CiberLATAMbywhalemate
Intelligence reportAug 7, 202629 min read

Latin America Cybersecurity Landscape, July 2026

July ended with regulatory pressure, banking fraud, ransomware in healthcare, and attacks on government and energy across the region.

Latin America Cybersecurity Landscape, July 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are filled automatically with the verified dated facts within the period. Each one states its basis and counting criteria so the figures reconcile across modules. They are the recurring month-by-month readout; the analysis that follows develops the cases without repeating this summary.

Indicator window: 867 dated facts in July 2026 · 9 from prior months (comparative frame, not month volume) · 41 without confirmed date (excluded from indicators) · 6 after the period (excluded). Facts from prior months are used only as a comparative frame in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Monthly verified signal dashboard July 2026 · Latin America Leading threat: Regulation (261 of 854 events). Coverage: 867 dated events in July 2026 · 9 months ago… VERIFIED EVENTS 854 period base: total count measured from below against this total RANSOMWARE / EXTORTION 126 21 encrypted assets confirmed · 4 exfiltration unencrypted (simple extortion) UNTYPED INCIDENTS 85 breaches or outages without declared threat type FRAUD / PHISHING 101 documented fraud campaigns REGULATION 261 rules, resolutions, or penalties UNIQUE CVEs 22 CVE-2023-20269 / CVE-2023-46805
Monthly verified signal dashboard — Base: 854 verified dated events for Latin America.
MONTHLY FIXED MODULE Threat axis distribution July 2026 · Latin America Each event counts in only one axis, so the total is exactly 854. "Unclassified incidents" is the remainder. Regulation 261 Unclassified 196 Ransomware 126 Fraud 101 Vulnerabilities 85 Incidents 85
Threat axis distribution — Each event is assigned to a single axis based on its classification; the total reconciles to the 854 events in the period.
FIXED MONTHLY MODULE Sector Distribution of Signal July 2026 · Latin America Base: 854 incidents in the period · total 1086 because 204 incidents are classified in more than one sector. Other / no sector ident… 275 Public sector / OIV 271 Finance 180 Technology 138 Telecom 98 Healthcare 73 Retail / Consumer 28 Energy 23
Sector Distribution of Signal — Heuristic classification by victim sector. One incident may affect more than one sector, so the total may exceed the base.
MONTHLY FIXED MODULE Geographic distribution of signal July 2026 · Latin America Each fact is assigned to a single country or to regional coverage, so the total is exactly 854 out of 854 facts … Brazil 189 Argentina 179 Mexico 143 Chile 121 Colombia 86 Peru 53 Paraguay 33 Bolivia 28 Regional 22
Geographic distribution of signal — Verified facts for the period grouped by country or regional coverage; each fact is counted only once.

Monthly executive summary

July 2026 produced a regional picture shaped by two forces moving in parallel. The first was regulatory. The month closed with 261 documented regulatory-related events in the verifiable database, making that axis the period's leading threat. The second was operational, with a mix of digital fraud, ransomware, and attacks on public agencies and critical sectors that again showed Latin America under sustained pressure, most visible in banking, healthcare, government, and energy.

The most consequential incident in terms of impact was the attack on Ecopetrol in Colombia. The company confirmed unauthorized access on July 17, activated its internal protocol, coordinated with the Fiscalía and the MinTIC to remove leaked files, and filed a 6-K with the SEC. The public attribution to the group The Gentlemen, along with the claim that it had up to one terabyte of information, was not validated by the company, but the episode stood out as one of the month's main events because it combined extortion, data exposure, and corporate and regulatory sensitivity.

Brazil carried the clearest pressure on critical infrastructure and healthcare. The country continued to appear as the regional epicenter of healthcare ransomware, with multiple reports involving hospitals, clinics, and healthcare providers, as well as incidents targeting energy and utilities. Global Secret Group listed SPDM and Sinop Energia on its leak site, while Blackwater appeared linked to msgas.com.br. At the same time, CERT.br and CTIR Gov warned about critical vulnerabilities actively being exploited in VPNs, SharePoint, and Ivanti, a set of issues that helps explain why the country sustained very high exposure across both corporate and state perimeters.

