CiberLATAMbywhalemate
Intelligence report

Latin America Cybersecurity Outlook, August 2026

August ended with regulation in focus, a spike in sanctions in Brazil, active ransomware in Argentina

Sep 1, 202628 min read
Latin America Cybersecurity Outlook, August 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are filled in automatically with the verified dated facts within the period. Each one states its basis and counting criterion, so the figures reconcile across modules. They are the recurring month-to-month reading, and the analysis that follows expands on the cases without repeating this summary.

Indicator window: 904 dated facts in August 2026 · 64 from earlier months (comparative frame, not monthly volume) · 25 without confirmed date (excluded from indicators) · 7 after the period (excluded). Facts from earlier months are used only as a comparative frame in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Monthly verified signal dashboard August 2026 · Latin America Top threat: Regulation (410 of 902 incidents). Coverage: 904 dated incidents in August 2026 · 64 of months an… VERIFIED INCIDENTS 902 period base: all counts measured from the bottom based on this total RANSOMWARE / EXTORTION 41 6 encrypted assets confirmed · 4 exfiltration unencrypted (simple extortion) UNCLASSIFIED INCIDENTS 48 breaches or outages without declared threat type FRAUD / PHISHING 85 documented fraud campaigns REGULATION 410 rules, rulings, or sanctions UNIQUE CVEs 2 CVE-2026-50751 / CVE-2026-73570
Monthly verified signal dashboard — Base: 902 verified dated incidents for Latin America.
MONTHLY FIXED MODULE Threat-axis distribution August 2026 · Latin America Each event is counted in only one axis, so the total is exactly 902. "Unclassified incidents" is the remainder. Regulation 410 Unclassified 306 Fraud 85 Incidents 48 Ransomware 41 Vulnerabilities 12
Threat-axis distribution — Each event is assigned to a single axis based on its classification; the total reconciles to the 902 events in the period.
FIXED MONTHLY MODULE Sector breakdown of signal August 2026 · Latin America Base: 902 incidents in the period · total 1128 because 192 incidents are classified in more than one sector. Other / no sector ident… 336 Public sector / OIV 295 Finance 238 Telecom 104 Technology 65 Retail / Consumer 40 Education 26 Healthcare 24
Sector breakdown of signal — Heuristic sector classification by victim sector. One incident may affect more than one sector, so the total may exceed the base.
FIXED MONTHLY MODULE Geographic Distribution of Coverage August 2026 · Latin America Each event is assigned to a single country or to regional coverage, so the total is exactly 902 of 902 events … Argentina 560 Brazil 304 Bolivia 38
Geographic Distribution of Coverage — Verified period events grouped by country or regional coverage; each event is counted once.

Monthly executive summary

August 2026 painted a regional picture dominated by regulation, with 410 verified events out of 902 and an operational signal that leaned more toward compliance than mass intrusion. The month was shaped by high-profile sanctions in Brazil, a new wave of ransomware campaigns focused on Argentina and Brazil, and a sustained front of digital fraud and phishing across the financial system.

The strongest reading of the period comes from Brazil. ANPD imposed a record fine on ByteDance for improper handling of teenagers' data and, at the same time, kept up an expanded enforcement agenda focused on major platforms, minors, security incidents, and the use of artificial intelligence. That combination not only increased regulatory volume, it also showed an authority already operating with a model of continuous enforcement rather than isolated cases.

On the incident side, the clearest signal came from Oldelval in Argentina, which reported a cyberattack on administrative systems without interrupting crude oil transport. The case was covered as ransomware or, at minimum, as an incident with a claim attributed to The Gentlemen, a group that continued expanding its global activity and also appeared in campaigns with victims in Argentina and Brazil. Added to that were claims against Flecha Bus, AMCA and Criba, reinforcing a pattern of extortion with a strong South American footprint.

The financial front continued to show intense pressure from fraud. Argentina reported roughly US$98 million in digital payment fraud in the first half of 2026, while local coverage kept recording scams involving vishing, phishing, identity theft and deepfake-enabled schemes. At the same time, Brazil amplified its own alarm with studies on deepfakes, AI-based impersonation, and the growing use of fake content in scams and deceptive campaigns.

The overall reading for the month is high risk for Latin America, although the nature of that risk changed noticeably. There was no single campaign with broad regional impact. Instead, three layers overlapped, stronger regulatory intervention, more sophisticated digital fraud, and persistent ransomware in large countries, with especially heavy exposure in financial services, health, transportation and critical infrastructure. The volume of critical CVEs mentioned was low, but that does not reduce the real pressure on exposed perimeters and applications.

