CiberLATAMbywhalemate
Intelligence report

Mining, Metals, and Natural Resources, September 2026

Puebla, APT campaigns, and 11 CVEs shaped September for LATAM mining and natural resources, with medium regional risk.

Oct 1, 202631 min read
Mining, Metals, and Natural Resources, September 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are populated automatically with verified facts dated within the period. Each one states its basis and counting criterion so the figures reconcile across modules. They are the recurring month-by-month reading, and the analysis that follows expands on the cases without repeating this summary.

Indicator window: 49 dated facts in September 2026. Facts from prior months are used only as comparative context in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Monthly verified signal dashboard September 2026 · Latin America Top threat: Unclassified (22 of 49 events). Coverage: 49 dated events in September 2026 VERIFIED EVENTS 49 period baseline: total count measured from below on this total RANSOMWARE / EXTORTION 8 8 unclassified with the material UNCLASSIFIED INCIDENTS 4 breaches or outages with no threat type stated FRAUD / PHISHING 3 documented fraud campaigns documented REGULATION 1 standards, resolutions or penalties UNIQUE CVEs 11 CVE-2025-39682 / CVE-2025-39964
Monthly verified signal dashboard — Base: 49 verified dated events for Latin America.
MONTHLY FIXED MODULE Threat Axis Distribution September 2026 · Latin America Each event is counted in only one axis, so the total is exactly 49. "Unclassified incidents" is the remainder. Unclassified 22 Vulnerabilities 11 Ransomware 8 Incidents 4 Fraud 3 Regulation 1
Threat Axis Distribution — Each event is assigned to a single axis based on its classification; the total reconciles to the 49 events in the period.
MONTHLY FIXED MODULE Sectoral Distribution of Signal September 2026 · Latin America Base: 49 incidents in the period · sum 77 because 20 incidents are classified in more than one sector. Public sector / OIV 19 Technology 15 Energy 14 Telecom 12 Other / no sector ident… 12 Finance 4 Retail / consumer 1
Sectoral Distribution of Signal — Heuristic classification by victim sector. One incident may affect more than one sector, so totals can exceed the base.
MONTHLY FIXED MODULE Geographic Signal Distribution September 2026 · Latin America Each incident is assigned to a single country or to regional coverage, so the total is exactly 49 of 49 incidents of… Regional 38 Mexico 10 Argentina 1
Geographic Signal Distribution — Verified incidents from the period grouped by country or regional coverage; each incident is counted only once.

Executive summary

September 2026 left a mixed picture for mining, metallurgy, and natural resources in Latin America. On one side, the month brought isolated but strategically significant incidents, with particular focus on energy infrastructure, clandestine crypto mining, and espionage campaigns against governments and sectors tied to energy, mining, and telecommunications. On the other, the evidence from the month does not point to a wave of mass intrusions against physical mining operations, but rather to a convergence of digital risks affecting the sector’s value chain, electricity, connectivity, remote control, corporate governance, and operational continuity.

The most visible event of the period was the dismantling in Puebla of a clandestine cryptocurrency mining installation illegally connected to a hydroelectric dam. The investigation, still ongoing, pointed to alleged power theft and had not identified any responsible parties. As the case developed during the month, the initial technical inventory diverged, from about 300 specialized computing units to later descriptions of more than 1,000 devices, along with network and power components. That gap matters less as a count dispute than as an operational signal. The installation did not look like an improvised setup, but like an operation with meaningful power, electrical distribution, and satellite connectivity requirements. For an industrial sector CISO, the case reinforces a familiar lesson, where there is abundant power, weak control, and remote resources, there is also room for infrastructure abuse.

On the digital extortion front, the month’s material included ransomware claims or publication threats against organizations tied to industry, metallurgy, and construction materials in Argentina, Panama, and Peru. In every case, available sources did not independently confirm the incident or allow a reliable classification of whether there was asset encryption, exfiltration, or only a mention on a leak site. For analytical integrity, that means treating them as reputational and extortion signals, not as verified compromises with proven operational impact. Even so, their geographic and sector spread suggests attackers still see value in material-heavy companies, especially where financial, logistics, or supply chain information can be monetized through public pressure.

