion.
Fraud conviction in Montevideo
The Ministry of the Interior reported the conviction of M.D.R.M. for two counts of computer fraud, with a six-month sentence replaced by probation. The case did not match the scale of a major corporate incident, but it did add something important to the month, a concrete court ruling under the new criminal classification.
The coverage shows how cybercrime law is beginning to organize cases that could previously have remained blurred within broader offenses. In September, that evolution was also visible in public debate about the rise in complaints, and in the distinction between fraud, cybercrime, and computer fraud.
International cooperation, digital evidence, and new tools
The Ministry of the Interior hosted a day of international cooperation on cybercrime, digital forensics, and digital evidence, with participation from authorities in Uruguay, Argentina, the United States, and UNODC. It also announced the addition of forensic tools and a 260-hour diploma program to strengthen local capabilities.
The agenda has a clear operational value: Uruguay appears to be investing in investigative capacity and evidence preservation, not only prevention. The introduction of Espejo Chubut, the software for extracting and preserving data from phones in a traceable way, points specifically to reducing friction in the handling of digital crime evidence.
Data risks in the Caranchos case
The eight-police-officer conviction in the so-called Caranchos case showed the misuse of privileged information and the leak of personal data from traffic accident victims. It is not a classic digital intrusion case, but it is an information security incident with direct consequences for confidentiality and abuse of internal access.
For the monthly reading, this episode matters because it is a reminder that part of the risk in Uruguay still comes from the improper handling of data inside institutional structures. Not all of the problem is outside, in external criminal actors.
Threats and active campaigns in Uruguay
Ransomware and extortion, with a focus on Gunra
September produced 14 cases with ransomware or extortion as the primary focus, but the details are not uniform. Only two have confirmed asset encryption, one was limited to exfiltration without encryption, two appear only as mentions on leak sites, and nine could not be classified precisely from the available material.
The Blanco & Etcheverry case is the clearest example of encryption followed by leakage. Gunra not only claimed the attack, but also published data when it did not get paid. By contrast, the available information is not enough to reconstruct the technical impact of several other claims associated with the group with precision.
That calls for caution. The presence of a name on a leak site does not, by itself, prove a breach or confirmed data theft. In September, Gunra’s activity in Uruguay was visible enough to treat it as an active campaign, but the material does not always allow a move from claim to forensic classification.
Fraud and phishing in accounts, payments, and impersonation
The month logged 9 documented fraud or phishing cases, with a pattern heavily concentrated in identity abuse and messaging. The UTE and WhatsApp scam is the clearest reference point, but it was not the only one. Official and press coverage also pointed to a rise in digital scam complaints in the country.
Coverage by la diaria and Prensa Latina describes the phenomenon as mass-scale and professionalized, with actors specialized in access, tooling, attack, and collection. The complaints data should not be read as a technical measure of intrusions, but it does signal sustained pressure on reporting and response systems.
The takeaway for security teams is direct. User authentication controls, impersonation alerts, and education about SMS codes remain basic barriers. This month’s fraud did not rely on complex malware, but on trust abuse and conversation hijacking.
APT, hacktivism, and other campaigns
The material did not show solid signs of an APT or hacktivist campaign with verifiable attribution for September. There were references to critical infrastructure, international cooperation, and protection of public entities, but not to a persistent actor with an identified campaign during the period.
That does not mean the absence of advanced threat activity, only the absence of sufficient evidence in the material reviewed. In practice, the month was dominated by extortion, leaks, and fraud, not espionage or politically motivated activity.
Critical Vulnerabilities Affecting Uruguay
In the September material reviewed, no critical CVEs were found that could be verified as linked to incidents in Uruguay. That does not mean there are no active vulnerabilities in the region, only that they were not documented in the sample used for this report.
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| No critical CVEs were recorded in the material analyzed | N/A | N/A | Period indicator |
Regulation and compliance in Uruguay
Regulatory activity was intense and covered three fronts, virtual assets, open finance, and the security of electronic operations. On Sept. 1, the BCU opened the application process for virtual asset service providers, and the framework was brought under its supervisory perimeter.
That regulatory expansion is not just formal. The process requires authorization, analysis of legality, business viability, source of funds, and the reputation of shareholders and directors. It also reinforces a key anti-money laundering principle, registering the provider is not enough, the regulator must assess who is operating and under what controls.
