Logistics, Ports, Airports and Transport, Sep 2026
September recorded 56 verified events in the vertical, including 9 ransomware cases and 17 incidents, with a focus on transport
Key findings
- September closed with 56 verified events, fewer than the previous month, but with signals more concentrated in cases with real impact and less in aggregate noise.
- The main documented operational impact in the vertical was the Águia Branca incident, with potential exposure of 7,883 customers and impact limited to the web purchasing environment.
- The logistics case with encryption in Colombia and Peru showed that ransomware still halts billing and tracking for days, with a return to manual spreadsheets and phone calls.
- The material clearly separates three forms of ransomware pressure: confirmed encryption, exfiltration without encryption, and mere mention on a leak site, and several claims remained without final classification.
- The FamousSparrow and SparroWocky campaign reinforced advanced actors' interest in Latin America, with mention of a Panamanian entity linked to a port dispute.
- Brazil was the center of the technical and compliance response, with CTIR Gov alerts and a national exercise that included transport as strategic infrastructure.
- There were no critical CVEs in the analyzed material, but there were software and attack-surface alerts that affect logistics, ports, and transport across the board.
Monthly reference modules
These modules are automatically populated with verified dated facts from the period. Each one states its basis and counting criterion, so the figures reconcile across modules. This is the recurring month-by-month readout; the analysis that follows expands on the cases without repeating this summary.
Indicator window: 59 dated facts in September 2026 · 5 from previous months (comparative frame, not monthly volume) · 1 without confirmed date (excluded from indicators). Facts from previous months are used only as a comparative frame in the analysis, never as volume for this period.
Monthly executive summary
September 2026 sent mixed signals for logistics, ports, airports, and transportation in Latin America. The month closed with 56 verified incidents, 17 unclassified incidents, and 9 cases where ransomware or extortion was the primary driver. The material points to more containment, response, and monitoring activity than large-scale disruption, although operational impact, data exposure, and pressure on critical supply chains persist.
The most concrete ground-transport case was Viação Águia Branca, which reported an incident on its official ticket sales sites and told Brazil’s data protection authority that 7,883 customers may have been affected. The company limited the scope to the web purchasing environment, said its official app, Zap Passagens, already issued tickets, and travel data were not affected, and notified potentially affected users individually. That episode captures much of the month’s picture for passenger mobility: contained impact, early response, and immediate regulatory handling.
In heavy logistics and maritime transport, attention shifted to the investigation into alleged cyberattacks against two tankers bound for Texas and to follow-up on other incidents involving vessels linked to energy operations. Sources confirm evidence of malicious activity on board and work by the Coast Guard and the FBI, but no physical or environmental damage and no proven operational disruption. For Latin America, the ripple effect is indirect but relevant: maritime transport and the cross-border logistics chain emerge as a risk surface connecting ports, shipping lines, cargo, and IT and operational technology operators.
The month also recorded espionage and pressure campaigns against public-sector actors in the region, especially in Central and South America, with the campaign attributed to FamousSparrow and the SparroWocky backdoor. The main target was not transportation, but a Panamanian entity involved in a Canal port dispute was mentioned, along with telemetry showing that nearly 90% of the observed targets were in Latin America. That combination places port infrastructure and foreign-trade bodies within the interest perimeter of advanced actors.
At the same time, Brazil’s CTIR Gov issued technical alerts on vulnerabilities in products widely used across organizations with logistics, port, and transport operations, including Secure Email Gateway, Identity Services Engine, Chromium V8, and Magento. The material reviewed did not include specific critical CVEs for the vertical or sector-specific regulatory moves, but it did show a clear tightening of operations, national exercises, urgent patching campaigns, and recommendations to check exposed versions. The risk level for this vertical for the month is medium, with high-risk pockets in maritime transport and passenger transport because of the mix of incidents, extortion, and data exposure.