Regional overview for the month

In August, the region saw a mix of tighter regulation, fraud cases moving into court, and opportunistic criminal activity, with Brazil, Argentina, Mexico, and Chile standing out as the most visible hubs. The risk picture for Latin America is high, not because of a single catastrophic event, but because of the accumulation of verifiable developments affecting regulation, payments, privacy, minors, critical infrastructure, and digital extortion.

The defining feature was regulation. With 410 documented regulatory moves, the month was shaped by public consultations, bill drafts, sanctions, authority rulings, and prudential updates. Brazil accounted for much of that activity through the ANPD, while Mexico moved pieces at Banxico and CNBV, Argentina kept adjusting the BCRA and several subnational jurisdictions, such as Zacatecas and Mexico City, pushed reforms on data, minors, and the digital environment.

That regulatory intensity should not be read as administrative noise. In several countries, the rules responded to concrete market or risk events, such as fraud in digital payments, exposure of minors' data, the need to strengthen authentication, or efforts to close supervision gaps around fintech, wallets, and platforms. The regional pattern is clear, the state arrives late, but it arrives with more tools and a greater appetite for enforcement.

At the same time, digital fraud remained the most cross-cutting threat in the daily lives of users and financial institutions. Argentina combined cyber scams through WhatsApp, fake websites, vishing, deepfakes, and a case involving fraud through tampered POS terminals. Brazil saw a jump in the use of deepfakes in fraud and a financial industry forced to deal with mass identity validation attempts. Mexico, although with less concrete incident evidence in this material, advanced in operating rules and discussions about biometrics, interoperability, and risk control.

Ransomware remained active, but with a more concentrated footprint than in the previous month. Confirmed cases were fewer than in July, though they continued to affect critical infrastructure, transportation, health care, and professional services. Argentina reappeared on the map with Oldelval, Criba, Flecha Bus, and AMCA. Brazil added victims and campaigns, including the preliminary signal on Mobilemed, while threat-intelligence aggregators kept showing groups such as The Gentlemen, Qilin, DragonForce, Kazu, and BlackWater in constant rotation.

TIMELINE Verified events for the period 1/8 Theattributionto The 1/8 Defonline notedthat the 1/8 An analyst fromsecurity 2/8 Local media from 2/8 Página/12reported that in 2/8 The RioTimesreports
Verified timeline of events, August 2026 — Confirmed milestones within August 2026. Events from earlier months are excluded from the timeline and used only as a comparative frame.

Period indicators

The table below summarizes the month’s quantitative base and shows a clear shift in composition from July, with less ransomware, less documented fraud, and much more regulation. The calculation base and time window are reproduced exactly as provided, because they frame how the report should be read and are not an editorial inference.

Indicator August 2026 Previous month Change
Verified events in the period (base for all indicators) 902 854 +48
Time window for the indicators 904 events dated in August 2026 · 64 from previous months (comparative frame, not month volume) · 25 with unconfirmed date (excluded from indicators) · 7 after the period (excluded)
Unclassified incidents (breaches or outages) 48 85 -37
Cases with ransomware or extortion as the primary focus 41 126 -85
Confirmed asset encryption 6
Exfiltration without encryption (simple extortion) 4
Leak site mention only 5
Classification could not be determined from the material 26
Documented fraud or phishing cases 85 101 -16
Documented regulatory actions 410 261 +149
Critical CVEs mentioned 2 22 -20
Sectors with at least one documented event 8 8 unchanged
Dominant threat of the month Regulation (410 of 902 events) Regulation (261 of 854 events) more pronounced
Events with direct source confirmation 96%
Aggregated telemetry figures excluded from volume 2 (aggregated attempts or blocks, not incidents with confirmed impact)

The base is not sector-exclusive, so a single event can involve regulation, privacy, and payments at the same time. For that reason, the indicator table should be read as the dominant signal, not as a sum of separate compartments. That distinction matters this month, because the regulatory jump coincides with a decline in ransomware and a persistent fraud pattern that did not disappear, only changed form.

Relevant incidents

The most useful incidents for understanding August were not necessarily the largest by volume, but the ones that combined operational impact, sensitive sectors, and a clear documentary trail. The strongest case was Oldelval, alongside several extortion and leak campaigns in Argentina and Brazil, plus the Latam data incident in Brazil.