Argentina, meanwhile, combined a regulatory agenda with a wave of digital fraud especially visible in banking and digital wallets. The Central Bank stepped up its anti-fraud messaging, published formal complaint guidelines, and alerts multiplied around vishing, WhatsApp impersonation, synthetic identities, and the use of AI to speed up scams. At the same time, Mendoza became the region's most active regulatory laboratory in the month, with bill proposals on cybersecurity, data protection, data governance, ethical hacking, and rapid incident notification. The province was also caught in a politically sensitive moment, as the legislative debate moved forward and the Senate website was breached in a politically motivated attack.

Chile added another strong regulatory thread, with the deepfake bill advancing in the Chamber of Deputies and new CSIRT alerts about OpenSSH, Ivanti, Citrix, SharePoint, and vulnerabilities in exposed environments. Chile's monthly picture combines three layers, technical pressure on the perimeter and appliances, regulatory adjustments to address fraud and impersonation in the financial system, and a growing legislative debate over digital identity and AI-generated content.

July's regional signal was not a single major shock, but an ecosystem hardening on several layers at once. Criminal groups kept exploiting credentials, VPNs, and exposed services. Banks and fintechs accelerated identity and authentication controls. Governments, especially in Argentina, Chile, Colombia, and Brazil, strengthened reporting, sanctioning, and governance frameworks. And AI emerged as a multiplier in both defense and attack, especially in identity fraud and assisted operations across OT and administrative environments.

Regional outlook for the month

The risk picture for Latin America in July 2026 is high. Not because of a single outlier campaign, but because several threat layers are hitting at once. There was extortion and ransomware targeting health care, energy, and the public sector. There was banking fraud and identity theft across several markets. There were critical vulnerabilities being exploited in widely used products. And there was an aggressive regulatory push that, while positive for institutional maturity, also shows the problem has reached the center of the public agenda.

The most repeated technical pattern was initial access through exposed surfaces and credential abuse. In ransomware, the month showed continuity in classic vectors, such as vulnerable VPNs, remote access services, exposed hypervisors, and poor configurations in third-party infrastructure. On the fraud side, the evidence pointed to social engineering, identity cloning, vishing, banking phishing, fake profiles, and the use of AI to clone voices, generate deepfakes, or automate contact with victims. The region is not facing abstract threats, but very concrete tactics that exploit operating habits and weak customer service channels.

Pressure on the financial sector was broad-based. In Argentina, the BCRA toughened its information stance and reinforced the need to use formal channels for fraud complaints. In Chile, the CMF pushed changes to stronger authentication, and banks reiterated that they never ask for passwords or codes over the phone. In Mexico, the industry acknowledged the need to bring cybersecurity and anti-fraud agendas together. In Colombia, complaint channels and account takeover patterns reflected a financial market with growing exposure. The regional trend is clear, fraud is no longer a byproduct, but a criminal business line with its own industrial scale.

At the same time, regulation stopped being background noise and became a central part of the threat map. Mendoza debated a provincial cybersecurity law covering data governance, penalties, mandatory reporting, and responsibilities for public agencies and critical service providers. Chile moved ahead on deepfakes and strengthened its fraud framework. Colombia consolidated rules on safe digital environments for minors. Brazil kept expanding the regulatory perimeter around platforms, big techs, and sensitive data. The result is a region where cybersecurity is no longer discussed only in technical terms, but also as an architecture of compliance, accountability, and oversight.

The severity picture differs by country, but the underlying issue is the same, exposure is growing faster than the ability to reduce risk. That is visible in the volume of regulatory reports, the repeated fraud campaigns, the persistence of ransomware, and the emergence of actors combining AI with well-known tactics. The risk is high because incidents continue to show operational reach, data exposure, reputational pressure, and, in some cases, potential impact on essential services.

Visible pressure by countryQualitative reading, from high to medium, based on verified incidents, regulations, and alertsBrazilHighArgentinaHighChileHighColombiaHighMexicoMedium-high
Countries with the highest visible pressure — Qualitative reading based on verifiable facts from the period, not on aggregated telemetry or a made-up metric.