Regional snapshot for the month
September’s regional signal was medium risk, with pockets of high risk in maritime and passenger transport. The assessment is based on 56 verified incidents, 17 unclassified incidents, 9 ransomware or extortion cases as the main driver, and a predominance of events still unclassified in the month’s taxonomy. There was no uniform wave of paralysis, but there was a steady flow of isolated incidents, espionage campaigns, and pressure on access surfaces.
Latin America continued to appear on the radar of actors that are not necessarily looking for immediate impact, but for persistence, exfiltration, or groundwork. ESET’s investigation into FamousSparrow placed close to 90% of its targets in the region between mid-2025 and 2026, and the technical report described a modular implant with file theft, screenshot capture, session enumeration, and component loading capabilities. In a vertical such as transport and logistics, that kind of activity matters because booking, dispatch, manifest, billing, corporate email, and remote access environments are high-value targets for reconnaissance and pivoting campaigns.
At the same time, coverage of tanker ships and maritime security reinforced a broader trend: the line between IT and physical operations has become less distinct. The available sources point to evidence of malicious activity, inspection boardings, and no physical or environmental damage at the time of verification. That combination lowers the noise from speculation, but it does not eliminate risk. Operationally, what was exposed is the dependence of ports, shipping lines, and cargo operators on networks and credentials that can be harassed even when an incident does not turn into a visible disruption.
The Águia Branca case adds another layer. The incident remained confined to the web purchasing environment, but the company identified nearly 8,000 potentially affected customers and activated direct notification and reporting to ANPD. For the region, that confirms that the most sensitive fronts in passenger transport are still public interfaces, payment gateways, booking portals, and personal data management. Disruption does not always come through the most spectacular channel, and in September it became clear again that data exposure can matter as much as unavailability.
Period indicators
The table below reproduces exactly the indicators provided for September 2026, including their base, time window, and comparison with the prior month. This reading should be taken as a signal of the axis, not as aggregated telemetry or an investigation count.
| Indicator | September 2026 | Previous month | Change |
|---|---|---|---|
| Verified events for the period, basis for all indicators | 56 | 67 | -11 |
| Time window for the indicators | 59 events dated in September 2026, 5 from prior months, 1 without confirmed date | ||
| Unclassified incidents, breaches, or disruptions | 17 | 27 | -10 |
| Cases with ransomware or extortion as the primary focus | 9 | 15 | -6 |
| Ransomware breakdown, confirmed asset encryption | 1 | ||
| Ransomware breakdown, exfiltration without encryption, simple extortion | 1 | ||
| Ransomware breakdown, leak site mention only | 2 | ||
| Ransomware breakdown, impact type could not be determined from the material | 5 | ||
| Documented fraud or phishing cases | 2 | 1 | +1 |
| Documented regulatory moves | 0 | 10 | -10 |
| Critical CVEs mentioned | 0, none in the material analyzed, this does not imply absence in the region | no comparable data | |
| Sectors with at least one documented event | 5 | 7 | -2 |
| Predominant threat of the month | Unclassified, 20 of 56 events | Incidents, 27 of 67 events | change in predominance |
| Events with direct source confirmation | 71% | ||
| Aggregated telemetry figures excluded from the total | 3, aggregated attempts or blocks, not incidents with confirmed impact |
The base of 56 verified events matters because it keeps the monthly reading from being inflated by telemetry or unconfirmed mentions. It also explains why the ransomware block should not be read as a single homogeneous mass. Within the 9 cases, the material distinguishes one confirmed encryption event, one exfiltration without encryption, two leak site mentions, and five situations where the impact type could not be determined precisely. That spread points to persistent activity, but with little uniformity in outcome.
Relevant Incidents
September produced few cases with fully detailed impact, but several were enough to shape the agenda for this sector. In land transport, the clearest case was Viação Águia Branca. On the maritime side, the picture was dominated by security investigations aboard tankers and signs of espionage aimed at the region.
Viação Águia Branca and the ticket sales incident
Águia Branca reported a cybersecurity incident on its official ticket sales websites and said 7,883 customers may have had data compromised. The company notified ANPD, contacted potentially affected users individually, and set up a dedicated inquiry channel. It also said the scope was limited to the web purchasing environment.