In parallel, the BCU Superintendency of Financial Services opened a public consultation on a draft that raises enhanced authentication requirements for card-not-present transactions and for linking electronic instruments to digital wallets. It also sets response deadlines for complaints involving foreign institutions, which brings more order to dispute handling and narrows gray areas.
The debate over open finance was the other major focus. The draft aims to share financial data through APIs, with prior, express, informed, and revocable consent, and to move practices such as screen scraping toward authorized and supervised channels. At the same time, AEBU warned that interoperability without minimum standards could increase data leaks, fraud, and other cybercrime.
The state also advanced on critical infrastructure. The critical infrastructure protection bill calls for a national registry, security plans, IDS/IPS, protocols for operational technologies and IoT, and incident notification to the state within a maximum of 12 hours. If approved as written, it would be one of the country's strictest early-notification frameworks.
The broader regulatory signal is clear. Uruguay is trying to bring order to a fast-growing financial and digital ecosystem while also tightening security and reporting requirements. That applies to banks, fintechs, virtual asset providers, and critical infrastructure operators.
Most affected sectors in Uruguay
The hardest-hit sector, based on the quality and type of incidents documented, was professional services, led by the Blanco & Etcheverry case as the clearest and most serious ransomware incident. It combined encryption, exfiltration, public leaking, and impact on clients and counterparties, a more sensitive mix than a simple leak site complaint.
The second focal point was the financial and regulated ecosystem. Not because there was a major visible banking breach this month, but because regulation, fraud complaints, and the advance of open finance put the financial system at the center of the conversation. BCU, AEBU, and SENACLAFT set the pace for the month on that front.
The public sector and citizen security also stood out. The Ministry of the Interior concentrated communications on fraud, international cooperation, digital evidence, convictions, and new forensic tools. That shows a state sector that is not only responding, but also trying to professionalize investigative capacity.
Energy and utilities showed a different dimension, one more tied to critical infrastructure and awareness. UTE and CIER put the cybersecurity of digital power grids on the agenda, although there were no concrete incidents tied to the sector during the period. The value there was preventive and coordination-focused, not reactive.
The sector breakdown also sends a negative signal. Only seven sectors had documented incidents this month, one fewer than in August, but within that relative decline the weight of fraud and ransomware cases increased. No single sector dominated everything, but there was a clear concentration in services, finance, government, and utilities.
Trends and signals to watch in Uruguay
Compared with August, total activity was higher, along with more unclassified incidents, more ransomware or extortion, and more fraud or phishing, while regulation fell as a share of the total. In figures, verified incidents rose from 49 to 67, unclassified incidents from 6 to 11, ransomware or extortion from 8 to 14, and fraud or phishing from 5 to 9. Regulation fell from 16 to 9 incidents.
That does not mean regulatory pressure eased in terms of significance. What changed was the month’s mix, with more operational events and more cases that resisted finer classification. In August, the leading threat was Regulation, with 16 of 49 incidents. In September, it shifted to Unclassified, with 24 of 67.
The decline in documented sectors, from 8 to 7, also points to a sharper concentration of signals across fewer fronts. Taken together with the increase in ransomware and fraud, that points to a month more driven by direct impact than by policy debate. The Gunra case reinforces the trend toward extortion with public exposure of data, a formula that continues to work against Uruguayan victims.
Another signal to watch closely is the gap between perception and preparedness. Radar’s study for Datasec, published by InfoNegocios, shows strong business concern, but also low formalization of policies, owners, and backups. That is consistent with a growing market, where the attack surface is expanding faster than controls.
September’s picture also offers a lesson about the state’s role. CERTuy, Interior, and BCU appear active and present, but the range of incidents suggests defense does not depend on institutional response alone. The critical issue is the operational maturity of organizations and users.
Security recommendations for teams in Uruguay
- Review stronger authentication controls in payment channels, wallets, and non-face-to-face transactions, especially where instruments are linked to mobile devices.
- Tighten verification procedures for calls, SMS messages, and requests for one-time codes. This month’s fraud showed that account takeover through social engineering remains the most profitable vector.
- Prepare a clear incident workflow for possible exfiltration, because several cases this month were not fully classified, and the difference between leakage, encryption, and a leak site claim changes the legal and technical response.
- Keep evidence logs and forensic preservation aligned with notification timelines, especially in sectors that may fall under 12-hour or 24-hour rules depending on the applicable regime.