Period indicators

Indicator Value Reference or breakdown
Verified events in the period 854 Base for all indicators, calculated only from facts dated within July 2026
Time window for the indicators 867 facts dated in July 2026 · 9 from previous months (comparative frame, not monthly volume) · 41 without confirmed date (excluded from indicators) · 6 after the period (excluded) Declared time window for the file
Untyped incidents 85 Breaches or disruptions without precise classification
Cases with ransomware or extortion as the primary focus 126 Single ransomware or extortion category
Confirmed encryption of assets 21 Ransomware breakdown
Exfiltration without encryption, simple extortion 4 Ransomware breakdown
Mention only on leak site 3 Ransomware breakdown
Cases whose classification cannot be determined from the material 98 Ransomware breakdown
Documented fraud or phishing cases 101 Documented cases in the period
Documented regulatory moves 261 Predominant threat of the month
Critical CVEs mentioned 22 Critical vulnerabilities mentioned in the material
Sectors with at least one documented event 8 Sectors reached by the signal
Predominant threat of the month Regulation 261 of 854 facts
Events with direct source confirmation 93% Direct confirmation based on the verifiable record
Aggregate telemetry figures excluded from volume 13 Aggregated attempts or blocks, not incidents with confirmed impact

The table shows a regional signal heavily skewed toward regulation, but that should not be read as an automatic reduction in operational risk. On the contrary, regulatory intensity is often the response to an ecosystem where fraud, extortion and data exposure are already persistent. Telemetry should also be kept separate from incidents, detection, attempt and blocking figures appear in the material as background noise, not as verified intrusions.

Relevant incidents

Ecopetrol and the extortion attributed to The Gentlemen

The most sensitive case of the month in Colombia was Ecopetrol. The company reported an unauthorized access on July 17, confirmed that it had not identified disruptions in operations or impacts on production or essential services, and later said it was working with the Attorney General's Office and the Ministry of ICT to remove leaked files from the internet. It also filed a Form 6-K with the SEC, which elevated the incident into a regulatory and financial sphere outside the country.

The public attribution to the The Gentlemen group, along with the claim that the actor had up to one terabyte of information with drilling records, payroll data, banking data, medical histories, biometrics and VPN credentials, was not corroborated by the company. Even so, the incident falls into the category of exfiltration with extortion pressure, because the available evidence points to leakage and demands for information rather than disruptive system encryption. For the region, the message is clear, reputational damage and exposure of sensitive data are already affecting strategic infrastructure and high-profile companies.

Mendoza Senate, breach and legislative agenda

Mendoza saw an unusual sequence over just a few days. As debate advanced on a Cybersecurity Law bill, the provincial Senate website was breached and displayed an image with a message against Argentina. Local press reported the incident as a cyberattack on the institutional site, and some coverage said a link to the legislative debate could not be ruled out, although that connection remained speculative.

Beyond attribution, the episode carried symbolic weight. The province had been presenting its initiative as a comprehensive framework to protect critical infrastructure, data and public services, with components for reporting within 72 hours, citizen notification, creation of a provincial cybersecurity system, an executive committee, an operational authority and even a provincial incident registry. The fact that the legislative chamber was altered while the debate was underway highlighted the gap between the policy design and the reality of the digital perimeter.

Global Secret Group, SPDM and Sinop Energia

Brazil produced two very different cases, but both were tied to the same criminal logic. On one side, healthcare provider SPDM appeared on Global Secret Group's leak site with a claim of 847 GB of stolen data. On the other, Sinop Energia, the operator of a hydroelectric plant in Mato Grosso, was also listed by the same group with an estimated exfiltration of 300 GB. In both cases, the available material confirms publication on leak sites and data exposure, but does not document operational encryption of assets.

The reading of these cases is twofold. First, energy and health remain high-value targets for extortion actors, because of the sensitivity of the data and the potential for reputational pressure. Second, the leak site remains a coercive tool strong enough to sustain campaigns even when there is no public evidence of total outage. In Brazil, that overlaps with a very broad attack surface and with official alerts about active exploitation of vulnerabilities in exposed appliances and servers.

Msgas.com.br and the Blackwater campaign

Also in Brazil, the site msgas.com.br was linked to Blackwater in a ransomware incident with data publication on July 25. The available technical analysis indicates that the group said it had stolen personal customer information, contracts and internal data. According to that coverage, the case fits more cleanly into an extortion scheme with data exposure than into large-scale operational sabotage.

The analytical value of the episode lies in the sector. Energy and public services remain attractive because they combine operational criticality with the commercial value of information. When personal data, contracts and internal documents are combined, the attacker does not need to take down the entire operation to create enough pressure. Exfiltration becomes the main weapon.