The other major thread this month was advanced intrusion and espionage. ESET, Check Point Research, and other coverage linked FamousSparrow/SparroWocky and Salt Typhoon to campaigns against government entities in Latin America, including Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. Although no concrete incidents against mining companies were reported in September, the relevance to the sector is clear. The same countries and strategic interests named by researchers include energy, mining, and telecommunications. Operationally, that means the exposure surfaces of ministries, critical service operators, and sector contractors may be under persistent exploration, with possible later access to high-value environments.

The report also shows sustained pressure on the region at the tactical level. Intrusion clusters were reported using tools backed by language models, along with job-themed phishing, custom payloads, iterative batch scripts, and living-off-the-land techniques. While these findings do not belong exclusively to mining or natural resources, they do affect companies that rely on regional vendors, OT integrators, electrical contractors, and corporate teams exposed to email and self-service portals. The practical readout is that the sector’s digital perimeter no longer ends at the plant. It includes suppliers, remote support environments, identity portals, collaboration tools, and cloud asset management.

For CISOs and security leaders in the sector, the priority should not be only ransomware prevention, but reducing dependence on high-value access paths, exposed remote access, weak authentication, insufficient segmentation between IT and OT, poor monitoring of power consumption and anomalies, and a lack of clear inventories of connected systems. September’s events show the threat can come from classic criminal networks, state-aligned actors, or opportunistic groups that exploit public vulnerabilities. The common pattern is the abuse of a dispersed and heterogeneous attack surface.

Overview

The month was marked by a mix of low-profile incidents and high structural significance. In the material reviewed, there was no confirmed major attack that halted a major mining operation or a large-scale smelter. That absence of headline-grabbing news should not be mistaken for lower risk. The region continued to show sustained ransomware activity, espionage, and vulnerability exploitation, with the mining and natural resources sector exposed through its ties to energy, logistics, industrial automation, and cross-border contracting.

A significant part of September’s picture was tied to infrastructure. The clandestine facility in Puebla is a reminder that illegal digital mining is not just a policing issue, but one involving heavy energy consumption, specialized equipment, cooling, communications, and manipulation of critical facilities. The relevance for the natural resources sector is direct. Where there are dams, medium-voltage lines, substations, isolated environments, and contracts with industrial operators, there are also opportunities for physical or cyber intrusion for profit. The Mexican investigation also left open the possibility that the stolen electricity came from a nearby hydroelectric dam, pushing the case from energy fraud into a possible intrusion against essential infrastructure.

At the same time, the espionage campaign attributed to FamousSparrow and activity observed by ESET and Check Point reinforce a pattern that has been building. Regional governments, along with companies tied to energy and mining, are targets because of their strategic value and the information they hold on projects, tenders, diplomatic ties, regulation, and infrastructure plans. For mining or metals companies, that does not mean they are the only target. It means they operate in an ecosystem where an intrusion into a ministry, a telecom operator, or a technology vendor can become a stepping stone toward industrial assets.

The other layer of the picture was opportunistic crime. Ransomware claims against firms in Argentina, Peru, and Panama were not independently verified in the available material, but they fit a broader regional trend. Extortion groups seek victims with high operational pressure, sensitive information, and the ability to pay. In extractive and metals sectors, that usually means payroll data, contracts, logistics, geological analyses, environmental licenses, financial statements, blueprints, supply agreements, and internal communications. Even if the source does not specify whether there was encryption or only exfiltration, the operational risk is real. A leak can trigger regulatory delays, litigation, loss of trust, and friction with industrial or financial partners.

From a risk management perspective, September confirmed that the line between cybersecurity and industrial security is increasingly blurred. Connected plants and mines depend on identity systems, sensors, satellite links, remote administration, radio links, and corporate support tools. Attackers no longer need to target the shovel, furnace, or conveyor belt directly. Controlling access, degrading trust, disrupting continuity, or monetizing sensitive information is enough. That is why sector defense requires a simultaneous view of IT, OT, energy, and business continuity.

