CiberLATAMbywhalemate
Intelligence report

Latin America Cybersecurity Landscape, September 2026

Regulation, digital fraud, and ransomware shaped September in Latin America, with Argentina and Brazil leading the signal.

Oct 1, 202628 min read
Latin America Cybersecurity Landscape, September 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are completed automatically using verified dated facts within the period. Each one states its basis and counting criterion, so the figures reconcile across modules. They are the recurring monthly readout, and the analysis that follows develops the cases without repeating this summary.

Indicator window: 856 dated facts in September 2026 · 132 from prior months (comparative frame, not current-month volume) · 4 without confirmed date (excluded from indicators) · 8 after the period (excluded). Facts from prior months are used only as a comparative frame in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Verified Signal Monthly Dashboard September 2026 · Latin America Top threat: Regulation (322 of 851 events). Coverage: 856 dated events in September 2026 · 132 from the mon… VERIFIED EVENTS 851 period base: all counts measured below from this total RANSOMWARE / EXTORTION 40 4 asset encryption confirmed · 2 exfiltration unencrypted (simple extortion) UNCLASSIFIED INCIDENTS 61 breaches or outages without declared threat type FRAUD / PHISHING 190 documented fraud campaigns REGULATION 322 rules, resolutions, or sanctions UNIQUE CVEs 2 CVE-2026-76461 / CVE-2026-84869
Verified Signal Monthly Dashboard — Base: 851 verified dated events for Latin America.
MONTHLY FIXED MODULE Threat Axis Distribution September 2026 · Latin America Each event counts in only one axis, so the total is exactly 851. "Unclassified incidents" is the remainder. Regulation 322 Unclassified 227 Fraud 190 Incidents 61 Ransomware 40 Vulnerabilities 11
Threat Axis Distribution — Each event is assigned to one axis based on its classification; the total reconciles with the 851 events in the period.
MONTHLY FIXED MODULE Sectoral Signal Distribution September 2026 · Latin America Base: 851 incidents in the period · total 1198 because 250 incidents are classified in more than one sector. Public sector / OIV 331 Finance 294 Other / sector not identi… 245 Telecom 130 Technology 103 Retail / Consumer 64 Healthcare 18 Energy 13
Sectoral Signal Distribution — Heuristic classification by victim sector. One incident may affect more than one sector, so the total may exceed the base.
MONTHLY FIXED MODULE Geographic Distribution of Signal September 2026 · Latin America Each event is assigned to a single country or to regional coverage, so the total is exactly 851 of 851 events … Argentina 658 Brazil 139 Bolivia 54
Geographic Distribution of Signal — Verified period events grouped by country or regional coverage; each event is counted once.

Executive monthly summary

September 2026 left Latin America with a picture shaped by regulation, digital fraud, and a series of incidents with uneven impact across countries and sectors. Of 851 verified events during the period, the leading threat was regulatory, with 322 documented moves, followed by 190 fraud or phishing cases and 40 ransomware or extortion cases as the primary focus. The month also recorded 61 uncategorized incidents, suggesting meaningful activity, but in several cases there was not enough material to determine whether there was encryption, exfiltration, or only a mention on leak sites.

The regional picture does not show a single wave of mass intrusions, but rather a mix of regulatory pressure, more sophisticated financial fraud, extortion campaigns posted on leak sites, and state resilience exercises. Brazil concentrated the most intense regulatory agenda, with the ANPD acting in both enforcement and advisory mode, along with a confirmed incident at CAPES. Argentina, meanwhile, combined a set of BCRA reforms on fraud with the submission to Congress of a national security bill that includes cybersecurity and critical infrastructure, while phishing, deepfakes, and ransomware claims multiplied.