AFA and unauthorized access to an institutional account

Although smaller in scale than the cases above, the unauthorized access to an institutional AFA account showed another pattern that is highly relevant for the region. The organization said emails were sent from that account without authorization. The confirmation does not mention encryption or major public exfiltration, but it does indicate compromise of institutional identity, a vector that can enable secondary phishing, impersonation and abuse of trust.

That kind of incident matters because it feeds the rest of the criminal ecosystem. A compromised institutional account becomes a platform for fraud, social engineering or malware distribution, especially when it comes from a highly visible organization. In Latin America, where trust in known senders remains a decisive factor, this type of event can spread farther than the initial damage suggests.

Threats and active campaigns

Ransomware and extortion

The month confirmed that ransomware in the region is not concentrated in a single sector or tied to one model. In Argentina, pressure on the Ejército Argentino surfaced through Qilin, with leak site activity and references to associated credential compromise. In Brazil, Global Secret Group was linked to health care and energy victims, while Blackwater appeared in a gas case. In Colombia and Mexico, different reports described intrusions and campaigns that combine data theft, extortion pressure and, in some cases, attacks on public services.

Most of the cases did not allow for a precise determination of whether assets were encrypted. That matters methodologically. The material makes it possible to distinguish several scenarios, but in many notes the confirmed fact is the appearance on a leak site or mention of leaked data, not system unavailability. When the material does not specify the operational effect, that should be stated clearly and the impact should not be overstated. Even so, the regional pattern is clear, extortion with exfiltration is gaining ground over purely disruptive ransomware.

In Brazil, pressure on health care was the most intense. ESET reported that in the first half of 2026 the country accumulated more than 100 ransomware victims, while sector-specific material noted that Brazilian health care faced pressure far above the global average. That context does not turn every case into a total outage, but it does point to a sustained chain of exposure across hospitals, clinics and providers.

In Argentina, Qilin and The Gentlemen show two complementary styles. Qilin appears as an extortion actor with a leak site, while The Gentlemen sits within the orbit of threats that use leaks and public pressure. In both cases, the gap between "claim" and "confirmed breach" must remain clear. Appearance on leak sites is a sign of risk, but it does not by itself prove encryption, full exfiltration or final operational impact.

Fraud and phishing

Digital fraud was likely the most common threat of the month. Argentina showed a particularly dense picture, with vishing campaigns, "paid likes" scams, identity theft through WhatsApp, techniques that block home banking and then impersonate the bank, and variants that use AI to clone voices or images. The BCRA responded with more precise guidance on what to do after a scam, what information to gather and why the first complaint should go through the financial institution.

The signal is not only local. Mercado and Sumsub showed a regional jump in AI-generated identity fraud, with Argentina, Chile and Colombia among the countries where the phenomenon accelerated. BioCatch, cited in several reports, pointed to a sharp increase in social engineering and impersonation. In Mexico, CONDUSEF reported impersonation of financial institutions and the press again focused on banking phishing, fake profiles and fraudulent loan offers. In Colombia, account takeovers, mule accounts and spoofing became a very active combination.

The new development this month is that fraud no longer depends only on traditional human deception. It increasingly relies on technical layers, deepfakes, voice cloning, bots for initial contact, synthetic documents and automation of the interaction with the victim. The operational consequence is clear. Static controls are not enough. Contextual verification, transactional behavior monitoring, risk monitoring and stronger authentication barriers are needed.

APT, hacktivism and AI abuse

In the APT space, or among actors using more advanced techniques, the month produced two very different signals. The first was PhantomEnigma, a campaign that abused Brazilian government domains to distribute malware and targeted banks and public agencies. The value of the case is not only in the malware, but in the trust abuse involved in using compromised .gov.br domains as a delivery vector. The second was the AI-assisted intrusion against Mexican government organizations and a water utility in Monterrey, where Dragos and Gambit Security said the attacker used models such as Claude and GPT to speed up reconnaissance, credential generation and password spraying.

In both cases, the key takeaway is that AI is already operating as a multiplier in different phases of the attack. It does not necessarily introduce a new offensive technique, but it does speed execution, reduce time and widen the target set. That is enough to change the economics of campaigns. The adversary can explore more, faster and at lower operational cost.