Oldelval and the attack on Argentina's oil infrastructure

Oldelval reported a cyberattack that affected its administrative systems and made it clear that crude transport continued without interruption. The company disclosed the incident to the CNV as a material event, and media coverage placed it in the context of critical infrastructure, operational expansion, and a possible claim by The Gentlemen.

The episode matters for two reasons. First, it confirms that pressure on energy assets in Latin America is not limited to data exfiltration or full unavailability, but also reaches the administrative systems that support operations and business management. Second, it shows a recurring pattern, public attribution on leak sites or by groups does not line up with an institutional confirmation of authorship, method, or scope.

From an operational perspective, the case also shows how the energy sector depends on real separation between administrative networks, operational infrastructure, and support systems. The recovered coverage consistently said SCADA and transport were not disrupted, but that does not remove the risk of lateral movement, credential manipulation, or reputational pressure. The risk signal centers on exposure at the corporate layer, not only at the industrial level.

Latam Pass and the notice to Brazil's ANPD

Latam acknowledged a security incident that exposed personal data from a limited portion of members in its Latam Pass loyalty program and notified both the ANPD and potentially affected customers. The company said it took containment and cybersecurity measures, in line with Brazil's compliance framework.

The value of the case is not the exact size of the affected set, which was not detailed in the material, but the response sequence. Early regulatory notification and user communication were central to the reputational impact. That places the incident in a different category from a silent leak, because in Brazil the duty to report and document is already part of incident handling.

For the aviation and travel sector, the sensitive point is the quality of loyalty data. Programs like Latam Pass hold information that can combine identification, contact details, travel preferences, and behavior tracking. That density makes even a partial exposure relevant, especially when it feeds later phishing or identity fraud campaigns.

Flecha Bus and extortion in transportation

Flecha Bus appeared in ransomware monitoring indexes as a victim claimed by CoinbaseCartel, with public signaling on a leak site and no institutional confirmation of the amount compromised. Coverage linked the case to the transportation and logistics sector in Argentina, which makes it especially relevant in a month when mobility and supply chains remained under pressure.

The analytical value of the case is twofold. On one hand, it reinforces that ground transportation remains an attractive target for extortion operators, both because of its dependence on uninterrupted operations and the reputational sensitivity of any disruption. On the other hand, the lack of public validation prevents the impact from being overstated, what is confirmed is the claim and the existence of a leak described by the group, not the final scale of the damage.

The operational signal for transportation companies is not new, but it is clearer. Ransomware groups are no longer focused only on encrypting visible infrastructure. In several cases, public exposure and the threat of publication are enough to turn an operating brand into a continuity and customer-service problem.

AMCA, Criba, and the persistence of extortion in Argentina

AMCA, an Argentine mutual association, and Criba, a company with a presence in Argentina, appeared in posts by BLACKWATER and DragonForce respectively. In both cases, the material reviewed makes it clear that what was verified is the leak-site publication or the victim's name appearing in the campaign, while the exact type of damage cannot always be determined.

That distinction is central. In August there were several cases where the source does not allow confirmation of whether there was asset encryption, exfiltration without encryption, or only public mention of the victim. Editorial discipline matters because the difference among those three scenarios completely changes the technical and legal reading. Not every leak site post equals an incident with confirmed operational loss.

Even so, the set of claims shows that Argentina remained one of the most visible countries for extortion groups. The mix of mutual associations, transportation, and manufacturing suggests heterogeneous targets and tactical opportunity rather than a single prioritized vertical. That points to a defense ecosystem that is still uneven, with some mature sectors and others more exposed.

Mobilemed and pressure on digital health in Brazil

Mobilemed was reported as a target associated with the Kazu group, with material pointing to a cloud PACS platform used for radiology and medical imaging in Brazil. The available coverage was cautious, it describes the claim, mentions exfiltration and ransom figures posted by the leak site, but says there was no independent confirmation of the technical scope or the full operational impact.

The case deserves attention because it broadens the health map to digitized clinical services, not just traditional hospitals. A cloud PACS concentrates images, clinical workflows, and dependence on remote access. Exposure of that kind of platform can disrupt diagnostic continuity even if there is no public evidence of mass encryption.

The risk reading in health changes when the target is not an isolated clinic but a provider of infrastructure for multiple care organizations. That expands the potential blast radius. The Mobilemed case, even if preliminary, fits a regional trend that combines extortion, cloud services, and shared platforms in sensitive sectors.