The key issue is not only the potential number of affected users, but the exposure boundary. The company said the official app, the Zap Passagens channel, tickets already issued, and travel data were not impacted. That reduces direct operational risk, but it leaves open what specific fields may have been exposed and how the incident began.
Secondary coverage, attributed to Mejor e-Tech, added that the problem would have been contained and resolved on the same day it was detected, although without specifying the origin of the attack or the affected fields. That matters because it places the case closer to a commercial front-end access incident than to a broad intrusion into core systems. For the industry, the lesson is clear, the booking and payment perimeter remains a critical front.
Transportes Montejo and the leak site claim
The Transportes Montejo S.A.S. case appears in the month as a claim posted by a ransomware group, not as a fully confirmed intrusion. Ransomware.mx reported that Krybit posted the mention on its leak site, Ransomware.live attributed it to NightSpire, and another source said zero users were compromised and no data was available. There is no independent confirmation of an intrusion or a specific leak in the material.
That kind of event falls into the single leak site mention category, which is useful for monitoring but not enough to conclude technical or legal harm. Even so, the episode matters because it shows how heavy logistics and specialized transport continue to appear in extortion narratives, even when public evidence is weak. For a security team, the priority is to distinguish reputation from a proven incident.
The ambiguity between Krybit and NightSpire also illustrates a classic threat intelligence problem, attribution is fragmented across repositories, scrapers, and monitoring sites. Without company confirmation, vector details, or evidence of exfiltration, the case's main value is tactical. It helps reinforce leak site monitoring, but not infer a successful campaign against the company.
Tankers bound for Texas and the investigation into malicious activity onboard
The maritime front was the most visible area of operational risk during the month. The Coast Guard and the FBI boarded two oil tankers bound for Texas and found evidence of malicious activity, although the cited sources do not publicly attribute the case to a specific actor. Coverage agrees that there were no physical damages, environmental impacts, or crew injuries.
The key element in this episode is the convergence of forensic investigation and maritime security. Dragos framed the case under MTSA cybersecurity requirements and said that, based on the confirmed information available, there was no physical damage or environmental impact. Safety4Sea and SecurityWeek added that the vessels were under investigation for several days. The signal is not one of disaster, but of persistent exposure in a sector where operational continuity depends on IT and OT.
For Latin America, the implication is systemic rather than geographic. Ports, terminals, shipping lines, and cargo operators in the region rely on similar flows of documentation, communications, access control, and navigation. What happened in the Gulf of Mexico shows the cost of investigating in time, but also the potential impact of an intrusion on a mobile asset that connects routes, terminals, and insurance.
FamousSparrow, SparroWocky, and pressure on the region
The campaign attributed to FamousSparrow occupied a large share of the technical conversation during the month. ESET described SparroWocky as a modular C++ backdoor with file theft, screenshot capture, session enumeration, persistence, and the ability to launch new instances. The same research said that about 90% of the actor's observed targets between mid-2025 and 2026 were in Latin America.
The most sensitive regional point was the mention of a Panamanian entity involved in a Canal port dispute. While the material does not specify the target's full nature, it does link it to a conflict of logistical and geopolitical relevance. That is enough to place ports and organizations tied to concessions, administration, and foreign trade on the actor's map of interest.
The risk here is persistence rather than loud impact. The campaign appears designed to watch, anticipate responses, and maintain access. In a sector where email, supplier portals, dispatch systems, and cargo documentation are common entry points, a modular backdoor of this type can serve as a precursor to internal phishing, credential theft, or lateral movement into more sensitive systems.
Active threats and campaigns
The month’s active threat picture clearly split between ransomware and extortion, fraud or phishing, and advanced espionage campaigns. The material does not point to a single dominant wave, but to several fronts affecting logistics, ports, and transportation in different ways.
Ransomware and extortion
Of the 9 cases where ransomware or extortion was the primary focus, only one had confirmed asset encryption, one involved exfiltration without encryption, two were mentioned only on leak sites, and five could not be conclusively classified from the available material. That breakdown matters because it separates operational damage from reputational pressure or negotiation. Not everything that appears on a leak site amounts to a verified, high-impact intrusion.