Critical vulnerabilities

CVE Software Exploitation Source
CVE-2026-25243 Redis OSS/CE, Redis Software, RedisTimeSeries PoC circulating, authenticated exploitation possible, RCE and memory corruption CGII Bolivia, 2026-07-23
CVE-2026-25588 Redis OSS/CE, Redis Software, RedisBloom PoC circulating, authenticated exploitation possible, RCE and memory corruption CGII Bolivia, 2026-07-23
CVE-2026-25589 Redis OSS/CE, Redis Software, RedisBloom PoC circulating, authenticated exploitation possible, RCE and memory corruption CGII Bolivia, 2026-07-23
CVE-2026-23479 Redis OSS/CE, Redis Software PoC circulating, authenticated exploitation possible, RCE and memory corruption CGII Bolivia, 2026-07-23
CVE-2026-23631 Redis OSS/CE, Redis Software PoC circulating, authenticated exploitation possible, RCE and memory corruption CGII Bolivia, 2026-07-23
CVE-2024-24919 Check Point VPN gateways Active exploitation confirmed, sensitive memory reading and compromise in Brazilian organizations CERT.br and Check Point, 2026-07-22 / 2026-07-23
CVE-2026-56291 Balbooa Forms for Joomla Active exploitation, unauthenticated file upload and RCE CTI Pilot, SentinelOne, Cyberwald, 2026-07-09 to 2026-07-10
CVE-2024-6387 OpenSSH Active exploitation confirmed according to CSIRT Chile CSIRT Government of Chile, 2026-07-24
CVE-2026-50522 Microsoft SharePoint Server Known exploitation, RCE, theft of machine keys and KEV listing CISA, CTIR Gov, Datawiza, Zetik, 2026-07-22 to 2026-07-24
CVE-2026-58644 Microsoft SharePoint Server Known exploitation, included in KEV Security Affairs, 2026-07-23
CVE-2023-46805 Ivanti Connect Secure Active exploitation, chained with CVE-2024-21887 CSIRT Government of Chile, 2026-07-23
CVE-2024-21887 Ivanti Connect Secure Active exploitation, chained with CVE-2023-46805 CSIRT Government of Chile, 2026-07-23
CVE-2024-22024 Ivanti Active exploitation reported CSIRT Government of Chile, 2026-07-23
CVE-2024-22026 Ivanti Active exploitation reported CSIRT Government of Chile, 2026-07-23
CVE-2024-22028 Ivanti Active exploitation reported CSIRT Government of Chile, 2026-07-23
CVE-2024-22029 Ivanti Active exploitation reported CSIRT Government of Chile, 2026-07-23
CVE-2024-22030 Ivanti Active exploitation reported CSIRT Government of Chile, 2026-07-23
CVE-2026-15409 SonicWall SMA1000 Critical firmware vulnerability, flagged by INCIBE and cited regionally Moncloa and INCIBE, 2026-07-15
CVE-2026-15410 SonicWall SMA1000 Critical firmware vulnerability, flagged by INCIBE and cited regionally Moncloa and INCIBE, 2026-07-15
CVE-2026-23479 Redis OSS/CE, Redis Software, RedisTimeSeries Redis security advisory, high severity CGII Bolivia, 2026-07-22
CVE-2026-25243 Redis OSS/CE, Redis Software Redis security advisory, high severity CGII Bolivia, 2026-07-22
CVE-2026-25588 Redis OSS/CE, Redis Software, RedisBloom Redis security advisory, high severity CGII Bolivia, 2026-07-22
CVE-2026-25589 Redis OSS/CE, Redis Software, RedisBloom Redis security advisory, high severity CGII Bolivia, 2026-07-22
CVE-2026-23631 Redis OSS/CE, Redis Software Redis security advisory, high severity CGII Bolivia, 2026-07-22

The vulnerability block shows a very consistent pattern. The exposed products are almost all part of the remote access layer, web collaboration, or critical databases. In other words, they are exactly the components attackers value most because they can be used to breach the perimeter, steal keys, or reach internal infrastructure. The region should read these alerts less as isolated events and more as a list of likely attack vectors for the coming weeks.