Indicators

The period’s indicators confirm that the month was not exceptional in terms of destruction volume, but it was notable for strategic density. In clandestine crypto mining, the Puebla case remained the clearest and best documented fact: an installation with approximately 300 GPU, a transformer, medium-voltage terminals, and satellite antennas, later described by other sources with broader inventories of equipment and electrical components. In ransomware and extortion, the mentions affected an Argentine industrial company, a Peruvian company linked to mining, and a Panamanian metallurgical firm, but none of those claims was corroborated by an official notice or by an independent technical source in the material analyzed.

In advanced persistent threats, the signals were stronger. ESET and associated media observed FamousSparrow activity using the new SparroWocky backdoor against governments in several Latin American countries. Check Point Research, meanwhile, attributed to Salt Typhoon a China-aligned espionage campaign against government entities in the region and a telecommunications organization in Puerto Rico. Although these episodes do not automatically translate into intrusions against mining companies, they do show an environment of active reconnaissance across countries whose infrastructure and regulated sectors matter to extractive operations.

In regional ransomware, September’s material confirmed persistent pressure. SCILabs, cited by several outlets, placed Mexico at 52 companies and entities attacked during the first half of 2026, and in a regional note said Latin America recorded at least 290 incidents in that same period, up 25.54% from the previous half-year. The figure is useful as context, but it should not be mixed with the specific incidents in this report or read as a September tally. Its value is in showing that the risk baseline remains high, especially for organizations with broad and heterogeneous attack surfaces.

The vulnerability and exploitation picture is also relevant. Several September alerts and advisories pointed to critical or exploited flaws in widely deployed products, from Citrix NetScaler and Cisco Secure FMC/SCC to SMA1000 Appliances, Orkes Conductor, Atlassian, and others, which can affect regional providers and operators. However, in this report those data should be read as exposure context, not as incidents specific to the mining or natural resources sector in September. The practical point is that exposure to remote access, administration, and orchestration vulnerabilities remains a risk multiplier for extractive and metallurgical companies.

Incidents

Puebla: dismantling of an illegal cryptocurrency farm tied to hydroelectric infrastructure

The clearest case this month was the dismantling in Tlaola, Puebla, of an illegal facility dedicated to digital asset mining and illegally connected to a dam belonging to a federal hydroelectric complex. Puebla’s Public Security Ministry initially reported finding about 300 specialized computers, and Reuters said the investigation focused on a possible theft of electricity. At that point, authorities had not determined who was responsible, and the Federal Attorney General’s Office had not announced any specific charges. That matters because it keeps the case in the category of an ongoing investigation, without assigning authorship or final motive beyond the alleged energy theft.

As the month went on, more detailed technical descriptions emerged. Reuters kept its focus on the illegal connection to hydroelectric infrastructure and the possible use of stolen electricity to run mining equipment. Later, Aristegui Noticias and Diario Cambio reported, citing police or naval sources, a larger inventory: 1,032 devices, 95 switches, three satellite antennas, a microwave antenna, five transformers, an air compressor, power conductor cable, and fragments of flexible tubing. Those figures do not replace the initial official confirmation, but they do give a sense of the size of the installation and the level of electrical and communications support required. The gap between about 300 units and more than 1,000 devices suggests different phases of inspection or counting, not necessarily conflicting accounts.

Operationally, the case is highly instructive. A Bitcoin farm of meaningful scale does not run on computers alone. It needs stable power, distribution capacity, thermal management, robust internet links, and, in clandestine settings, mechanisms to avoid disruption or tracking. The presence of satellite antennas and microwave links suggests independent connectivity was also part of the design. For the mining and metals sector, that has two readings. First, an installation with those resources can operate in remote or semi-rural areas where oversight is limited. Second, where sensitive power infrastructure exists, a third party can try to extract value without compromising corporate systems, simply by diverting energy and hiding the operation.

The investigation also showed authorities were examining whether the cryptocurrencies obtained could be used to conceal profits from illicit activity. That hypothesis, reported by Reuters, remains unconfirmed in court and should not be overread. Even so, it points to a deeper issue: clandestine mining can function as monetization infrastructure for criminal networks, not just as energy theft. In other words, the problem is not limited to stolen kilowatts. It can extend to money laundering, tax evasion, shell accounts, anomalous billing, and the takeover of buildings or facilities.