The case of the logistics company with operations in Colombia and Peru, reported by SIMCOD, is the clearest example of confirmed encryption with operational impact. The material says its billing and shipment tracking systems were encrypted for nearly four days, and that the company had to operate with spreadsheets and phone calls. A source described as uncertain also said initial access may have come through a phishing email sent to an administrative employee, and that there was no MFA or segmentation between operational and billing systems.
That episode is especially sensitive for the sector because it combines three common weaknesses, email access, poor segmentation, and disruption of critical back-office processes. A major multinational is not required for the damage to be significant. In mid-sized logistics firms, four days without billing and tracking can affect service, cash flow, customer support, and partner trust.
There were also references to public-sector entities and companies with a presence in Brazil, including mentions of the Caxias government and Receita Federal on leak sites or in claims by groups such as Emperador. In both cases, the material does not allow the intrusion or exfiltration to be fully confirmed, so they should be read as extortion pressure in an incomplete verification stage. The correct taxonomy here is explicit, mention or claim, not a closed fact.
Fraud and phishing
The month recorded 2 documented fraud or phishing cases, up from 1 in the previous month. The figure is not large, but it matches how incidents usually begin in transportation and logistics, initial access through email, portal impersonation, or credential capture. The SIMCOD case is again the most illustrative, because the source attributed the initial access to a phishing email sent to an administrative employee.
That pattern has direct operational consequences. In transportation and logistics companies, administrative users often have access to billing, suppliers, service orders, and operational support. If phishing reaches an account with broad permissions and there is no MFA or segmentation, the attacker does not need a sophisticated exploit to stop processes.
The practical reading is that fraud and phishing remain the most plausible entry point for incidents that later present as ransomware or disruption. September’s data does not suggest a sharp increase, but it does confirm that the human vector remains the cheapest path to high-value assets in the sector.
APT and hacktivism
The FamousSparrow campaign, and the discussion around Salt Typhoon, were the month’s main advanced-activity signal. In this case, the issue was not disruption but espionage. ESET, The Register, The Hacker News, and other coverage described a modular backdoor with persistence, exfiltration, and evasion capabilities. The Record said, as an assessment attributed to ESET, that the campaign was likely intended to help China monitor the reactions of Latin American governments.
The mention of a Panamanian entity tied to a port dispute again links this activity to the transportation and ports sector. The material does not show operational impact on terminals, airports, or logistics operators, but it does show interest in the institutional infrastructure surrounding foreign trade. That requires separating the actor’s apparent objective from the observable damage, which do not always match.
In priority terms, this category should not be confused with ransomware. Its main risk is sustained exposure, information gathering, and preparation for future operations. For security teams at ports, airports, and logistics companies, that means monitoring endpoints, email, and lateral movement, not just perimeter defenses.
Critical vulnerabilities
No critical CVEs were recorded in the material analyzed for September 2026. That does not mean critical vulnerabilities were absent from the region, only that this sample did not identify any as such. The month focused on product alerts and update recommendations rather than a closed list of CVEs explicitly tied to the sector.
The table below summarizes the technical advisories that did appear in official sources and may have cross-sector impact on logistics organizations, ports, airports, and transportation.