Regulation and Compliance

Argentina, Mendoza, and the shift toward rapid notification

Argentina was the country with the most visible regulatory activity in the month. Mendoza province concentrated several parallel proposals. One, backed by the executive branch, seeks to create a Provincial Cybersecurity System to coordinate prevention, detection, response, and recovery. Another, introduced by Fuerza Patria, proposes a law against cybercrime and for personal data protection across provincial and municipal public agencies. Both texts share elements that are already standard across the region: incident notification within 72 hours, appointment of data officers, privacy by design, and traceability in data processing.

The debate is no small matter. Mendoza also added notions of data governance, information life cycle, an operational authority separate from the committee, tiered sanctions, and even a regime for ethical hackers, or white hats. That points to an unusually ambitious regulatory push for a subnational jurisdiction. If enacted, the province could become a reference point for other local governments, although it remains to be seen whether the proposed architecture can withstand implementation.

At the national level, Resolution 725/2026 in the Official Gazette updated police protocols for cybercrime, especially when minors are involved. At the same time, the BCRA strengthened its anti-fraud regime, with specific recommendations and a more formalized complaint process. The institutional message is that digital fraud damage is no longer treated only as a user problem, but as an operational and regulatory risk for the financial system.

Chile and digital identity as the focus

Chile had a particularly active month in cybersecurity regulation. The Chamber of Deputies approved in general the bill on deepfakes, which is moving forward in the legislative process and seeks to regulate the creation and dissemination of realistic digital imitations of image, body, or voice. The logic of the text is clear, protect digital identity and integrity against AI-generated content and give tools to remove content, sanction harm, and hold platforms and legal representatives accountable.

At the same time, guidance from the Central Bank and the Financial Market Commission kept a hard line on fraud involving cards and financial instruments. The country consolidated a standard in which issuers must offer free 24/7 channels, block inactive instruments, periodically report affected users, and provide itemized information to the CMF. On authentication, the new ARC is pushing banks and fintechs to strengthen multifactor authentication and abandon weak schemes such as coordinate cards.

The other side of the picture is operational. CSIRT Chile issued alerts on OpenSSH, Ivanti, Citrix, and SharePoint. That shows an institutional setup that not only regulates, but also issues timely warnings about exploited flaws. The country thus stands out as one of the region’s most complete cases in the overlap of prevention, reporting, and enforcement.

Brazil, platforms, data, and oversight

Brazil continued to move on two tracks. On one, it tightened the regulatory environment for platforms and data, with a set of changes that also affect digital governance and supervision. On the other, its technical bodies, such as CERT.br and CTIR Gov, issued alerts about active exploitation of vulnerabilities in VPNs, SharePoint, Ivanti, and other exposed surfaces. Brazil’s regulatory picture is not limited to a single topic. It spans big tech, data protection, AI in health, and increasingly concrete security requirements.

At the same time, the LGPD continued to serve as the enforcement backbone for the compliance ecosystem. Although the material does not reconstruct a single major regulatory leap in July, it does show ongoing oversight and a more sophisticated institutional approach. The political takeaway is obvious, Brazil already operates with a more developed enforcement apparatus than much of the region, and its economic weight means that any shift in standards spreads to banks, healthcare, retail, and platforms.

Colombia, minors, and digital co-responsibility

Colombia issued Decree 0769 of 2026, which regulates Law 2489 of 2025 and sets out shared responsibilities among platforms, schools, and families to ensure safe digital environments for girls, boys, and adolescents. The focus is on cyberbullying, exploitation, online sexual abuse, and inappropriate content. It also requires platform providers, apps, video games, and AI services to identify risks, adopt protective measures, provide complaint mechanisms, and report periodically to the Ministry of ICT.

The shift matters because it reflects a broader digital safety policy that is no longer centered only on financial fraud or critical infrastructure, but also on minors’ exposure and the responsibility chain of digital intermediaries. In a country with high fraud volumes and significant financial exposure, the decree broadens the regulatory perimeter and forces platforms and providers to take on part of the problem.

Guatemala, Mexico, and Peru

Guatemala continued debating its Initiative 6347 on cybercrime, with penalties of up to nine years for conduct such as unlawful access, attacks on system integrity, computer fraud, and misuse of devices. Mexico, for its part, showed a more fragmented regulatory debate, with references to AI, minors, digital fraud, and impersonation of financial institutions, but without a single consolidated rule in the material reviewed. Peru kept a relevant front open with the SBS warning about identity theft in financial products and the BCRP deepening changes in payments and transfers, although much of that material appears more as a compliance framework than a specific risk incident.