For a CISO in extractive or industrial sectors, the lesson is twofold. First, protecting energy infrastructure is not separate from cybersecurity, because power facilities and connectivity systems are part of the operational perimeter. Second, the lack of identified suspects in a case like this does not reduce the risk, it shows clandestine operations can go undetected for long periods. Security teams should review physical access to substations, power consumption monitoring systems, inventories of connected devices, radio link controls, and load anomaly alerts that could indicate unauthorized use of energy.

Mexico: simultaneous pressure from regional ransomware and critical exposure to infrastructure

Although the Puebla case was not classic ransomware, it unfolded in the same country amid a broader threat environment. Multiple reports said Mexico accounted for a significant share of ransomware attacks observed in Latin America during the first half of 2026, and that about 52 Mexican companies and entities were attacked in that period according to SCILabs. That data belongs to an earlier window and should not be added to September’s tally, but it helps frame the pressure on Mexican organizations with high exposure to digital extortion. In a country where organized crime, critical infrastructure, and industrial digitization intersect, the combination of energy theft, remote access, and extortion can escalate quickly.

The most important sector takeaway is that many assets in the mining and natural resources ecosystem depend on Mexican providers of services, logistics, maintenance, and technology. If the country shows a high base of ransomware incidents and growing sophistication in intrusions supported by new tools, the impact does not stop at the direct target. It also raises the risk of disruption to shared services, including billing, identity, communications, industrial system support, monitoring centers, and third-party platforms. For industries that depend on continuous operations, digital supply chain risk has to be treated as part of production risk.

The Puebla case also exposes a cross-cutting vulnerability, dependence on energy. In mining, metallurgy, and materials processing, operational continuity depends on pricing, availability, supply quality, backup power, and consumption control. A clandestine installation that steals power from a dam does not only consume resources. It can also degrade visibility, distort measurements, and complicate asset management in remote areas. Even though the case is still under investigation, it is a useful example of why security teams need to work more closely with operations, maintenance, and energy teams.

Argentina: Qilin claim against Ceres Tolvas and the reputational risk of leak sites

DeXpose reported that the ransomware group Qilin claimed to have attacked Ceres Tolvas, an Argentine industrial company, and that its post suggested a possible data leak if demands were not met. The source did not provide official confirmation from the company or independent proof of the incident. For that reason, the event should be treated cautiously. There is not enough evidence to say encryption occurred, data was actually exfiltrated, or operations were impacted. What can be verified is the existence of a claim in a leak site or a post attributed to the group, which by itself creates reputational and commercial pressure.

From an operational perspective, these signals matter because extortion groups exploit the gap between publication speed and verification speed. For an industrial company, being named by a criminal actor can trigger calls from customers, questions from banks, regulatory inquiries, and internal concern, even before any technical confirmation exists. That reputational pressure is not secondary. It can affect contracts, negotiations, tenders, and relationships with supply chain partners. When the available material does not say whether there was encryption or exfiltration, the security response should focus on forensic verification, credential control, and restrained internal communication.

The case also shows that manufacturing and materials companies remain attractive targets, even when they are not multinational giants. Attackers often look for organizations with a need for operational continuity, low tolerance for downtime, and valuable information assets such as customer data, purchase orders, plans, inventories, contracts, and financial records. In that sense, the exposure surface of an Argentine industrial company can be as attractive to an extortion group as that of an energy-intensive firm or a miner with a regional presence.

Panama: Incransom threat against Metales Panamericanos

Dexpose also reported that the ransomware group Incransom claimed to have attacked Metales Panamericanos, a company linked to the metals and construction materials sector in Panama, and threatened to publish information if negotiations did not begin. As in the Argentine case, the information was not corroborated by an official notice from the company, a CERT, a security vendor, or independent technical analysis. It is therefore not possible to confirm encryption or even validated exfiltration. What does exist is a claim that puts a metals-sector company on the digital extortion radar.

The analytical value of this kind of incident lies in the pattern, not in its isolated operational truth. Leak site campaigns usually target organizations with stable revenue, low public appetite for scandal, and a dependence on continuous operations. Panama also occupies a relevant logistics position in the region, which can make industrial and materials companies more attractive. The combination of metallurgy, construction materials, and extortion pressure suggests attackers are not focused only on obvious sectors such as finance or health care. They also look for productive chains with cash, sensitive data, and a strong need to avoid interruptions.