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| No critical CVEs were recorded in the material analyzed | Secure Email Gateway | Vulnerability alert with potential impact on confidentiality, integrity, or availability | CTIR Gov, Alert 88/2026 |
| No critical CVEs were recorded in the material analyzed | Magento Open Source, branches 2.4.6, 2.4.7, 2.4.8 and 2.4.9 | Vulnerability notice affecting e-commerce and Magento, with potential impact on confidentiality, integrity, or availability | CTIR Gov, Alert 90/2026 |
| No critical CVEs were recorded in the material analyzed | Chromium V8 | Vulnerability with potential for arbitrary code execution by a remote attacker, included in CISA KEV | CTIR Gov, Alert 83/2026 |
| No critical CVEs were recorded in the material analyzed | Cisco Identity Services Engine | Recommendation to verify versions and apply vendor patches | CTIR Gov, Alert 87/2026 |
| No critical CVEs were recorded in the material analyzed | Brazilian government institution web servers | Active campaign exploiting vulnerabilities through dynamic path injection and malicious modules, cloaking technique | CTIR Gov, Recommendation 17/2026 |
The value of these notices for the sector is indirect but real. A booking portal, a secure mail system, an authentication environment, or an e-commerce front end can become the first step in an access chain. Although the material does not link each alert to a transportation or logistics incident, it does point to the kind of attack surface threat actors can exploit.
Regulation and compliance
There were no documented regulatory moves for the vertical in September 2026, compared with 10 the previous month. The drop does not mean a softer regulatory environment, but rather a lack of such developments in the material analyzed. What did appear was a more operational compliance and governance response, especially in Brazil and in the Águia Branca case.
Brazil again served as a regional gauge of regulatory maturity and technical response. CTIR Gov issued alerts and recommendations on Secure Email Gateway, Magento, Chromium V8, Cisco ISE and active campaigns against government web servers. Brazil's Ministry of Defense also promoted the Guardião Cibernético 8.0 exercise with around 1,300 participants and 300 organizations, including the transport sector among the strategic infrastructures simulated.
That exercise matters because it shifts the compliance discussion from rules to drills. The transport industry not only has to respond to incidents, it also has to practice continuity, communications and coordination with authorities. In practice, that applies just as much to passenger companies as it does to port operators, terminals and cargo logistics providers.
The Águia Branca case also touched the regulatory side in a concrete way. The company reported the incident to the ANPD and notified potentially affected users individually. That does not solve the problem, but it does show a course of action that other transport firms should treat as standard when exposure affects passengers' or customers' personal data.
Countries and most affected subsegments
The geographic spread in September was uneven. Brazil accounted for much of the compliance activity, technical alerts and some extortion incidents, while Mexico, Panama, Colombia and Peru appeared across different risk and exposure fronts. The readout needs to be done by country where the facts are documented and by subsegment when the material allows it.
Brazil
Brazil was the country with the highest density of signals in September, though not necessarily because of the operational impact volume in the vertical. The Águia Branca case set a clear reference point for passenger transport. It was joined by CTIR Gov alerts on vulnerabilities and active campaigns, plus the events tied to Emperador and the government of Caxias in Minas Gerais, although the latter were not conclusively confirmed in the material.
The relevance for logistics, ports and transport lies in the combination of public exposure and response maturity. Brazil is not only dealing with incidents, it is also institutionalizing exercises and advisories. For companies with local or regional operations, that means notification thresholds and response expectations are becoming more demanding.
Mexico
Mexico appeared as a reference on two different levels. On one side, the SCILabs report cited by La Jornada and El Economista said around 52 Mexican companies and entities were hit by ransomware in the first half of 2026, with a significant regional concentration. On the other, the country continued to appear in the broader map of information kidnapping activity in Latin America.
Although those figures do not reflect September volume in this vertical, they do help frame the ransomware pressure on companies with cross-border supply chains, transport operators and support services. The most sensitive subsegment remains corporate, not only because of size but because of exposure to billing, support and document logistics.
Panama
Panama drew attention because of a mention of an entity involved in a Canal port dispute within the campaign attributed to FamousSparrow. The material does not show evidence of an operational incident at a Panamanian port, but it does show strategic interest in a highly sensitive logistical space with geopolitical weight.
For the vertical, Panama matters as a transit hub and as an environment where authorities, concessionaires, shipping lines and service operators converge. That raises the value of intelligence, corporate email and digital identity. An advanced actor does not need to disrupt a port to gain leverage if it can map its ecosystem.
Colombia and Peru
Colombia and Peru appear together because of the medium-sized logistics company that suffered ransomware and was left without billing and tracking systems for four days. It is the clearest example of operational damage in the sample. The disruption was not abstract: the company fell back on spreadsheets and phone calls to keep operations running.