Active threats and campaigns

Criminal activity in the month showed fewer confirmed ransomware cases than in July, but it kept the same cross-border campaign pattern, public pressure through leak sites, and strain on critical sectors. On the fraud side, perceived intensity remained high and was increasingly driven by social engineering and deepfakes.

Ransomware and extortion

The Gentlemen was again the most visible actor in regional reporting, with activity in global campaigns and victims in Argentina and Brazil. Its expansion does not rely on encryption alone, because the group uses multi-extortion, public pressure, and a mix of intrusion through exposed perimeters, tool reuse, and cross-targeting.

The most useful August data point is that, of the 41 cases where ransomware or extortion was the primary focus, only 6 had confirmed asset encryption. In 4, there was exfiltration without encryption, in 5 the evidence was limited to a leak site mention, and in 26 the material did not allow a clear determination of the exact method. That breakdown suggests the extortion ecosystem is more fragmented than the generic label "ransomware" implies.

Among the most visible campaigns were those attributed to The Gentlemen, DragonForce, CoinbaseCartel, BLACKWATER and Kazu. DragonForce posted victims in Argentina and Brazil, CoinbaseCartel listed Flecha Bus, BLACKWATER appeared with AMCA, and The Gentlemen kept adding cases in Argentina, including Criba and the claim against Oldelval. The same country appearing across several different families does not point to a single flaw, but to a broad and uneven attack surface.

Fraud and phishing

Fraud and phishing remained the most routine threat and, at the same time, the one most adapted to product changes and regulation. Argentina showed a clear shift from card cloning to fake pages, impersonation, vishing and WhatsApp-based attacks, while Brazil strongly brought deepfakes and AI-powered identity cloning into focus.

The figure of 85 documented cases does not capture the full phenomenon. August reporting shows the opposite, a fraud landscape shifting toward cheaper ways to scale and methods that are harder for end users to identify. In several countries, facial verification, biometrics and authentication flows became part of the problem rather than the solution, because attackers learned to imitate or work around them.

Pressure on the financial system was also visible in references to digital payment fraud, investigations into biometric controls and complaints against banks and fintechs. The signal is not only that fraud is growing, but that it is becoming multichannel and combining emotional manipulation, automation, templates based on well-known brands and opportunistic use of official or semi-official channels.

APT and hacktivism

The only clearly attributable APT signal in the material was the exploitation of CVE-2026-73570 by groups linked to Russia, with campaigns against government agencies, universities and state institutions in Brazil and Argentina. That reference was not accompanied by a large volume of regional cases, but it carried high strategic value because of the target profile.

August did not show a large block of hacktivism with confirmed operational impact comparable to ransomware or fraud. The APT signal instead serves as a reminder that government, education and state infrastructure perimeters remain exposed to geopolitically motivated or espionage-driven campaigns, and that a critical vulnerability can open a regional window even if the rest of the month is dominated by another type of incident.

The low number of critical CVEs mentioned should not be read as reassurance. The material recorded only two, which means that in this sample the focus was on regulation and fraud rather than public exploitation of technical flaws. That does not mean there were no exploited vulnerabilities in the region.

Critical vulnerabilities

Few critical CVEs were recorded in the material reviewed for August, and that marks a shift from July. The right reading is not that the region had no technical exposure, but that this month’s corpus focused elsewhere, especially on regulatory enforcement and extortion and fraud campaigns.

CVE Software Exploitation Source
CVE-2026-73570 Zimbra Collaboration Suite Exploited by Russia-linked APT groups against government agencies, universities, and state institutions in Brazil and Argentina SCWorld
CVE-2026-50751 Not specified in the source Cited as the most likely primary vector in The Gentlemen campaign Security Arsenal

The evidence of technical exploitation this month was limited, but relevant because of the type of environment exposed. In Zimbra, the targets are state and academic entities in the region. In The Gentlemen, the focus is on exposed perimeters such as VPNs and firewalls, rather than on a single platform. Both signals point to a hybrid attack surface, public vulnerability paired with poor operational exposure.

Regulation and compliance

Regulation was the dominant threat of the month because it stopped being a background factor and began shaping how the market responded. The regulatory bloc saw action on privacy, platforms, payments, biometrics, AI, child protection, transparency, and financial oversight across several countries in the region.