Latin America’s most affected countries

Argentina

Argentina combined three layers of pressure. First, financial fraud and identity theft, with recurring BCRA advisories, vishing campaigns, fraudulent WhatsApp messages, home banking lockouts, and the use of AI for more sophisticated scams. Second, Mendoza’s regulatory agenda, which was the most visible in the region during the month for a subnational jurisdiction. Third, the Argentine Army case on Qilin’s leak site and the intervention on the Mendoza Senate website, which left a clear sign of institutional exposure.

The technical takeaway is that the country is dealing with two different surfaces. One is financial, where fraud is scaling through social engineering. The other is state-linked, where the cybersecurity debate is already translating into bills, reporting requirements, and governance. The bridge between both is data protection and the need to strengthen digital identity.

Brazil

Brazil had the broadest and, at the same time, most varied ecosystem. It saw ransomware cases in health care, energy, and gas. It had official alerts about active exploitation of VPNs, SharePoint, and Ivanti. It also saw campaigns abusing government domains. On top of that, telemetry showed very high volumes of phishing attempts and ransomware activity, although those figures should be read as detection volume, not as confirmed incidents with impact.

On the sector side, health care was the most sensitive node. But the country also showed pressure on electric infrastructure and service providers. That means Brazil’s attack surface is not concentrated in a single vertical. It stretches from hospitals to utilities and platforms, with a corporate perimeter that remains a preferred target.

Chile

Chile stands out as the country with the strongest regulatory density and one of the most committed efforts to close gaps in authentication and exposure. The deepfakes bill, the Central Bank’s guide on card fraud, the ARC, and CSIRT alerts make up a fairly coordinated state response. At the same time, the country is not free from technical pressure. Warnings about OpenSSH, Ivanti, Citrix, and SharePoint confirm that exposure remains a serious issue.

Chile’s financial system appears to have understood earlier than others the link between fraud, authentication, and issuer liability. That gives it an advantage, but it does not eliminate risk. Banks’ repeated reminders that they never ask for passwords or codes by phone show that social engineering is still widespread.

Colombia

Colombia had an intense month because of the Ecopetrol case and the financial fraud front. The country was already facing high exposure to social engineering, impersonation, account takeover, and mule accounts. The attack on Ecopetrol raised the stakes because it involved a flagship company, with possible extortion and exposure of sensitive data. At the same time, the decree on safe digital environments for minors broadened the security agenda into a more social and regulatory space.

The Colombian case shows how two layers of risk coexist. One is patrimonial, where banking fraud and impersonation are highly industrialized. The other is corporate and critical, where energy companies and essential services become targets for more complex campaigns. The appearance of new AI tactics and exposed remote access reinforces that reading.

Mexico

Mexico appears in the material more as a setting for debate and high-impact attacks than as a country with a single dominant trend. There were reports of banking fraud, impersonation of institutions, phishing, AI-driven campaigns, and the alleged SIDAC breach, as well as the AI-assisted intrusion against Mexican government bodies and the water utility in Monterrey. There was also debate over whether AI regulation should move sector by sector or through a general law.

The strongest signal is that Mexico is highly exposed both to financial impersonation and to attacks on government and public services. The coexistence of mass fraud and complex intrusions forces different controls depending on the type of asset. A bank account is not defended the same way as a state system holding citizen data.

Peru

Peru had a narrower signal, but not an insignificant one. The SBS warned about identity theft in financial products, and the BCRP continued adjusting the payments system and transfer rules. It is a country where the regulatory layer is advancing and financial controls are becoming more formalized, although the month’s material did not show the same volume of incidents seen in Brazil, Colombia, Mexico, Argentina, or Chile.

Paraguay, Bolivia and the United States

Paraguay was absent from the month’s verified impact picture, although the file includes regulatory and comparative context. Bolivia had a relevant intervention with the CGII alert on Redis, a useful regional signal of technical response to critical CVEs. The United States appears only indirectly, as a regulatory or ecosystem reference, with no region-specific facts during the period.