That kind of interruption has direct consequences for SLAs, deliveries, collections and customer reputation. It also forces companies to think about internal segmentation, business continuity and offline capabilities. For transport and logistics operators in both countries, the lesson is that resilience is not tested when everything works, but when the main system goes down.
Passenger transport, heavy logistics and maritime
Within the vertical, passenger transport was hit by the Águia Branca case, with a focus on reservations and customer data. Heavy logistics was represented by Transportes Montejo and by the logistics company in Colombia and Peru that suffered encryption. Maritime was the subsegment with the greatest strategic weight, driven by the tankers under investigation and the attention given to port security.
That distribution shows a fragmented vertical. There is no single pattern. There are passenger operators vulnerable in their front ends, logistics companies exposed to ransomware because of weak segmentation, and maritime environments where IT and OT mix, so an intrusion can have broader effects. The sector reading, therefore, has to be specific, not generic.
Trends and signals to watch
Compared with the previous month, verified incidents, unclassified cases, and ransomware or extortion incidents all declined, while fraud and phishing edged up slightly. Regulatory activity that appeared in the prior sample also disappeared this month. The underlying trend is not easing, but a reshuffling, less aggregate noise and a tighter focus on specific cases with operational impact or advanced monitoring.
In the previous month, incidents had been the dominant threat category. In September, unclassified cases took that place, pointing to a more dispersed and less uniform mix. That matters because it suggests public coverage is not capturing a single wave, but multiple episodes at different stages of intelligence maturity. For a CISO, that complicates prioritization and forces attention to impact type, not raw volume.
The first signal to watch is the persistence of ransomware with real impact on midsize logistics operations. The case in Colombia and Peru showed that encrypting billing and tracking systems is still enough to halt processes for days. The second is the continued appearance of mentions on leak sites without strong confirmation, which may conceal extortion in preparation or attempts at reputational pressure. The third is the advance of espionage campaigns aimed at Latin America, especially when they affect ports or entities linked to foreign trade.
The most useful comparison point is the maritime sector. The August and September events, although they do not make up the volume from the previous month in this report, show a sequence of investigation, boarding, and technical analysis on tanker ships. That should not be read as a confirmed campaign against the region, but it does signal sustained attention on the maritime surface from both threat actors and authorities.
Security team recommendations
This month’s priorities are more operational than theoretical. The first recommendation for transportation and logistics teams is to harden the perimeter around bookings, quoting, billing, and tracking. The Águia Branca case shows that an incident in the commercial front end is enough to compromise customer data and force individual notifications. Those environments should have MFA, anomaly monitoring, and reviews of third-party integrations.
The second is to review segmentation and recovery at mid-sized companies. The case of the logistics company with operations in Colombia and Peru showed that when billing and tracking are encrypted, the organization falls back to manual operations. That is not a minor detail. Administrative and operational domains need to be separated, restoration should be tested, and offline procedures should be defined that do not depend on the availability of email or the main ERP system.
The third priority is to reduce the phishing attack surface. This month’s material again points to an initial email aimed at administrative staff. In logistics and transportation companies, that group often holds permissions useful to attackers. Awareness programs should focus on accounts with access to shipping documents, collections, payroll, reservations, and vendors, not on generic campaigns for the entire workforce.
The fourth is to strengthen monitoring of leak sites and early mentions, but without confusing them with confirmed intrusions. Transportes Montejo is a useful example of how to separate reputation from incident. A mature team must know how to distinguish a claim from a technical fact and respond differently to each one. The first requires intelligence and verification, the second containment and forensic analysis.
The fifth is to view the maritime and port front as an extension of the corporate network. Reports on tankers under investigation for malicious activity, along with the alert on port security in the Bahamas, are a reminder that logistics continuity depends on communications systems, access, and coordination among multiple actors. Teams operating ports, terminals, or fleets should review credentials, segmentation between IT and OT, emergency procedures, and coordination with local authorities.