For security teams, the lesson is that a leak site mention requires formal handling, validation of credential exposure, review of remote access, key rotation, evidence preservation, and coordination with legal and communications teams. Even if the source does not confirm the incident, the risk of impersonation, follow-on phishing, and targeted fraud is real. Attackers often use these posts to amplify pressure, and industrial organizations can become exposed to secondary extortion by third parties posing as affiliates or brokers.

Peru: signal attributed to TheGentlemen against Comin SAC

Another case attributed by a secondary source was TheGentlemen against Comin SAC, a Peruvian company linked to mining. Again, the available information was not corroborated by the company, a CERT, or independent technical analysis. That prevents the alleged attack from being classified as encryption, exfiltration, or simple leak site presence. In an intelligence report, caution is mandatory. It should not be presented as a confirmed incident, but as a threat signal with potential reputational and operational impact if it were ever validated.

Even with that limitation, the case matters because of the profile of the alleged victim. Peru’s mining sector is a high-value target because of its economic weight, its dependence on continuous operations, and the sensitivity of its technical and contractual information. If a ransomware group claims to have reached a mining company or a company tied to mining, the organization should assume there was at least prior reconnaissance or exploitation of some exposed surface, even if the scope is uncertain. In companies in the sector, a good practice is to immediately review privileged identities, VPN or remote desktop exposure, network segmentation, and offline backups, without waiting for the threat to turn into a public leak.

Brazil: ClickFix, seized cryptoassets, and sustained pressure on critical organizations

Brazil contributed a different kind of risk during the period. On one hand, the Ministry of Justice and Public Security reported on Operação ClickFix, where victims were induced to execute malicious code through fake error notices on websites and browsers. On the other hand, the operation ended with the seizure of more than R$8.7 million in cryptoassets. Here there is a confirmed element of criminal activity disrupted by authorities, although the case is not limited to mining or natural resources. Its relevance to the sector lies in the method, deception, user-driven code execution, and monetization in cryptoassets.

That pattern is especially sensitive for industrial companies with distributed staff, contractors, maintenance providers, and operations teams that move between corporate systems and web applications. Campaigns that exploit fake errors or deceptive prompts can become the first step toward credential theft, malware installation, or workstation compromise, which then serves as a bridge to more sensitive systems. In mining and metallurgy, where the line between administrative users and operational technicians can be blurred, social engineering remains an effective entry path.

Brazil also stood out on another front. A journalistic report based on Fortinet data said the country recorded about 69,000 illegal cryptomining cases during 2026, surpassing the total from the previous year. As telemetry data, not confirmed incidents, it helps show environmental pressure on Brazilian organizations, but it should not be confused with a wave of concrete intrusions in the mining or natural resources sector. Even so, the figure suggests the region is dealing with an abuse ecosystem that goes beyond ransomware. Hijacked compute, unauthorized consumption, and endpoint manipulation are also part of the problem.

Chile: industrial cybersecurity, connected mining, and regulatory obligations

Although it was not an incident, the industrial cybersecurity meeting in Chile provides relevant context for the sector. The event addressed risks for connected mining, including remote control centers, autonomous trucks, and exploration drones connected in real time. Chile’s National Cybersecurity Agency also presented aspects of the Cybersecurity Framework Law 21.663 and the obligations that apply to Operators of Vital Importance. This does not describe an intrusion, but it does point to the direction of risk for an industry where digitization has become inseparable from productivity.

The takeaway for mining, metallurgy, and natural resources is clear. Connectivity brings efficiency, but it also expands the attack surface. A remote control center, an autonomous truck, or an exploration drone may depend on links, authentication, APIs, firmware, and real-time telemetry. If any of those components fail or are compromised, the impact can range from loss of visibility to the physical disruption of operations. For CISOs in the sector, the message is that industrial security cannot stop at firewalls. It needs asset security management, vendor validation, environment segmentation, firmware control, and operational resilience testing.