TIMELINE Verified events in the period 1/9 TheCommunication“A” 8471 1/9 The coveragereviewedindicates 1/9 In Mexico, the**resolution 1/9 The officialtext of the 1/9 TheCommunication"A"8471 1/9 TheCommissionNationalBanking

Timeline of verified events, September 2026 — Milestones with confirmed dates within September 2026. Events from earlier months are excluded from the timeline and used only as comparison context.

On the incident front, the clearest and most verifiable case was K3G Solutions Brazil, attributed to Panzer, with an estimated 300 GB exfiltrated according to specialized trackers, along with several claims involving Argentine and Brazilian entities where independent confirmation was not enough to close the question of impact, scope, or the authenticity of the material. At the same time, the health sector was hit by the posting of Grupo Hospifar on Titan's leak site and by the Sanatorio Modelo de Caseros case, although in the latter most sources agree it was a claim that had not been publicly corroborated by the end of the period.

Digital fraud shifted in scale and technique. Argentina logged repeated BCRA warnings about fake investment scams and the use of risk profiles for transfers, while regional media detailed voice deepfakes, audiovisual phishing, and more convincing social engineering scripts. In Brazil, the combination of ANPD decisions, the TikTok case, and the CAPES investigation reinforced a compliance agenda that no longer stops at privacy policies, but extends to enforcement, reporting deadlines, preventive measures, and concrete sanctions.

Viewed through a risk lens, the region closed the month at a high level. Not because one mega-incident dominated, but because of the density of verified events, the sector breadth, the prominence of finance and government, and the convergence of fraud, data protection, critical infrastructure, and the use of AI as a multiplier of deception. The pressure came not only from external attackers, but also from new regulatory frameworks and the need to prove compliance with documentary and operational evidence.

Regional snapshot for the month

September’s regional picture shows Latin American cybersecurity becoming more tightly bound to financial regulation, data protection, and the defense of essential services. The number of verified incidents was high, and severity was high too, although spread across different fronts. The region did not show a single dominant technical intrusion vector, but several overlapping layers of risk: banking fraud, ransomware campaigns, APT activity targeting governments, tighter regulation, and preparedness exercises for attacks on critical infrastructure.

Brazil remained the clearest barometer. ANPD moved ahead with a public hearing, a public consultation, and a new enforcement practice, while the TikTok case kept sanctions and child protection in focus. CAPES also confirmed an incident on the Meus Dados Platform involving unauthorized access to personal data and notice to authorities. At the same time, CTIR Gov issued an alert over a critical vulnerability in Secure Email Gateway, with CVE-2026-76461 mentioned in the material, and the Guardião Cibernético 8.0 exercise once again showed the state’s priority on operational continuity for essential sectors.

Argentina combined the most visible side of public policy with the noisiest fraud front. The BCRA tightened controls on transfers, introduced risk profiles, and made fraud management a central part of the financial agenda. At the same time, public debate filled with AI scams, voice deepfakes, bank impersonation, and court cases tied to digital fraud. The submission of a national security bill that includes cybersecurity and critical infrastructure adds another layer. The state is starting to treat digital protection as part of public security architecture, not just as technical hygiene.

The risk map was not limited to those two countries. Bolivia recorded attacks on the National Chamber of Industries and pushed a response-strengthening agenda through Bolivia Cibersegura 2026. Peru closed compliance deadlines on personal data matters. Paraguay kept moving on critical infrastructure protection. Ecuador debated a partial objection in its Assembly over its cybersecurity bill. Mexico, although with fewer confirmed incidents in the month’s material, maintained a regulatory agenda on payments, authentication, and Banxico’s public consultation.

The month’s qualitative risk is high for three reasons. First, the volume and diversity of verified events. Second, because several incidents and campaigns affected sectors with high systemic sensitivity, including government, health, and finance. Third, because the material shows a convergence between attack, fraud, and regulation, with organizations forced to prove detection, response, traceability, and notification capabilities under increasingly strict deadlines.