- Review third-party and vendor exposure, especially in open finance, virtual assets, and professional services with customer data. This month showed that damage does not always come through the traditional perimeter.
- Confirm that backups are tested and restorable. In the September report, a significant share of the operational problem appeared as loss of control, leakage, or extortion, situations where recovery depends on both backup and traceability.
- Train customer service, help desks, and front office teams to spot impersonation tied to utilities, banks, or support areas. If the first point of contact fails, the rest of the control comes too late.
Frequently Asked Questions
What changed between August and September in Uruguay?
Verified incidents rose from 49 to 67, ransomware or extortion cases increased from 8 to 14, and fraud or phishing cases also climbed from 5 to 9. At the same time, regulatory activity fell from 16 to 9. The full comparison is in the indicators section and in Trends and signals to monitor.
How severe was the Blanco & Etcheverry case compared with the rest of the month?
It was the clearest and most serious incident of the period, because it combined confirmed encryption, a ransom demand, and the later release of about 300 GB of information. Coverage also cited data on at least 35 individuals and 149 companies. The technical and contextual detail is in Relevant incidents and Active threats.
Why does the report say the dominant threat was "Unclassified"?
Because 24 of the month’s 67 incidents could not be more precisely categorized with the material available. That does not mean there was no risk, only that the published evidence was not enough to assign a single category with rigor. The methodological nuance is in Period indicators and Material limitations.
How do the BCU’s new rules relate to the month’s fraud?
The reinforced authentication, complaints, and open finance rules are meant to reduce exactly the risks the month exposed: impersonation, misuse of data, and unauthorized activity. The link between regulation and threats appears in Regulation and compliance, along with the WhatsApp scam and the virtual assets agenda.
Were any critical vulnerabilities exploited in Uruguay during September?
No documented critical CVEs appeared in the material analyzed for this month. That does not mean there were no vulnerabilities regionally, only that none were recorded in the sample used for the report. The chart and its scope are in Critical vulnerabilities affecting Uruguay and Material limitations.
Material limitations
This report was built exclusively from the material provided for Uruguay in September 2026. Facts from the comparison block for prior months were used only for contrast, never as part of the month’s volume, and facts without a confirmed date were left out of the indicators, although they could be mentioned as context if they added qualitative value.
The critical CVE indicator is listed as zero because none appeared in the September material analyzed. That does not mean there were no critical vulnerabilities in the region, much less that there was no active exploitation outside this sample.
Aggregated telemetry such as incidents or blocks was also not included, because the material does not provide figures of that kind. Attempts, scans, or automated blocks, even if they existed in other sources, are not counted as incidents in this report.
Sources excluded by editorial rule or format were not used as evidence: consumer social networks, sponsored posts, commercial press releases, and material not included in the list of available sources. When a claim came from a news report on outside figures or from a source with uncertain attribution, it was kept with the appropriate level of caution.
Sources
- La paradoja de la ciberseguridad en UY (de la preocupación a la resiliencia)InfoNegocios
- Finanzas Abiertas: Urutec ante una nueva etapa del sistema financiero uruguayoEl País Uruguay
- En Uruguay ya se hacen 350 pagos electrónicos por habitante al año, más del doble que en 2019Ámbito Uruguay
- Estado de la ciberseguridad en Uruguay - V Simposio CIERComisión de Integración Energética Regional (CIER)