Cross-border risk: governments, telecom, and indirect value for the extractive sector

The FamousSparrow/SparroWocky and Salt Typhoon campaigns were not aimed exclusively at mining or energy companies, but they are highly relevant to them. ESET said FamousSparrow had likely replaced SparrowDoor with SparroWocky and observed the new tool against government entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. At the same time, Check Point Research described a China-aligned espionage campaign against Latin American government entities and a telecommunications organization in Puerto Rico. In both cases, a constant appears, interest in countries and organizations that hold information about critical infrastructure, the economy, and regulation.

For the natural resources sector, that matters because much of decision-making is intertwined with ministries, regulators, environmental authorities, ports, customs, and telecom operators. An intrusion into a government agency or a carrier may not affect a mine immediately, but it can enable reconnaissance, credential collection, or access to providers that later help compromise industrial operations. In other words, the target does not have to be the mining company for the impact to end up affecting it.

Countries

Mexico

Mexico concentrated two risk fronts in September. The first was the case in Puebla, where a clandestine cryptocurrency mine was operating connected to a hydroelectric dam and under suspicion of power theft. The second was the broader backdrop of ransomware and intrusion that had already been affecting the country since the first half of the year. The finding in Tlaola showed that the threat is not limited to offices or data, it can also take the form of unlawful energy use in remote environments that are difficult to supervise. For Mexico’s mining sector, that means closer attention to power monitoring, the physical integrity of infrastructure, and the detection of anomalous loads.

Mexico also appeared in Unit 42’s clusters and in coverage of AI-assisted intrusion, where transportation organizations, federal ministries, and municipal water companies were named. Although those incidents do not belong to the extractive industry itself, they reinforce a warning for mining suppliers and contractors, the country remains a space of varied offensive activity, with a mix of crimeware, phishing, automation, and exploitation of exposed surfaces. That density of threats increases the risk of pivoting from an administrative organization to industrial support systems, or the other way around.

Argentina

Argentina appeared on two different fronts. On one hand, Qilin’s claim against Ceres Tolvas put an industrial company on the extortion radar. On the other, the country was listed among the targets of espionage campaigns attributed to FamousSparrow and in coverage of Salt Typhoon. The convergence matters, this is not just an isolated company facing a ransomware threat, but a national environment that also appears in analyses of state or strategically aligned intrusion.

At the sector level, that means treating the protection of engineering, procurement, logistics, and finance data as one problem. Industrial and natural resource organizations in Argentina operate with complex supply chains and, often, with subcontractors at very different levels of maturity. An extortion group can exploit a minor incident at a vendor to reach the core network, while an espionage actor may go after credentials, emails, and documentation on projects, licenses, or financing. Defense needs to cover both vectors without assuming one excludes the other.

Panama

Panama saw the mention of Metales Panamericanos in a supposed Incransom case, and at the same time it appeared in the FamousSparrow campaign observed by ESET and The Record. That combination puts the country in an interesting position, on one side as the base for companies tied to materials and metallurgy that could be targeted for extortion, and on the other as territory watched by espionage actors seeking governments and possibly regional strategic information. Although none of the ransomware claims were corroborated, the risk signal for Panama’s industrial ecosystem is clear.

In a country with heavy logistics and trade exposure, the impact of a leak or an intrusion does not end at the affected company. It can reach shipping lines, freight forwarders, contractors, banks, insurers, and outsourced services. So even without confirmation of encryption or exfiltration, metallurgy and materials companies should assume they are operating in an environment where digital extortion can spread quickly through economic interdependence.

Peru

Peru was mentioned in the alleged TheGentlemen action against Comin SAC and, separately, in the geographic reach of the FamousSparrow campaign. The overlap does not prove any link between the cases, but it does show that the country appears on the map of interest for several threat actors. For Peruvian mining, this is especially sensitive because the sector combines high economic value, dispersed territorial presence, and dependence on complex corporate and logistics systems.

A CISO in Peru should read these signals as a prompt to strengthen access controls, segmentation, inventory, and incident response. If a mining company is named on a leak site, the risk does not end with the posting, it starts there. Possible consequences include targeted fraud, supplier-focused social engineering, secondary extortion, and exploitation of corporate anxiety. Without technical corroboration, the best defense is rapid validation and reputational damage containment.