Period indicators

Indicator September 2026 Previous month Change
Verified events during the period 851 902 -51
Unclassified incidents (breaches or disruptions) 61 48 +13
Cases with ransomware or extortion as the primary focus 40 41 -1
Documented fraud or phishing cases 190 85 +105
Documented regulatory moves 322 410 -88
Critical CVEs mentioned 2 2 unchanged
Sectors with at least one documented event 8 8 unchanged
Dominant threat of the month Regulation (322 of 851 events) Regulation (410 of 902 events) volume changed, same priority
Events with direct source confirmation 94% not provided n/a
Aggregate telemetry figures excluded from volume 5 not provided n/a
Time window for the indicators 856 events dated September 2026, 132 from prior months as comparative context, 4 without confirmed date excluded, 8 later events excluded same n/a
Base for all indicators 851 verified events during the period 902 -51

Relevant incidents

CAPES and the Meus Dados Platform incident

CAPES confirmed a security incident in the Meus Dados Platform that allowed unauthorized access to personal data available in the system. The agency reported the case to the relevant authorities, including the Federal Police and Brazil's ANPD, and said it had not identified any changes to the stored data. The case matters because it shows an intrusion into a sensitive state platform, although the technical scope remains limited in the public information available.

The operational reading is twofold. On one hand, the incident confirms that personal data management environments in Brazil remain targets for unauthorized access. On the other, it shows that the notification threshold no longer depends only on completed harm, but on unauthorized access to data that could compromise the security or privacy of data subjects. In a month when the ANPD stepped up enforcement and regulatory debate, CAPES served as a practical example of the need for traceability and rapid response.

K3G Solutions Brazil and the Panzer campaign

K3G Solutions Brazil was one of the clearest signs of ransomware with possible exfiltration in the region. Ransomware.live, Breach House, Dexpose.io, Kalir, and other tracking sources recorded the victim attributed to Panzer with discovery and attack dates of September 18, 2026, and the material indicates an estimated 300 GB exfiltration. The company was described as a Brazilian telecom and IT consultancy based in Manaus, with network services, ISP support, monitoring, and colocation.

Here the difference from other cases this month is significant. The material is not limited to a leak site mention, multiple trackers reinforce the attribution and provide consistent metadata. Even so, independent confirmation of the company's operational impact does not appear in the corpus. The risk to the ecosystem is high because of the sector profile and the overlap between telecom, IT, and potentially sensitive infrastructure.

Grupo Hospifar S.R.L. and Titan

Grupo Hospifar S.R.L., an Argentine health provider, appeared on Titan's leak site on September 22. APJ One included it in its daily roundup, and the available material agrees that this was a leak site publication, with no public confirmation from the affected entity. Kalir added context, but without enough public forensic evidence to assert encryption, exfiltration, or confirmed disruption.

The key point is the exposure of the health sector as a persistent target. Unlike K3G, the material here does not allow a precise classification of the impact. For that reason, the correct reading is a claim recorded by extortion monitors, useful for early warning, but insufficient to treat it as a confirmed incident with verified operational consequences.

Sanatorio Modelo de Caseros and the dispute between claim and confirmation

Sanatorio Modelo de Caseros was one of the most discussed cases of the month, with claims attributed to Qilin and multiple breach monitors following it. Some sources described encryption of critical files and exfiltration, while others, such as RecentBreaches, explicitly classified it as an uncorroborated claim. Ransomlook, HookPhish, Darkfield, and other trackers say there was a leak site publication, but public confirmation from the institution does not appear in the material.

This case is a good example of the difference between visibility and verification. For operational analysis, the most prudent source is the one that labels the case an "unconfirmed breach claim", because it avoids assuming real impact where there is only a gang publication. Even so, the repeated tracking of the same victim means the case still needs follow up, especially because it involves a healthcare provider, a sector where any leak can affect clinical data and institutional reputation.