The sixth recommendation is to align compliance, response, and drills. Brazil issued technical advisories, operational recommendations, and a national exercise this month that included transportation among strategic infrastructures. The lesson applies across the region: policies are not enough. Teams need to rehearse service shutdowns, external communications, regulator notifications, and a controlled return to operations.
Frequently Asked Questions
What did this month combine between real incidents and espionage campaigns?
September combined a passenger transportation data incident, ransomware that encrypted a logistics company, and espionage campaigns linked to Latin America and port-related interest. The common thread was not volume, but the range of impacts. To understand them better, it is worth reading the Relevant incidents and Active threats and campaigns sections together.
Which cases had proven operational impact, and which remained only pressure or mentions?
Proven operational impact appeared in the encryption of billing and tracking systems at a logistics company with operations in Colombia and Peru, and in the exposure of Águia Branca customers. By contrast, Transportes Montejo appeared only as a mention on a leak site, and several claims about Brazil went no further than unconfirmed attribution. The distinction is developed in Relevant incidents and Active threats and campaigns.
Which countries received the most attention in the material, and why?
Brazil stands out for technical advisories, institutional response, and a passenger transportation case. Mexico appears because of regional ransomware pressure. Panama comes up because of the mention of an entity involved in a port dispute, and Colombia and Peru because of the logistics case involving encryption. The country-by-country reading is developed in Countries and subsegments most affected and in Regulation and compliance.
What should a transportation or logistics operator review first?
First, access to the front end for reservations, sales, billing, and tracking. Next, segmentation between administrative and operational systems, and offline recovery plans. This month showed that a phishing email can open the door and that encrypting a billing environment is enough to stop operations for several days. The specific recommendations are in Recommendations for security teams.
Were there any critical CVEs directly tied to this vertical?
No critical CVEs appeared in the material analyzed for September 2026. There were alerts about Secure Email Gateway, Magento, Chromium V8, Cisco ISE, and a campaign against government web servers in Brazil. That does not mean critical vulnerabilities were absent from the region, only that none were recorded as such in this sample. The table is in Critical vulnerabilities.
Material limitations
This report was built exclusively from the material provided for September 2026 and from facts from earlier months used only as a comparative frame when the text allowed it. The indicator base is the one stated in the material itself, with 56 verified facts from the period and 59 facts dated September 2026 within the time window used for the indicators. Facts without a confirmed date were left out of the count.
A zero indicator, especially for critical CVEs, means none were recorded in the material analyzed for this month, not that no critical vulnerabilities were exploited in the region. The same applies to regulatory moves. Their absence in the table reflects a lack of documented facts in this sample, not the absence of regulatory activity in Latin America.
Telemetry also has to be separated from incidents. Figures for attempts or blocks, such as those for the Port of Los Angeles, are automated volumes of malicious activity filtered by defense systems, not confirmed intrusions. For that reason, they are not added to the monthly total and are not used as evidence of regional impact.
Finally, sources whose content did not allow the date to be confirmed were left out of the indicators, as were materials that offered only unverified claims, promotional content, or coverage without enough technical confirmation to close an incident. That cut reduces noise, but it can also leave out early signals that still do not meet the verification threshold required for this report.