Brazil

Brazil concentrated a significant share of the regional context, police operations against criminals using browser-based deception, official alerts on vulnerabilities, a high number of illegal cryptomining cases reported by the security ecosystem, and its presence in Unit 42 findings on the use of language models in intrusions. Although not all of those events relate to mining or natural resources, they define a highly active offensive environment that affects companies with complex operations and industrial technology suppliers.

For asset-intensive sectors, the key takeaway is that Brazil’s risk is not limited to classic ransomware. It also includes fraud, infrastructure abuse, vulnerability exploitation, and more sophisticated social engineering campaigns. In a market this large and digitally interconnected, attackers can test tactics in the general corporate environment and then move them into critical or regulated industries. Defense therefore has to cover email, identity, remote access, private clouds, and endpoint monitoring.

Chile

Chile did not produce direct incidents during the period, but it did provide a relevant regulatory and operational backdrop for connected mining. The discussion around autonomous trucks, exploration drones, and remote control centers shows where the attack surface is heading. That matters for companies operating across several countries in the region, because industrial cybersecurity requirements are becoming institutionalized, and organizations that do not adapt their security architecture to that reality will fall behind.

Law 21.663 on the Cybersecurity Framework and the category of Vital Importance Operators raise the expected standard. For the extractive sector, that means cybersecurity is no longer just a best practice, it is a condition for operation and regulatory trust. Companies with a presence in Chile should review how they document controls, what resilience testing they perform, and how they manage the security of vendors with access to remote systems or connected assets.

The first trend emerging from September is the convergence of energy infrastructure and criminal economics. The Puebla case shows that electricity theft and cryptocurrency mining can coexist in the same clandestine operation, with significant equipment and its own communications links. For mining, metallurgy, and natural resources, that means the line between cybersecurity and the physical protection of energy assets is becoming nearly indistinguishable. A security team that does not coordinate with operations, maintenance, and energy may miss an anomaly that later turns into losses or a more complex intrusion.

The second trend is the persistence of ransomware as a pressure tactic, even when the damage cannot always be proved with precision. Claims against companies in Argentina, Panama, and Peru show that extortion groups still see industry and construction materials as attractive targets. In a report like this, accuracy requires not turning claims into confirmed facts. But from a risk perspective, the existence of a malicious post is enough to trigger containment, validation, and communication measures. Modern extortion feeds on both encryption and rumor.

The third trend is the sustained interest of actors aligned with China, or described that way by private researchers, in strategic Latin American governments and organizations. Although the reports from ESET, Check Point and The Record focus on government entities, the value for mining and natural resources is indirect but serious. Where there are energy policies, concessions, infrastructure, and telecom networks, there is useful information for anticipating decisions, mapping projects, and understanding the network of actors surrounding an extractive industry. That kind of espionage does not always aim for immediate damage. Often, it aims for long-term positioning.

The fourth trend is the normalization of more adaptive intrusion techniques. Unit 42 and related coverage described campaigns that use language models, iterative scripts, living-off-the-land techniques, custom RATs, and Go-based proxies. In other words, tools that reduce footprint, increase flexibility, and make classical detection harder. For industrial sectors, that means blocking known malware is no longer enough. Organizations need to detect anomalous behavior, lateral movement, unusual use of administrative tools, strange outbound connections, and automation patterns that do not match normal operations.

The fifth trend is the growing role of access and administrative vulnerabilities. Although September’s material includes bulletins from multiple vendors and catalog alerts, the key point for Latin America is that attackers continue to exploit exposed management products, remote services, and identity systems. In mining and metallurgy, where third-party integrations, remote workstations, monitoring panels, and contractor access are common, every exposed interface is an opportunity to pivot. Reducing the attack surface therefore remains a high-return priority.

In regional terms, September suggests that the countries with the most digitized industrial ecosystems, Mexico, Brazil, Chile, Peru, Argentina, and Panama, face a mix of risks, extortion, espionage, energy fraud, and infrastructure abuse. The response should not be fragmented by incident type. One security program must cover identity, workstation hardening, network monitoring, asset inventory, remote access control, response to leak sites, third-party protection, and energy governance.