Judicial Branch of the Province of Jujuy and Emperador

The Judicial Branch of the Province of Jujuy appeared linked to the Emperador group, with several monitoring sources flagging a data leak and exfiltration of judicial infrastructure, including administrative credentials and court databases. Other sources, however, classified it as an uncorroborated claim. The final result is still contested, although there are enough signs not to dismiss it outright.

The most important point here is the typology. The material does allow us to say that the claim exists in the leak site ecosystem and that the target belongs to the government and defense sector. What it does not allow, at least without independent confirmation, is to close the level of intrusion. For that reason, the correct reading is a "extortion claim with material suggestive of exfiltration, still without official confirmation".

Diarco and the Incransom claim

Diarco was flagged by Incransom in tracking sources, but without verifiable details on encryption, exfiltration, ransom demand, or operational impact. ThreatCluster even marked the publication as unverified. The relevance of the case lies less in confirmed harm and more in the accumulation of claims against Argentine organizations on extortion platforms.

This kind of signal matters for threat intelligence, but it should not be confused with a confirmed incident. In editorial terms, it belongs in the reputational exposure and leak site monitoring radar, not in the same category as a corroborated breach. The distinction is key to avoiding artificial inflation of the real volume of intrusions.

Argentine government, national security plan, and cyber defense

The Argentine executive branch sent Congress a 133-article bill that creates a National Security System and adds cybersecurity and critical public and private infrastructure protection functions. Coverage also indicates that the bill entered the Chamber of Deputies on September 17, began committee debate on September 30, and will continue its legislative path in October.

The cyber component is not incidental. The definition of critical infrastructure covers facilities, networks, systems, services, and assets whose disruption could affect security, defense, health, the economy, essential services, or the functioning of the state. In practice, that brings legislative language closer to a broader protection model, where cybersecurity, operational continuity, and national security begin to overlap in a single framework.

Cyber.ar 26 and the focus on critical infrastructure

Cyber.ar 26 closed in Argentina with a focus on critical infrastructure, and the technical presentations included GNSS signal interference and spoofing, along with hands-on tests on a simulated electrical substation. UNDEF and Infodefensa showcased a space where defense, academia, and the technology sector discussed coordination, periodic testing, and resilience.

The signal from the event matters because it shifts the conversation from tools to the environment. It was not just about malware or phishing, but about the ability to respond to disruptions in essential services. That transition, also visible in the national cybersecurity plan, suggests the region is starting to accept that cyber defense can no longer be separated from the rest of critical infrastructure planning.

Active Threats and Campaigns

Ransomware and extortion

The strongest ransomware and extortion campaign of the month was Panzer, with K3G Solutions Brazil as the best documented victim and an estimated 300 GB exfiltrated according to specialized trackers. At the same time, Titan listed Grupo Hospifar S.R.L. on a leak site and Qilin kept visible activity against Sanatorio Modelo de Caseros, although that last case did not move beyond disputed claims.

The region also saw activity tied to Emperador against the Poder Judicial de Jujuy and claims by Incransom over Diarco, but both were only partially verified. The gap between posting a victim and proving impact remains central. In September, most regional ransomware cases landed somewhere between a leak site mention and partial confirmation of exfiltration.

Campaign Country Type of impact according to material Verification status
Panzer Brazil Estimated 300 GB exfiltrated multiple tracker verification
Titan Argentina Leak site mention only claim, no public confirmation
Qilin Argentina Source does not specify whether encryption occurred; some trackers suggest exfiltration disputed claim
Emperador Argentina Source does not specify whether encryption occurred; trackers show signs of exfiltration disputed claim
Incransom Argentina Leak site mention only unverified claim

Fraud and phishing

Fraud and phishing were the month’s real critical mass. The BCRA warned about fake investment campaigns that imitate banks, wallets and public agencies and ask for credentials or tokens. Regional press also reported a sharp rise in deepfakes, identity theft and voice cloning used in banking and family scams, with Argentina and Brazil standing out.