There is no month-over-month comparative baseline of our own for this indicator format in Latin America, so it would be incorrect to invent a month-to-month change. What can be read instead is the consolidation of trends that were already taking shape and became clearer in July.

The first signal is the growth of AI-assisted identity fraud. The material from Argentina, Chile, Colombia, and Mexico repeats deepfakes, impersonation, voice cloning, synthetic profiles, and automated outreach. At the same time, banks are tightening authentication and regulators are pushing procedural changes. The signal to watch is whether that technical escalation starts to translate into stricter contextual validation requirements and more friction for users.

The second signal is the persistence of ransomware with a focus on health care, energy, and the public sector. Brazil accounts for the most visible share of that pressure, but Argentina, Colombia, and Mexico also saw related events or campaigns. The point to monitor is not only which groups are attacking, but which vectors they use, especially VPNs, exposed services, hypervisors, and leaked credentials.

The third signal is the maturation of the regulatory response. Mendoza, Chile, Colombia, and Brazil moved ahead with tougher rules on reporting, penalties, notification, authentication, and platforms. This does not eliminate risk, but it does change the cost of operating without controls. The key question is which jurisdictions manage to turn the rule into practice and which remain on paper.

The fourth signal is that AI is no longer just a defensive story. In several incidents it appeared as an offensive accelerator across government, OT, fraud, and the generation of fake identities. The question is not whether AI is present, because it already is. The question is which stage of the attack it helps most, and how controls are prioritized to cut off that advantage.

Recommendations for security teams

First, harden the remote access layer. This month’s material again shows VPNs, gateways, appliances, and exposed services as recurring attack vectors. That means prioritizing real MFA, configuration reviews, credential rotation, minimal exposure, and continuous monitoring for anomalous access. A patch being available is not enough if the perimeter stays open or authentication remains weak.

Second, strictly separate fraud controls from intrusion controls. Digital fraud in the region already uses social engineering, AI, and impersonation. Teams need contextual validation, transaction behavior analysis, out-of-band verification, and adaptive friction rules. In banking and fintech, treating everything as generic phishing is not enough.

Third, review detection and response capabilities for institutional accounts. The AFA showed how a single compromised account can be enough to spread unauthorized messages. Teams should protect high-privilege accounts, strengthen identity recovery, control forwarding, and monitor for sending anomalies from legitimate accounts.

Fourth, treat health care, energy, and government as top-priority verticals. July’s pattern shows those sectors are still preferred targets for extortion and exfiltration. That calls for segmentation, tested backups, privileged access control, an inventory of exposed assets, and restoration tests that do not rely on optimistic assumptions.

Fifth, build data governance and traceability into security controls, not just compliance. The Mendoza debate and Chilean regulations show that the region is already demanding greater transparency around data, incidents, and responsibilities. Organizations without fine-grained traceability across the information lifecycle will be exposed both technically and legally.

Sixth, review third-party contracts and exposure. In several cases, from health care to utilities, the attack surface runs through vendors, exposed software, or external services. Supply chain risk remains one of the cheapest paths for attackers and one of the hardest to close without monitoring the full ecosystem.

Material limitations

This report was prepared exclusively from the material provided for July 2026 and from facts dated within the period window. Undated facts were left out of the indicators, although some may add qualitative context. Facts from earlier months that reached the file through coverage published in July were used only as a comparative frame and never as July volume.

One important nuance also applies to the indicators. When an indicator appears as zero, that means it did not appear in the material analyzed for this period, not that the event did not occur in the region. This is especially true for CVEs and for any category where the absence of a mention does not equal the absence of real activity. This month, critical CVEs were mentioned, so that number should be read as a signal present in the material, not as a complete universe of regional vulnerabilities.

Aggregated telemetry, such as phishing attempts, scans, or automated blocks, was excluded from the incident volume. If it is mentioned, it should be understood as an exposure measurement, not as a confirmed intrusion. Sponsored content, commercial press releases, or consumer publications that are not on the approved citation list were also not used as evidence of trend.

Finally, the report does not introduce external sources beyond the provided corpus, nor does it attribute incidents where the material offers only a leak site claim, a journalistic conjecture, or an assertion not verified by the source. When a fact did not allow a distinction between encryption, exfiltration, or a leak site mention, that ambiguity was preserved rather than forcing a classification.

Sources