Recommendations for CISOs

First, assess the energy and physical perimeter with the same rigor used for the digital perimeter. The Puebla case shows that a high-consumption facility can remain hidden if there are no controls on electrical load, access to substations, transformer monitoring, or alerts for unusual consumption. Security and operations teams should agree on anomaly thresholds, escalation owners, and physical inspection procedures when persistent deviations appear.

Second, strengthen protection against extortion and data leakage. If an organization appears on a leak site, even if the data is not verified, response time matters. It is advisable to have a playbook that includes technical validation, forensic preservation, credential rotation, data exposure assessment, coordination with legal and communications, and monitoring for follow-up phishing. The costliest mistake is treating the claim as noise until it is already affecting customers or suppliers.

Third, close remote access and administration surfaces. The evidence from the month, along with the September vulnerability alerts, reinforces the need for phishing-resistant MFA, strict segmentation, expiring third-party access, review of privileged accounts, and monitoring of administrative sessions. In OT environments, any remote access to HMI, historians, jump servers, or maintenance tools should be inventoried and justified.

Fourth, raise digital supply chain resilience. Many mining and metallurgy companies depend on integrators, maintenance providers, telecommunications, logistics, and consulting. If one of those links fails, operations can be affected even if the core network remains up. It is advisable to include security clauses in contracts, require early incident notification, audit minimum practices, and segment third-party access.

Fifth, adopt behavior-based detection, not signatures alone. The campaigns described by Unit 42 and other analyses show the use of more flexible, lower-footprint techniques. Defense teams should look for authentication anomalies, unusual traffic, atypical use of PowerShell or batch, connections to unknown domains, and suspicious scheduled tasks. In industrial environments, it is also worth watching for changes in consumption, latency, and the availability of connected assets.

Sixth, integrate regional threat intelligence with operational context. Not every campaign against governments or telecoms will directly affect a mining company, but they can help anticipate vectors, countries of interest, and reusable tools. A strong intelligence program does not just collect news, it turns it into concrete risk hypotheses about assets, suppliers, and the geographies where the company operates.

Material limitations

This report is based solely on the research material provided, so its scope depends on the quality, date, and corroboration of those sources. Several signals should be treated with caution: some are claims by criminal groups without independent verification; others are technical or journalistic coverage that summarizes findings from third parties; still others are vulnerability alerts or telemetry reports that describe exposure, not confirmed incidents. For that reason, this report distinguishes between confirmed fact, source attribution, and uncorroborated signal.

It is also important to stress that the absence of a confirmed incident in the material analyzed does not mean there was no activity in the region. Likewise, elevated telemetry on cryptomining or blocked attempts should not be interpreted as a concrete operational incident without additional evidence. September showed high pressure across the Latin American ecosystem, but the analytical value lies in verifiable facts: Puebla, extortion claims, espionage campaigns, and security alerts affecting the region's technology environment.

Frequently Asked Questions

What was the most relevant development of the month for mining and natural resources?

The most significant case was the illegal cryptocurrency mining farm dismantled in Puebla, which was illegally connected to a hydroelectric dam. Beyond the criminal angle, the episode showed how energy infrastructure and remote connectivity can be abused in industrial or rural settings with limited oversight.

Was there a major confirmed ransomware attack against a mining company in September?

The material reviewed did not include a major confirmed ransomware case with proven operational impact against a specific mining company. There were claims against industrial companies or firms linked to mining in Argentina, Panama and Peru, but the sources did not independently corroborate whether there was encryption, exfiltration or only a mention on a leak site.

Which country showed the greatest operational pressure?

Mexico stood out for the combination of the Puebla illegal farm and the regional ransomware context observed during the first half of 2026. Brazil also showed heavy security activity, although several references relate to telemetry, alerts or police actions, not confirmed incidents in the mining sector.

What should CISOs do first?

The most urgent step is to review remote access, segmentation, privileged credentials and monitoring for unusual energy or connectivity consumption. It is also advisable to prepare a reputation and extortion playbook, verify any mention on leak sites quickly, preserve evidence and coordinate internal and legal communications without improvising.

Sources