There were also more specific technical signs. Casbaneiro stayed active against users at financial institutions in Argentina, Peru, Colombia and Mexico, using malicious PDF infection chains, downloaders and geofencing. In Argentina, the use of AI to imitate voices and faces is already showing up as an operational fraud tool, not just a media curiosity.

Campaign or method Countries reached Technique observed Operational read
Fake investment scheme impersonating the BCRA Argentina impersonation of an agency and credential theft classic financial phishing with institutional credibility
Casbaneiro Argentina, Peru, Colombia, Mexico malicious PDF, loaders, geofencing regional banking credential theft
Deepfakes and voice cloning Argentina audiovisual impersonation high-persuasion social engineering
AI-powered phishing Latin America deepfakes and boosted malware greater effectiveness of deception

APT and espionage

The clearest APT signal of the month came from ESET Research with SparroWocky, a backdoor used by FamousSparrow against government targets in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico and Venezuela. The significance of the case lies in its persistence and the regional scope of the targeting, with mechanisms designed to reduce its footprint and make response harder.

That pattern sits alongside a broader one of AI-assisted attacks observed by Unit 42 in organizations across Latin America. The material does not support turning that into a single incident, but it does point to a more mature offensive posture: abuse of legitimate tools, persistence in Windows and campaigns that mix espionage, fraud and access preparation.

Critical vulnerabilities

In the material reviewed, 2 critical CVEs were recorded. That does not mean there were no other relevant vulnerabilities in the region, only that just two were explicitly identified in the month’s corpus.

CVE Software Exploitation Source
CVE-2026-76461 Cisco Secure Email Gateway the flaw appears in CISA's Known Exploited Vulnerabilities catalog, with an EPSS of 28,27% CTIR Gov
CVE-2026-84869 ConnectWise ScreenConnect CISA confirmed active exploitation Aviatrix Threat Research Center

The fact that only two CVEs were mentioned in the material should not be read as evidence of low vulnerability risk in the region. The month was shaped by other editorial and regulatory priorities, and the research corpus does not provide an exhaustive list of technical exploitation. What it does show is that, when a critical vulnerability appears, the focus falls on remote management and email products, two surfaces that have long been sensitive for corporate cybersecurity.

Regulation and compliance

September confirmed that regulation is no longer a backdrop. It is now the month’s main threat in terms of document volume. The figure of 322 regulatory developments out of 851 verified during the period reflects a region that is highly active in rulemaking, public consultations, enforcement reforms, and compliance updates. That does not mean less risk, it means more obligations and more traceability for teams.

Argentina accounted for much of the agenda with BCRA Communication A 8473, which formalizes a fraud risk score for instant transfers and requires banks and PSPs to use it for onboarding, monitoring, and roster review. The BCRA also issued alerts about scams using its name for fake investments and moved forward with a broader prevention framework built on public information and risk profiles. For the financial sector, the message is clear, antifraud controls have become a structural part of compliance.

In parallel, the Executive Branch sent Congress a national security bill that incorporates cybersecurity and critical infrastructure. That initiative aligns with earlier discussions on state modernization, digital public services, and data sovereignty. The common thread is a state seeking to organize its digital assets, classify what is critical, and define security responsibilities more precisely.

Brazil showed another side of the same trend. The ANPD held a public hearing, opened a public consultation on oversight of digital platforms, and published guidelines on security incidents and documentation. TI Inside and RNP noted the deadline of up to three business days to report incidents under the LGPD, and the TikTok case reinforced a stricter sanctioning approach. For regional companies, the takeaway is clear, document governance matters as much as technical control.