Sources
- Cibersegurança entra na agenda estratégica do transporteValor Econômico
- Exercício Guardião Cibernético 8.0 reúne cerca de 1.300 participantes em BrasíliaMinistério da Defesa do Brasil
- Águia Branca confirma ataque hacker: dados de 7.883 clientes podem ter sido comprometidosMelhor e-Tech
- Viação Águia Branca sofre ataque cibernético que afetou quase 8 mil clientesTecMundo / Estadão
- Viação Águia Branca sofre ataque cibernéticoA Gazeta
- Águia Branca registra incidente de cibersegurança que pode ter afetado 7.883 clientesÔnibus & Transporte
- Transportes Montejo Data Breach in 2026BreachSense
- [Intel MX] 2026-09-01 México sin víctimas, pero el vecindario ...Ransomware.mx
- Victim: Transportes Montejo S.A.S.Ransomware.live
- transportesmontejo.com Listed by Krybit Ransomware GroupGalaxyWarden
- Un ciberataque podría exponer información militar y de seguridad nacional: ¿qué tan vulnerable está Perú?Infobae
- Investigative cyber threat research report: cyberattacks on U.S.-bound energy tankersShieldworkz
- ALERTA 88/2026Gabinete de Segurança Institucional de Brasil — CTIR Gov
- ALERTA 90/2026Gabinete de Segurança Institucional de Brasil — CTIR Gov
- Perú en la mira del ciberespionaje chino: grupo de hackers concentró el 90% de sus objetivos en América LatinaInfobae
- ALERTA 90/2026Gabinete de Segurança Institucional de Brasil — CTIR Gov
- ALERTA 83/2026Gabinete de Segurança Institucional de Brasil — CTIR Gov
- ALERTA 87/2026Gabinete de Segurança Institucional de Brasil — CTIR Gov
- VL Prosperity: What MTSA Cybersecurity Already RequiresDragos
- Maritime Cyber Incidents Test Coast Guard Cyber PreparednessFoundation for Defense of Democracies
- Brazil's tax agency appears on a young crew's leak siteIntelFusions
- Bahamas moves over cyber threats to portsThe Tribune 242
- Documentan 52 ataques a los sistemas de empresas y entidadesLa Jornada
- FBI, Coast Guard probe suspected cyberattacks on ships entering US watersSupply Chain Dive
- Ransomware Attack Targets Cassias MG Government and InterThreatCluster
- Daily OT Security News: September 19, 2026Security Boulevard
- Cyware Weekly Threat Intelligence — September 12Cyware
- FBI, Coast Guard boarded hacked oil tankers heading toward US coastTechCrunch
- China-Aligned FamousSparrow Deploys SparroWocky Backdoor in Latin American Government AttacksThe Hacker News
- Chinese hackers use SparroWocky malware in government espionage attacksBleepingComputer
- China's FamousSparrow hackers target Latin America with new backdoorThe Record
- FamousSparrow Swaps SparrowDoor For New Backdoor in Latin America CampaignInfosecurity Magazine
- Port of LA Foiled Around 120 Million Cyberattacks Last MonthBloomberg
- Hackers vinculados a China atacan entidad en disputa portuaria del Canal de Panamá, dice ESETThe Epoch Times
- Cyberattacks on two US-bound tankers put cyber risk back in the spotlightSafety4Sea
- Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board VesselsSecurityWeek
- ESET Research: FamousSparrow targets Latin American governments with new SparroWocky backdoorESET Research
- China's Salt Typhoon backdoors Latin American orgs with new snooping malwareThe Register
- US Tracking Cyber Threats Against Nearly 20 Ships WorldwideInsurance Journal
- Coast Guard, FBI investigating after 2 oil tankers bound for U.S. were hit with suspected cyberattacksABC News
- ALERTA 81/2026 — Portal Gov.brGabinete de Segurança Institucional de Brasil — CTIR Gov
- Ransomware in Latin America: The Attack That Set Off…SIMCOD
- RECOMENDAÇÃO 17/2026 — Campanha ativa contra servidores web de instituições governamentais brasileirasGabinete de Segurança Institucional de Brasil — CTIR Gov
- Alerta por ciberseguridad: crecen 25% los ataques con secuestro de informaciónEl Destape
- El ransomware crece 25.5% en América Latina y México concentra 17.93% de los ataquesEl Economista
- US Coast Guard and FBI board oil tanker to investigate cyber attackBitdefender
- Coast Guard and FBI boarded 2 energy tankers due to cyberattacks. How big is the risk?CBS News
- US Coast Guard boarded a Texas-bound oil tanker to investigate a cyberattack, Bloomberg News reportsReuters
- Coast Guard, FBI boarded Texas-bound oil tanker after cyberattack concernsCBS News
- Cyberattacks on Oil Tankers Put Maritime Critical Infrastructure at RiskSecurity Affairs