Brazil was the most intense case. ANPD fined ByteDance for improper handling of adolescent data and reinforced a large-scale enforcement strategy, with cases against major platforms, guidance on security incidents, transparency rules for minors, and regulatory debate over deepfakes and synthetic content. The message is clear: Brazil's authority is no longer acting only on isolated violations, but on business patterns and platform design.

In Argentina, the BCRA continued expanding rules for payment methods, transfers, installment debits, and oversight requirements. The new Cobro con Transferencia mechanism, the update to clearinghouse rules, and the discussion on incident reporting in fintech are consolidating a payments ecosystem that is increasingly traceable and more demanding. There is no single cybersecurity law, but there is a network of rules that effectively covers much of the field.

Mexico moved on two fronts. On one hand, Banxico opened public consultations on payment networks and clearinghouses, with a focus on efficiency, interoperability, and operational security. On the other, the debate over the Federal Cybersecurity Law remains unresolved, leaving the country with a fragmented architecture where compliance depends more on circulars, sector-specific rules, and prudential regulation than on a single framework.

Chile, for its part, continued debating the delay of the Personal Data Protection Law. The issue is not minor, because a possible postponement of the effective date would affect the credibility of the digital rights agenda and extend uncertainty for companies that are already preparing for the future agency and a stricter compliance regime. The debate is no longer about whether regulation will arrive, but when it will and how strict it will be in practice.

Paraguay and Colombia present two different problems. Paraguay already has a data protection law in force, but public debate still revolves around draft bills and the lack of more developed cybersecurity rules. Colombia, according to the month's analyses, still has no comprehensive cybersecurity law and relies on scattered rules, which fragments digital defense and complicates the assignment of responsibilities. That fragmentation was underscored in local coverage.

Countries most affected in Latin America

The month’s geographic spread was clearly tilted toward Brazil and Argentina, with Chile, Mexico, Colombia, Paraguay and Bolivia standing out as countries of regulatory relevance or isolated signals. Peru did not provide enough material for a standalone reading in this corpus, and the United States appears only as an incidental reference in some comparative analyses.

Argentina

Argentina showed the most visible mix of ransomware, fraud and secondary regulatory pressure. Oldelval dominated the critical infrastructure conversation, while Flecha Bus, AMCA and Criba kept the country present in extortion panels. At the same time, bank fraud continued shifting toward WhatsApp, phishing, vishing and deepfakes, with signs of greater judicial action against banks for security or response failures.

The sector-level picture in Argentina shows three sensitive areas: energy, transportation and financial services. Energy was exposed through Oldelval and the critical infrastructure discussion. Transportation came up with Flecha Bus and La Sevillanita. The financial system remained under pressure from scams, court-ordered refunds, digital fraud and new BCRA rules. The country did not have the highest number of total events, but it did have the widest range of fronts under strain.

Brazil

Brazil was the month’s epicenter by regulatory volume and by the density of privacy and fraud incidents. The ANPD issued decisions on TikTok, Discord, proceedings against major tech companies and guidelines for minors, AI and deepfakes. At the same time, Latam reported a security issue in Latam Pass, and Mobilemed emerged as a possible victim in digital health.

On the fraud front, Brazil showed a clear escalation in the use of generative AI for impersonation, cloning people and creating deepfakes in deceptive campaigns. This trend is not just technical, it is behavioral. End users are facing more convincing forgeries, with direct consequences for identity verification, onboarding and stronger authentication. The month left Brazil as the region’s main regulatory laboratory and the main gauge of synthetic fraud.

Chile

Chile was dominated by debate over the postponement of the Personal Data Protection Law and by the passage in general of the anti deepfake bill. The country’s agenda was shaped by two different timelines, one tied to the entry into force of already approved rules and another tied to delays in setting up the new data protection agency.

The clearest signal is that Chile has entered the political implementation phase of its data regime. The concern is not theoretical. If full enforcement is delayed, the business ecosystem gains some time, but the institutional closure required for the law to operate is also pushed back. The country therefore stands out as one of the Cono Sur’s most relevant regulatory focal points, although it had fewer operational incidents than Argentina or Brazil.

Mexico

Mexico combined financial reform, Banxico public consultations and a federal cybersecurity law that still has not been approved. The debate centered on payments, cards, clearing houses, incident reporting and prudential oversight of Sofomes and fintechs. The country still lacks a single framework, but sector-specific regulation is advancing with considerable intensity.