- Transferencias instantáneas ya superan el 70% de las operaciones entre institucionesMontevideo.com.uy
- El aumento de los pagos digitales y el custodio para la nueva etapa que propone el BCUEl Observador Uruguay
- Ley de competitividad: advierten riesgos en el manejo de los datos bajo el sistema de finanzas abiertasEl Observador Uruguay
- Organizaciones públicas y privadas fortalecen la cooperación para el intercambio de inteligencia de amenazasCentro Nacional de Respuesta a Incidentes de Seguridad Informática (CERTuy)
- Se multiplican en Uruguay denuncias por fraude y estafas digitalesPrensa Latina
- Mayor protección ante fraudes: la nueva propuesta del BCU para realizar compras y definir reclamosEl País (Uruguay)
- De 2.000 a 30.000 denuncias: el ciberdelito crece, se profesionaliza y desafía a la justiciala diaria
- Nueva estafa en la modalidad de suplantación de identidadMinisterio del Interior de Uruguay
- Alerta por nueva modalidad de estafa: se hacen pasar por funcionarios de UTE para acceder a WhatsApp y pedir dineroEl Observador
- Se hizo pasar por funcionario de UTE, obtuvo un código y tomó el control del WhatsApp de un hombre en RochaTelenoche
- AEBU expuso reparos a Ley de Competitividad y pidió reforzar la protección de datosCaras y Caretas
- BCU modifica el régimen de fiduciarios generales y financierosFERRERE
- Deudores irrecuperables: ¿qué pasa cuando la Categoría 5 te borra del mapa?Caras y Caretas
- Normativa – Departamento de Normas de Regulación Financiera, Superintendencia de Servicios FinancierosBanco Central del Uruguay
- Proyecto de competitividad: AEBU alertó por “ciertos riesgos” en el manejo de datos bajo el sistema de finanzas abiertasla diaria
- Deudores irrecuperables: ¿qué significa y cómo se sale de esa categoría?Caras y Caretas
- Senado tratará 'infraestructura crítica' en su sesión ordinariaÚltima Hora (Uruguay)
- Memoria de Sostenibilidad 2025Banque Heritage Uruguay
- Consulta pública "Norma de Gobierno de TI y Gestión de Servicios de TI"Asociación de Ingenieros del Uruguay / UNIT
- Activos Virtuales II: El Proyecto PSAV y la Circular del BCUAbogados.com.ar
- Durante la Semana del Aprendizaje Digital de la UNESCO los ministros de educación reclaman que la educación siga siendo un bien común en la era de la IAUNESCO
- Comenzó el V Simposio CIER de Redes y Ciudades InteligentesUTE
- Mensaje sobre recomendaciones de AGESIC para regular IA presentadas al ParlamentoSuNoticiasUY (X)
- Uruguay lanza su “think tank” de inteligencia artificial: la apuesta por encabezar el desarrollo tecnológico de la regiónÁmbito
- Hackean y filtran 300 GB de información de un estudio jurídico y contable uruguayoEl Observador
- BCU ordenó cesar una operativa de transferencias de fondos que funcionaba sin registroEl Observador (Uruguay)
- BCU ordenó cesar una operativa de transferencias de fondos que funcionaba sin el registroMSN
- Blanco & Etcheverry Data Breach in 2026BreachSense
- Así opera Gunra, un nuevo grupo cibercriminal que está bajo la mira del FBI y que ya atacó tres empresas uruguayasEl Observador
- Uruguay: Small Country, Big Fintech AmbitionsThe Fintech Times
- Gunra Ransomware Hits Three Uruguayan Firms in Three MonthsThe Rio Times
- Finanzas abiertas en Uruguay: abrir los datos no alcanzaEl País (Uruguay)
- Uruguay — ampliación de reglas de reporte de incidentes en organismos públicos (hilo sobre infraestructura crítica)X (Twitter)
- CTI ALERT 🇺🇾 | cutzinger CLAIMS EXPOSURE OF ...VECERTRadar
- Blanco & Etcheverry Listed by Gunra Ransomware GroupGalaxy Warden
- Comunicado SENACLAFT sobre procedimientos de DDCSecretaría Nacional para la Lucha contra el Lavado de Activos y el Financiamiento del Terrorismo (Uruguay)
- Comunicado SENACLAFT sobre procedimientos de DDC (comunicados)Secretaría Nacional para la Lucha contra el Lavado de Activos y el Financiamiento del Terrorismo (Uruguay)
- Blanco & Etcheverry Ransomware Claim (2026) — What’s Alleged & Am I Affected?Recent Breaches
- Victim: Blanco & EtcheverryRansomware.live
- Mónica Ferrero dijo que Gilberto Rodríguez, “en tres semanas, avanzó más que el anterior fiscal en los tres años que estuvo”la diaria
- Uruguay regula a las billeteras y criptomonedas en su territorio (versión AMP, con detalle de Título VII Ter y definición de PSAV)iProUP