Country Key regulatory move Operational impact
Argentina BCRA Communication A 8473 and national security bill more antifraud control and greater scrutiny of critical infrastructure
Brazil ANPD hearing and consultation, oversight and sanctions greater pressure on documentation, reporting, and remediation
Peru gradual rollout for the Personal Data Officer compliance timelines by company size
Ecuador legislative treatment of cybersecurity debate over legal framework and governance
Paraguay progress on critical infrastructure and data protection greater sensitivity around essential services
Mexico public consultations and authentication rules in payments tighter identity controls and fraud prevention

Most Affected Countries in Latin America

Argentina

Argentina had the highest density of combined signals in September. There were ransomware cases or extortion claims, banking fraud campaigns, a regulatory shift from the BCRA, and a national project that brings cybersecurity into the state security architecture. The overall picture does not show a single breaking point, but rather overlapping financial, judicial, and critical infrastructure risks.

In ransomware, the most visible names were the Poder Judicial de Jujuy, Diarco, Librería Santa Fe, Sanatorio Modelo de Caseros, the Ministry of Education, and Tecno Acción, although not all carried the same level of confirmation. On fraud, the dominant reference was the ecosystem of transfers, wallets, and identity theft, reinforced by the growing use of AI in scams and by tighter BCRA rules. The country ends the month with heavy regulation and heavy exposure, a combination that demands sharper response and compliance at the same time.

Brazil

Brazil concentrated the most mature regulatory agenda and the clearest confirmed incident evidence. The ANPD was at the center of enforcement, with a public hearing, a public consultation, and debate over transparency and sanctions. CAPES confirmed an incident on the Meus Dados Platform, and CTIR Gov issued an alert over a critical vulnerability. Added to that was the TikTok case, which kept shaping the discussion around child protection and the regulator's enforcement reach.

On the criminal side, Brazil also appeared in the Panzer campaign against K3G Solutions and in ransomware signals linked to industrial and service sectors. The country closed the month as the clearest example of a region where regulation, enforcement, and real incidents are moving in parallel, not in sequence.

Bolivia

Bolivia showed a narrower signal, but not a minor one. The National Chamber of Industries reported an attack on its official Facebook page, with temporary disruption to institutional communications, and Entel, AGETIC, and ATT launched Bolivia Cibersegura 2026 to strengthen incident response. Data on attempted cyberattacks against the banking sector was also circulated, although that figure comes from telemetry and not from confirmed intrusions.

The country reading points to capability-building, not a single major incident. The risk center is the institutional maturity of response and the need to professionalize sector CSIRTs and reporting channels.

Peru

Peru appears more in regulatory terms than in incidents. The deadline for appointing Personal Data Officers in mid-sized companies under Law 29733 shows an ongoing compliance timetable. There were also signs of regional criminal activity with Casbaneiro targeting users in the country, although the case was reported in a multinational context and not as an isolated local incident.

For Peruvian companies, the month reinforces a gradual compliance picture and exposure to regional financial fraud. The link between data regulation and digital fraud is stronger here than in other Andean countries.

Colombia

Colombia stood out because of the Casbaneiro campaign, which targeted users of financial institutions in the country, and because of legislative debate over a new data protection bill that would toughen penalties and expand territorial scope. The material does not include confirmed incidents with the same level of detail as Argentina or Brazil, but it does show clear pressure from regulation and exposure to cross-border banking fraud.

The combination of AI, phishing, and regulatory change suggests the country is entering a phase of closer regional alignment with stricter protection models. The operational priority is identity, monitoring, and response to highly realistic impersonation attempts.

Mexico

Mexico maintained a strong agenda around payments, authentication, and fraud prevention, although with fewer confirmed incidents in the month's material. Banxico kept public consultations open, and financial sector coverage continued to reflect tighter controls on cards, payments, and clearinghouses. On the criminal side, Casbaneiro also targeted users in Mexico, reinforcing the picture of a shared regional financial vector.

The country appears less as a site of isolated incidents and more as a market where authentication rules, payment oversight, and pressure to fight fraud converge. September's snapshot is that of a financial ecosystem still closing identity gaps.