The Mexican problem is not a lack of activity, but fragmentation. The CNBV, Banxico, the DOF and other agencies are pushing pieces that affect payment and data security, but the legal architecture remains spread across multiple instruments. That forces companies to read risk horizontally. Financial compliance, privacy, authentication, continuity and incident reporting do not sit in separate silos.

Colombia

Colombia stood out less for specific incidents and more for its structural diagnosis. Local media reported that the country still lacks a comprehensive cybersecurity law and that its framework relies on scattered rules, a situation that limits defensive cohesion against growing threats. In a regional context marked by synthetic fraud and pressure on identity, that weakness is more visible than in previous months.

Paraguay

Paraguay showed a clear signal in data protection, with Law No. 7.593/2025 already part of public debate, but without a consolidated cybersecurity bill identified in the Senate based on the information retrieved. The country combines a more modern privacy base with a still fragmented discussion about institutional cybersecurity.

Bolivia

Bolivia showed an institutional agenda focused on 2FA, strengthening the CSIRT and digital protection. At the same time, signs emerged of a possible breach and of opaque political digital activity, such as the so-called mini bot farm linked to Fernando Cerimedo. August’s material suggests an ecosystem that is more active in building capacity than in producing confirmed incidents, although exposure is growing in public and financial services.

The comparison with the previous month shows relative improvement on some fronts and a worrying acceleration on others. Unclassified incidents fell, ransomware or extortion cases as the primary focus dropped sharply, and documented fraud or phishing also declined. But the month shifted much more toward regulation, and that change is not cosmetic.

Compared with July, the drop in ransomware from 126 to 41 cases should be read with caution. It does not mean the actor lost capability, but rather that August’s corpus included fewer events of that type and more regulatory material, along with campaigns where classification could not be determined. The key point is not only volume, but the persistence of groups such as The Gentlemen, DragonForce, Qilin, BLACKWATER and Kazu across different countries in the region.

The regulatory jump from 261 to 410 events is the month’s most important change. Brazil drove most of it, but Argentina, Mexico, Chile and Paraguay also contributed. The underlying signal is that states are closing the gap between observed risk and applicable rules, especially in payments, children’s data, digital platforms and incident reporting.

The decline in critical CVEs mentioned, from 22 to 2, is also significant, although it should not be overstated. In August, the available material focused on public policy, enforcement and fraud more than technical vulnerability exploitation. That does not mean the technical attack surface shrank, only that it was less visible in the corpus analyzed.

The signal to watch for September is the convergence between regulation and fraud. When authorities tighten controls, authentication, traceability and reporting, more sophisticated evasion attempts often follow, especially in banking, fintech and platforms with large user bases. The month makes it clear that the next pressure will come not only from malware, but from social engineering adapted to new requirements.

Security team recommendations

Security teams across the region should treat August as a priority signal, not a calendar footnote. The first step is to review which parts of the business are exposed to regulation that is already in force or still in transition, because several of the month’s cases ended in sanctions, formal inquiries, or new reporting obligations.

In financial firms, fintechs, and payment providers, the priority should be tighter authentication, stronger identity monitoring, and better incident traceability. This month’s reporting showed vishing, phishing, deepfakes, impersonation of authority figures, and manipulation of onboarding flows. That calls for a mix of technical controls, out-of-band verification, and faster rollback and reporting procedures.

In energy, transportation, health care, and shared services, the focus has to be on real segmentation of environments and readiness to respond to extortion. Oldelval and Mobilemed offer a similar lesson, even if the incidents were different. An intrusion into administrative systems may not stop operations, but it can still disrupt continuity, strain the relationship with regulators, and widen the attacker’s leverage.

It is also worth reviewing perimeter exposure and remote services. Activity attributed to The Gentlemen and other groups again points to abuse of VPNs, firewalls, and exposed access points. That requires rapid patching, well-implemented MFA, an inventory of external access, rotation of privileged credentials, and a serious exercise in detecting lateral movement.

For legal and compliance teams, the message is not to wait for a single law before acting. In Brazil, Argentina, Mexico, and Chile, there is already enough regulatory material to justify programs for privacy, incidents, retention, vendor governance, and risk assessment. Regulatory fragmentation is not an excuse. It is the normal condition of the Latin American market.

Finally, response playbooks should be ready for cases where the public evidence is incomplete. Several incidents this month surfaced on leak sites or as preliminary claims. That means a team may need to respond before confirming the full intrusion. In that scenario, the most useful steps are not guessing attribution, but cutting off access, preserving evidence, reviewing credentials, and closing the door on a second wave of extortion.