- Uruguay regula a los proveedores de criptomonedas: ¿qué cambia para los usuarios?CriptoNoticias
- Uruguay regula a las billeteras y criptomonedas en su territorioiProUP
- Mutual recognition of digital signatures between the EU and Latin American countriesEstonian e-Governance Academy (eGA)
- Uruguay's push to de-dollarise boosted by new money market fundsBuenos Aires Times
- Luis Gama: "El juego online ya es una realidad y necesita un marco jurídico acorde con esa realidad"Yogonet Latinoamérica
- El Banco Central uruguayo cumple cinco años sin intervenir en el mercado cambiarioMercopress
- Uruguay's central bank marks five years without intervening in the currency marketMercopress
- Circular Nº 2509 del Banco Central del Uruguay introduce obligaciones de información a depositantes en moneda extranjeraGuyer & Regules
- Uruguay Casino Chamber Pushes for Online Gambling RegulationiGamingToday
- Cuoasec Impulsa Proyecto de Ley para Regular el Juego Online en Uruguay y Limitarlo a Operadores PresencialesSCCG Management
- Uruguay tendrá por primera vez un mapa completo de su industria fintechÁmbito
- Strengthening Cybersecurity in Uruguay - Project UR-L1152Banco Interamericano de Desarrollo (IDB)
- CYBERJUSTICE FORECAST 2026: menciones a URCDP y AGESICX (usuario individual)
- Gestión de ciberseguridadGobierno de Uruguay - CERTuy
- Cooperación Sur-Sur: Interior participa en intercambio de tecnología para enfrentar los desafíos del ciberdelitoMinisterio del Interior de Uruguay
- De INAU a los hijos de Orsi: los hackeos que dejaron datos de menores al alcance de ciberdelincuentesEl Observador
- Interior suma tecnología y una diplomatura para optimizar combate al ciberdelitoPresidencia de la República Oriental del Uruguay
- Interior combatirá el ciberdelito con tecnología argentina y una diplomatura pioneraLa Mañana
- Cómo Urudata se convirtió en la empresa más confiable en ciberseguridad, según FactumEl Observador
- Gunra ransomware group - Discover all the information about themBreach.house
- Gunra Strikes Blanco & EtcheverryDexpose.io
- Publicación en X sobre Blanco & Etcheverry como posible víctima de GunraVenariX en Español
- Espejo Chubut llegó a UruguayEl Diario Web (Chubut)
- Uruguay incorporó Espejo Chubut, el software forense desarrollado por el Ministerio Público FiscalMetadatanoticias
- Ministerio del Interior incorpora herramientas para fortalecer la investigación de delitos digitalesMinisterio del Interior de Uruguay
- How to Report Cybercrime and Online Fraud in Uruguay (2026)Ministry of Cyber Affairs
- Un hombre fue condenado por dos delitos de fraude informático tras una investigación de la Seccional 14.ªMinisterio del Interior de Uruguay
- Gunra Ransomware: Why Stopping Data Exfiltration ...BlackFog
- How to Track Ransomware Groups Before They Hit Your SectorScrutex.ai
- Financial services threat intelligence report — 29 August – 4 September 2026Cyber Defence
- Gunra Ransomware: Guessable Linux KeysAlpha Cyber
- Gunra Ransomware: What Defenders Should HuntAbout InfoSec
- The Signal, An Offensive Intelligence Digest (Volume 002)Evolve Security
- Ocho policías condenados por el caso Caranchos: penas de hasta dos años de prisión por filtrar datos de víctimas de siniestrosDebate.com.uy
- Global Ransomware Group Compromises Vigilia in UruguayDexpose
- Uruguay Ransomware & Cyber AttacksBreach House
- ¿Hackearon tu empresa? Qué hacer en UruguayInfoSecura
- Uruguay Security Brief — September 21, 2026Geobit
- Alertan por filtración de datos de UTEC a la dark web: qué dijo la universidadMontevideo.com.uy
- Uruguay prepara integración de inteligencia artificial en su ...Consultor Salud
- Uruguay analiza cómo integrar la inteligencia artificial en la salud públicaCiudadanía Noticias
- MSP creó comité operativo para coordinar la preparación de los sistemas de salud ante El NiñoTelenoche
- Criptomonedas: el BCU avanza con una nueva regulación en UruguayGrupo R Multimedio
- Tokenización de activos en Uruguay: Ley 20.345 y BCUUnknown Gravity
- Tokenización de activos en Uruguay: guía para emisoresHokenfi
- Law No. 20,345 Regulating Virtual Assets (2024) — UruguayCryptoSlate
- Escucha CFA Society Uruguay Podcast | Radios del UruguayRadios del Uruguay