Paraguay

Paraguay continued to move forward on discussions about critical infrastructure and data protection. The available material points to a regulatory architecture that is still taking shape, with a focus on essential services and personal data rules. There were no confirmed major incidents comparable to those in Argentina or Brazil, but there was a clear signal of steady regulatory construction.

For the regional analysis, Paraguay matters because it shows the kind of legal foundation that other countries are still debating. Its relevance is less media driven and more structural.

Chile

Chile appears in the material mainly as a point of comparison in data protection laws and debates over regulatory delays. There were no relevant incident-related developments within the scope of this report for September, at least in the corpus provided. That does not mean there was no risk, only that there were no facts in the included coverage that were sufficiently verifiable.

Ecuador

Ecuador had a legislative step on cybersecurity and an operational reference in the SparroWocky campaign by FamousSparrow, which affected government bodies in the country. The strongest point is not a major public breach, but confirmation that the Andean region remains on the radar of APT actors focused on government targets.

The country combines regulatory debate with exposure to digital espionage. In that sense, the material places it closer to a state defense front than to a mass fraud ecosystem.

Compared with August, September had fewer verified incidents overall, but more fraud activity and more uncategorized incidents. The 851 incidents in September were down from 902 the previous month, and regulatory actions also fell from 410 to 322. Even so, documented fraud and phishing jumped from 85 to 190, and uncategorized incidents rose from 48 to 61. The signal is clear, there was less regulatory noise than in August, but more real pressure from fraud and more cases that still cannot be closed technically.

In ransomware, the change was minimal, from 41 to 40 cases with extortion as the primary focus. That points to stability rather than decline. What changed was the mix: more claims involving organizations in the region, more difficulty distinguishing encryption, exfiltration or simple posting on a leak site, and a greater need to validate each case before assuming impact. The region remains a profitable target for extortion, but the operational value is increasingly in exfiltration and reputational pressure.

The other major shift is fraud. The jump from 85 to 190 documented cases is not explained only by broader coverage, but also by more sophisticated deception and the use of AI in deepfakes, voice cloning and more persuasive phishing scripts. Reporting from Argentina, Brazil and the broader region shows that fraud no longer depends on obvious mistakes. Social authentication and human verification need to be strengthened as much as technical controls.

Regulation has not disappeared, even if the volume is down. On the contrary, the month showed a shift from broad rulemaking to concrete enforcement. Brazil's ANPD and Argentina's BCRA are in an implementation and oversight phase, not just an announcement phase. That is a relevant signal for security and legal teams, because it requires evidence, not just policies.

September vs. previous month comparisonIncidentsUnclassifiedRansomwareFraudRegulationCVEs85161401903222
Signal comparison — September saw declines in total incidents and regulation, but a sharp rise in fraud or phishing and unclassified incidents.

Security team recommendations

The immediate priority is to review anti-fraud controls on payment and transfer channels, especially where there are high-frequency flows, new customer onboarding, and sensitive home banking or wallet operations. This month’s material shows that fraud now combines impersonation, AI, and the exploitation of process weaknesses, so controls need to cover identity, behavior, validation, and user response.

Second, incident response discipline around leak sites and unverified complaints should be tightened. Not every listing means a confirmed intrusion, and September produced several examples where the difference between mention, exfiltration, and encryption changes the case priority completely. Any team monitoring these signals should classify them by certainty, sector, evidence type, and possible impact on regulated data.

Third, regulated sectors, especially finance, health, and government, should review their notification obligations and documentation requirements. Brazil already operates with short deadlines and recordkeeping requirements, while Argentina adds risk scoring, transfer profiles, and a critical infrastructure agenda. If a team cannot reconstruct a technical timeline and a business decision timeline, it is already behind what the month is beginning to demand.

Fourth, controls against AI-assisted fraud need to be adjusted. That includes second-channel verification, limits on trusting audio or video, training on deepfakes, and clear procedures for rejecting urgent requests that arrive through messaging apps or unverified calls. This month’s material shows that deception no longer depends on bad spelling or clumsy messages.