Frequently Asked Questions

Why was August dominated by regulation, not ransomware?

Because the monthly base concentrated 410 regulatory moves versus 41 ransomware cases or extortion as the primary focus, and there were also 85 fraud or phishing incidents. Regulation absorbed more than half of the signal because Brazil, Mexico, Argentina and Chile moved rules, sanctions and consultations that directly affect security and data.

Which countries showed the strongest combined pressure from incidents and compliance?

Brazil and Argentina. Brazil combined an ANPD record fine against ByteDance, expanded oversight and signs of synthetic fraud. Argentina added Oldelval, Flecha Bus, AMCA, Criba and a strong front of financial scams. Chile stood out more for regulation, and Mexico for prudential changes and Banxico consultations.

How should the ransomware cases from the month be read?

With caution and by separating three layers, confirmed encryption, exfiltration without encryption, and a mention only on a leak site. In August, of the 41 cases with ransomware or extortion as the primary focus, only 6 had confirmed encryption, 4 were simple exfiltration, 5 stayed on leak sites and 26 could not be classified precisely.

What changed in digital fraud compared with the previous month?

The documented volume fell, but the tactics became more sophisticated. The material shows less card cloning and more phishing, fake websites, vishing, deepfakes and identity theft, especially in Argentina and Brazil. The combination with biometrics and facial validation raised the risk of bypassing controls.

What do the two critical vulnerabilities mentioned imply?

They show that technical exposure did not disappear, even though the month was dominated by regulation. CVE-2026-73570 affected Zimbra and was exploited against government and academic targets in Brazil and Argentina, while CVE-2026-50751 was cited as a likely vector in The Gentlemen campaign. The low number does not mean there is no risk.

Material limitations

This report was built exclusively from the material provided for August 2026 and the comparative frame from earlier months included in the file. There was no internet access, and no sources outside the authorized list were used. Facts without confirmed dates were left out of the indicators and used only when they helped provide context.

The stated time window for the period included 904 dated incidents in August 2026, 64 from earlier months as a comparative frame, 25 without confirmed dates excluded from the indicators, and 7 after the period, also excluded. The monthly indicators are reproduced exactly as provided and were not independently recalculated.

An indicator of 0, especially the critical CVEs indicator, means none were recorded in the material analyzed for this month, not that no vulnerabilities were exploited in the region. The same applies to any missing sector or country in a specific section. The absence of evidence in this corpus does not mean the phenomenon did not exist.

Aggregated telemetry, automated attempts or blocks, and promotional content were also excluded as trend evidence, along with press releases and advertorials when they were the only basis for the claim. Figures for fraud attempts, blocks, or scans were mentioned only when the material allowed them to be attributed to a vendor and made clear that they are not incidents with confirmed impact.

July 2026 vs August 2026Verified indicator baseline for the period. Does not include telemetry.Ransomware12641RansomwareFraud10185FraudRegulation261410Regulation
Verified signal comparison, July vs August — Changes in composition between the previous month and August 2026 for the most sensitive indicators.

Technical appendix: indicators of compromise and TTPs

The Gentlemen and the observed attack chain

The campaign attributed to The Gentlemen showed an intrusion chain with initial access through Internet-exposed firewall interfaces, reconnaissance using Advanced IP Scanner, use of PowerRun.exe for privilege escalation, and ThrottleBlood.sys for defense evasion. The material also mentioned abuse of VPN gateways, firewalls, and unpatched remote access tools.

Explicit IOCs and artifacts in the material

The evidence laid out in the corpus did not provide verified hashes, IP addresses, or domains to add as a clean technical list. It did provide names of tools, drivers, and vectors: Advanced IP Scanner, PowerRun.exe, ThrottleBlood.sys, exposed FortiGate interfaces, exposed VPN gateways, and virtualized systems such as Linux, ESXi, and Hyper-V, along with Go backdoors and curve25519 and xchacha20 encryption in The Gentlemen's technical description.

Technical reading recommendation

For a blue team, the value of these signals is not in attribution, but in the pattern. If an organization exposes perimeter services, uses remote administration, and has weak segmentation between the administrative network and critical systems, the The Gentlemen case serves as a guide for defensive prioritization. The material does not include enough IOCs for a blocklist, but it does provide clear TTPs to strengthen detection and hardening.

Sources