Fifth, organizations exposed to essential services or critical infrastructure should test continuity and segmentation more often. Cyber.ar 26 and Guardião Cibernético 8.0 show that the region is already treating substations, energy, health, and networks as real targets. Exercises should validate recovery, not just the existence of backups.

Priority Action Practical application
1 strengthen anti-fraud controls scoring, monitoring, additional validation, account review
2 classify extortion claims distinguish leak site, exfiltration, and encryption
3 prepare notification incident logging, evidence, reporting timelines
4 train against fraudulent AI deepfakes, voice cloning, audiovisual impersonation
5 test continuity exercises on critical infrastructure and essential services

Frequently Asked Questions

Why did September show more fraud than ransomware in the material analyzed?

Because the month brought 190 documented fraud or phishing cases, compared with 40 cases where ransomware or extortion was the primary focus. Argentina and Brazil also concentrated many signals of impersonation, deepfakes, and banking scams. The Indicators section and the Active Threats and Campaigns section show this clearly.

Which countries concentrated the most relevant signal in the month?

Argentina and Brazil concentrated the highest density of verifiable incidents. Argentina led in fraud, banking regulation, and ransomware complaints. Brazil led in data oversight, a confirmed incident at CAPES, and activity by the ANPD. For a detailed reading, see Countries Most Affected in Latin America and Regulation and Compliance.

What is the difference between a victim published on a leak site and a confirmed case?

A leak site posting may be only an extortion claim. A confirmed case requires additional evidence of impact, ideally from the organization itself or from strong technical sources. In September, several cases in Argentina fell into that gray area, which is why the report distinguishes claim, exfiltration, and encryption in Active Threats and Campaigns.

What changed in Argentina's regulatory agenda compared with the previous month?

The BCRA moved from anti-fraud discussion to the implementation of risk scores and profiles for transfers, while the executive branch sent Congress a national security bill that includes cybersecurity and critical infrastructure. The comparison with August is developed in Period Indicators and Trends and Signals to Watch.

Were critical vulnerabilities published during the month?

Yes, the material analyzed mentions 2 critical CVEs, CVE-2026-76461 and CVE-2026-84869. That does not mean there were no other flaws in the region, only that those two were explicitly identified in the month's corpus. See the Critical Vulnerabilities table for details and the associated source.

What should a financial team in the region prioritize after this month?

It should prioritize transfer fraud controls, stronger identity verification, response to brand impersonation, and monitoring for extortion on leak sites. The material shows a jump in AI-enabled phishing and tighter regulation around evidence and traceability. The operational recommendations are in Recommendations for Security Teams.

Material limitations

This report uses only the facts provided for September 2026 and its comparison frame. The 851 verified facts from the period are the basis for all monthly indicators, while 132 facts from earlier months were used only for comparison and never as period volume. Four undated facts and 8 facts dated after the period were also excluded.

One important point is that a zero indicator, especially for vulnerabilities, means it did not appear in the material analyzed, not that it did not exist in the region. In this case, 2 critical CVEs were mentioned, but that does not allow any inference about the total number of vulnerabilities exploited in Latin America during the month. The same standard applies to other fields: absence from the corpus does not equal real-world absence.

The indicator time window included 856 facts dated in September 2026, 132 from earlier months as a comparative frame, 4 undated facts excluded, and 8 later facts excluded. The material also contains 5 aggregated telemetry figures, which are automated attempts or blocks, not incidents with confirmed impact. Those figures were kept out of the monthly volume.

Attribution quality varies by case. In several facts, especially ransomware and leaks, the corpus includes leak site trackers, breach trackers, or secondary notes that do not amount to official confirmation. When the material does not allow a distinction between encryption, exfiltration, or a simple mention, this report says so explicitly. Sources not allowed under the assignment, such as consumer social networks or posts outside the authorized list, were also excluded.

Sources